Skip to content
Tenant Excellence

GDPR

Tenant Excellence was built to assess a Microsoft 365 and Azure estate without accumulating personal data in the first place. This page describes how, and where the limits are.

Effective
Sep 25, 2026
Last updated
Sep 25, 2026
Data protection contact
support@tenantexcellence.com
Contents

At a glance

  • No tenant content

    Not designed to access e-mails, chats, files, attachments or recordings.

  • Read-only access

    The assessment reads. It does not create, change or delete users, content, settings or resources.

  • No passwords, no stored tokens

    Authentication goes through Microsoft Entra ID; access tokens stay in the browser session.

  • No standing copy

    Assessment data is processed in the browser to produce the result, not retained server-side.

  • Only what you choose to keep

    Evidence you attach and 24-hour auditor snapshots are the only tenant-derived records stored.

  • Traceable by default

    Sign-ins, administrative changes and link creation go to an append-only audit log kept for 90 days.

1. The short version

The simplest way to protect personal data is not to hold it. The application assesses configuration, security, compliance, licensing and adoption from metadata about how a tenant is set up, not from its content, and it is designed so that sensitive material never enters it.

2. Data protection by design and by default — Article 25

Scope limited at the permission layer: access is constrained by the permissions an authorised administrator approves on Microsoft’s consent screen; the list there is authoritative and cannot be widened afterwards.

Content deliberately out of scope: questions such as “is MFA enforced”, “which licences are unused” or “is this storage account public” need no message or document reading, so those permissions are not requested.

Nothing retained that the result does not need: a finished assessment is findings and proof references, not a copy of the tenant. Only the evidence you attach and the auditor snapshots you create are stored, and the snapshots expire after 24 hours.

Separation of duties in the product: a platform administrator can create a company, register its tenant and set entitlements, but cannot open its assessment, read its evidence or issue an auditor link. The server enforces this.

3. What the application is not designed to access

The content of e-mails, Teams chats, SharePoint documents, OneDrive files, attachments, or audio or video recordings. Any future optional feature requiring more would be disclosed before authorisation; the customer decides.

4. Optional AI insights

AI insights use Microsoft’s Work IQ, called from the user’s browser under the user’s own Entra ID identity, within the tenant’s trust boundary and its own compliance controls. The summary is reduced to counts, statuses and published control identifiers; nothing passes through NSE servers and no third-party model provider is involved.

5. Roles and the agreement between us — Article 28

For account, contract and support records, NSE is the controller. For tenant data processed on the customer’s instructions, the customer is the controller and NSE the processor. A data processing agreement covering the Article 28(3) terms is available on request.

6. Lawful bases — Article 6

As controller: contract, pre-contractual steps, legitimate interests, legal obligation, and consent where required. As processor: the customer’s lawful basis.

7. Security of processing — Article 32

Encrypted transport for all network communication. Microsoft Entra ID authentication for tenant access; platform sign-in protected by a second factor sent by e-mail. Role-based, least-privilege access enforced server-side. Session invalidation on password change and administrative revocation of sessions. Rate limiting on authentication and write operations. An append-only audit log. Auditor links that are read-only, scoped to a single framework and expire automatically. Measures are reviewed as the service changes; no system is guaranteed secure.

8. Storage, retention and deletion — Article 5(1)(e)

Accounts until deleted by the administrator; tenant registration until the tenant is deleted; attached evidence with the tenant record; auditor snapshots 24 hours; audit log 90 days; demo requests are not deleted automatically. Deleting a tenant removes its stored evidence and auditor links.

9. International transfers — Chapter V

Standard contractual clauses, adequacy decisions and technical and organisational measures as applicable. Microsoft’s transfer commitments govern the Microsoft services read.

10. Data subject rights — Articles 12 to 23

Access, rectification, erasure, a copy, restriction, objection, withdrawal of consent and complaint to a supervisory authority. For data in a customer tenant, the customer is the controller and we assist it. For account and support records, contact the data-protection address below.

11. Sub-processors

Providers for hosting, authentication, transactional e-mail and support, bound by contractual terms. The current list and the change-notification procedure are provided with the data processing agreement.

12. Personal data breaches — Articles 33 and 34

Procedures to detect, investigate and record breaches. As processor we notify the affected customer without undue delay with the information it needs; as controller we notify the supervisory authority within 72 hours where notifiable, and individuals where the risk is high.

13. Records and impact assessments — Articles 30 and 35

We keep records of processing carried out on behalf of customers and provide, for a customer’s impact assessment, information about the processing, data categories, security measures and sub-processors.

14. Scope of this page

This page describes design and supporting measures. It is not legal advice. The GDPR offers no product certification; compliance depends on how a controller deploys and uses a tool. The agreement and the data processing agreement prevail over this page.

How the design maps to the regulation

  • Lawfulness, fairness, transparency — Art. 5(1)(a)
    Access is granted through Microsoft’s consent screen, which lists every permission before anything is authorised.
  • Purpose limitation — Art. 5(1)(b)
    Tenant data is processed to produce the assessment the customer asked for; it is not used for advertising or sold.
  • Data minimisation — Art. 5(1)(c)
    Configuration and usage metadata only. Message, file and recording content is outside the permission set.
  • Storage limitation — Art. 5(1)(e)
    No standing server-side copy of tenant data; evidence with the tenant, snapshots 24 hours, audit log 90 days.
  • Integrity and confidentiality — Art. 5(1)(f)
    Encrypted transport, Entra ID with a second factor, least-privilege roles, audit logging.
  • Accountability — Art. 5(2)
    Append-only audit log, records of processing, data processing agreement on request.
  • By design and by default — Art. 25
    Read-only scopes, content out of scope, administration separated from customer data.
  • Processor obligations — Art. 28
    Documented instructions, confidentiality, sub-processor terms, deletion at the end of the service.
  • Security of processing — Art. 32
    The measures in section 7, reviewed as the service changes.
  • Breach notification — Art. 33 and 34
    Detection and recording procedures; customer notified without undue delay.

Contact