1. Introduction
Tenant Excellence is a software-as-a-service web application operated by NSE. It assesses the security posture, compliance readiness, licence use, user adoption and operational risk of Microsoft 365 tenants and Azure subscriptions, using read-only access authorised by the customer.
This policy describes what personal information and tenant data may be processed, why, how it is protected, and the choices and rights you have.
2. Scope
It applies when you visit this site, request a demonstration, create or administer an account, contact support, or authorise a tenant assessment. Third-party services, including Microsoft, have their own terms and notices.
3. Roles and responsibilities
NSE determines the purposes and means of processing for information submitted directly to it for account administration, sales, support, security and service operation, and acts as controller. For tenant data processed on a customer’s instructions, the customer is the controller and NSE the processor, subject to the agreement between them.
4. Information we may process
Contact and account information: name, business e-mail address, organisation, role, and the account, tenant, user and session identifiers used for authentication and access control; information submitted through demo, onboarding or support interactions.
Customer-authorised Microsoft 365 and Azure data, read in the browser during an assessment: tenant, domain, subscription and service configuration metadata; Entra ID user, group, role, authentication and access-policy metadata; security, compliance, governance and protection settings; licence assignments and usage reports; Azure resource, policy, security and cost metadata; and the findings, control mappings, recommendations and tenant-sourced proof the application derives from them.
Technical and security data: IP address, browser and device information, timestamps and security logs where necessary to operate, secure and troubleshoot the service.
5. Optional AI insights
When enabled for a tenant, a summary of the assessment is sent from the user’s browser to Microsoft’s Work IQ service under the user’s own Entra ID identity. The summary contains counts, statuses and control identifiers only — no names, user principal names, e-mail addresses, domain names, resource names or evidence text. It does not pass through NSE servers and no third-party model provider is involved.
6. Information the application is not designed to access
The application is not designed to access the content of e-mails, Teams chats, SharePoint documents, OneDrive files, attachments, or audio or video recordings. Should a future optional feature require additional access, its permissions and purpose will be disclosed before authorisation and this policy updated.
7. Microsoft access and authentication
Microsoft Graph and Azure Resource Manager are accessed only within the permissions approved through Microsoft’s consent framework by an authorised customer representative. The assessment is read-only. The application never requests or stores your Microsoft password; access tokens are held in the browser session and are not stored on our servers. The consent screen is the authoritative permission list.
8. Purposes of processing
Authenticate users and administer access; perform the assessments the customer requests; generate dashboards, findings, recommendations, reports, evidence and customer-authorised auditor views; provide demonstrations, onboarding, support and service communications; maintain availability and security, prevent misuse and investigate incidents; comply with legal obligations and enforce agreements. We do not sell personal information and do not use tenant data for advertising.
9. Legal bases
Under the GDPR and similar laws: performance of a contract or pre-contractual steps, our legitimate interests in operating and protecting the service, legal obligations, and consent where required. Where we process on a customer’s documented instructions, the customer’s legal basis governs.
10. Storage and retention
Data read for a live assessment stays in the browser and is not retained as a server-side copy. We store: company and user accounts (until deleted by the administrator); tenant registration records (until the tenant is deleted); evidence the customer attaches to controls (with the tenant record); auditor-link snapshots (24 hours); an audit log of sign-ins, administrative changes and link creation (90 days); and demo requests submitted on this site. Microsoft passwords are never stored.
11. Disclosures and service providers
Information may be disclosed to authorised personnel and to service providers supporting hosting, authentication, transactional e-mail, security and support, only where necessary and under contractual safeguards. We rely on Microsoft Entra ID, Microsoft Graph, Microsoft 365 and Azure. Information may be disclosed where required by law or to protect rights, safety and security. We do not sell, rent or monetise customer tenant data.
12. International data transfers
Where data is transferred across borders we apply the safeguards required by applicable law: contractual protections, approved transfer mechanisms and technical and organisational measures. Microsoft’s own transfer commitments govern the Microsoft services read.
13. Security
Encrypted transport, Microsoft Entra ID authentication for tenant access, a second factor sent by e-mail for platform sign-in, role-based and least-privilege access enforced server-side, rate limiting, an append-only audit log, and auditor links that are read-only, scoped and expire automatically. No system is completely secure.
15. Your rights
Access, rectification, erasure, a copy of your data, restriction or objection, withdrawal of consent, and complaint to a data-protection authority. Send requests to the data-protection contact below; we may verify identity and authority, and may refer requests about tenant data to the customer that controls it.
16. Customer responsibilities
Customers ensure they have lawful authority to connect a tenant, grant permissions, authorise users and use the outputs; provide any notices required to their own users; and configure the application consistently with law and their internal policies.
17. Children
This is a business application not directed to children. We do not knowingly collect children’s data.
18. Changes to this policy
Updates are published at this address with a new revision date; additional notice is given where the law requires it.