Skip to content
Tenant Excellence

Privacy policy

How Tenant Excellence handles personal information and customer-authorised Microsoft 365 and Azure data.

Effective
Sep 25, 2026
Last updated
Sep 25, 2026
Data protection contact
support@tenantexcellence.com
Contents

1. Introduction

Tenant Excellence is a software-as-a-service web application operated by NSE. It assesses the security posture, compliance readiness, licence use, user adoption and operational risk of Microsoft 365 tenants and Azure subscriptions, using read-only access authorised by the customer.

This policy describes what personal information and tenant data may be processed, why, how it is protected, and the choices and rights you have.

2. Scope

It applies when you visit this site, request a demonstration, create or administer an account, contact support, or authorise a tenant assessment. Third-party services, including Microsoft, have their own terms and notices.

3. Roles and responsibilities

NSE determines the purposes and means of processing for information submitted directly to it for account administration, sales, support, security and service operation, and acts as controller. For tenant data processed on a customer’s instructions, the customer is the controller and NSE the processor, subject to the agreement between them.

4. Information we may process

Contact and account information: name, business e-mail address, organisation, role, and the account, tenant, user and session identifiers used for authentication and access control; information submitted through demo, onboarding or support interactions.

Customer-authorised Microsoft 365 and Azure data, read in the browser during an assessment: tenant, domain, subscription and service configuration metadata; Entra ID user, group, role, authentication and access-policy metadata; security, compliance, governance and protection settings; licence assignments and usage reports; Azure resource, policy, security and cost metadata; and the findings, control mappings, recommendations and tenant-sourced proof the application derives from them.

Technical and security data: IP address, browser and device information, timestamps and security logs where necessary to operate, secure and troubleshoot the service.

5. Optional AI insights

When enabled for a tenant, a summary of the assessment is sent from the user’s browser to Microsoft’s Work IQ service under the user’s own Entra ID identity. The summary contains counts, statuses and control identifiers only — no names, user principal names, e-mail addresses, domain names, resource names or evidence text. It does not pass through NSE servers and no third-party model provider is involved.

6. Information the application is not designed to access

The application is not designed to access the content of e-mails, Teams chats, SharePoint documents, OneDrive files, attachments, or audio or video recordings. Should a future optional feature require additional access, its permissions and purpose will be disclosed before authorisation and this policy updated.

7. Microsoft access and authentication

Microsoft Graph and Azure Resource Manager are accessed only within the permissions approved through Microsoft’s consent framework by an authorised customer representative. The assessment is read-only. The application never requests or stores your Microsoft password; access tokens are held in the browser session and are not stored on our servers. The consent screen is the authoritative permission list.

8. Purposes of processing

Authenticate users and administer access; perform the assessments the customer requests; generate dashboards, findings, recommendations, reports, evidence and customer-authorised auditor views; provide demonstrations, onboarding, support and service communications; maintain availability and security, prevent misuse and investigate incidents; comply with legal obligations and enforce agreements. We do not sell personal information and do not use tenant data for advertising.

9. Legal bases

Under the GDPR and similar laws: performance of a contract or pre-contractual steps, our legitimate interests in operating and protecting the service, legal obligations, and consent where required. Where we process on a customer’s documented instructions, the customer’s legal basis governs.

10. Storage and retention

Data read for a live assessment stays in the browser and is not retained as a server-side copy. We store: company and user accounts (until deleted by the administrator); tenant registration records (until the tenant is deleted); evidence the customer attaches to controls (with the tenant record); auditor-link snapshots (24 hours); an audit log of sign-ins, administrative changes and link creation (90 days); and demo requests submitted on this site. Microsoft passwords are never stored.

11. Disclosures and service providers

Information may be disclosed to authorised personnel and to service providers supporting hosting, authentication, transactional e-mail, security and support, only where necessary and under contractual safeguards. We rely on Microsoft Entra ID, Microsoft Graph, Microsoft 365 and Azure. Information may be disclosed where required by law or to protect rights, safety and security. We do not sell, rent or monetise customer tenant data.

12. International data transfers

Where data is transferred across borders we apply the safeguards required by applicable law: contractual protections, approved transfer mechanisms and technical and organisational measures. Microsoft’s own transfer commitments govern the Microsoft services read.

13. Security

Encrypted transport, Microsoft Entra ID authentication for tenant access, a second factor sent by e-mail for platform sign-in, role-based and least-privilege access enforced server-side, rate limiting, an append-only audit log, and auditor links that are read-only, scoped and expire automatically. No system is completely secure.

14. Cookies

This site and the application set only strictly necessary cookies: the session cookie of the application, and your language and theme preferences. No analytics or advertising cookies are set.

15. Your rights

Access, rectification, erasure, a copy of your data, restriction or objection, withdrawal of consent, and complaint to a data-protection authority. Send requests to the data-protection contact below; we may verify identity and authority, and may refer requests about tenant data to the customer that controls it.

16. Customer responsibilities

Customers ensure they have lawful authority to connect a tenant, grant permissions, authorise users and use the outputs; provide any notices required to their own users; and configure the application consistently with law and their internal policies.

17. Children

This is a business application not directed to children. We do not knowingly collect children’s data.

18. Changes to this policy

Updates are published at this address with a new revision date; additional notice is given where the law requires it.

Contact