Legal
Data processing agreement
How we process personal data from the Microsoft 365 tenants you connect, on your behalf and on your instructions.
Last updated 25 September 2026
Draft, pending legal review
1. Scope and roles
This agreement forms part of the Terms of service between [Company legal name] (“we”) and the customer (“you”). It applies to personal data that we process on your behalf when providing SurePosture, as described in Annex A, and meets the requirements of Article 28 of the UK GDPR.
For that data, you are the controller and we are your processor. Where you act for your own clients (for example as a managed service provider), your client is the controller, you are their processor, and we are your sub-processor; you confirm you are authorised by your client to appoint us. If this agreement conflicts with the Terms of service, this agreement prevails for personal data.
2. Processing on your instructions
We process the personal data only on your documented instructions: these terms, your configuration of SurePosture and the actions your users take in it, unless the law requires otherwise, in which case we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks data protection law. You are responsible for having a lawful basis for the processing and for giving any notices to the people whose data is processed.
3. Confidentiality
Everyone we authorise to process the personal data is bound by a duty of confidentiality, and access is limited to those who need it to provide, support or secure the service.
4. Security
We maintain appropriate technical and organisational measures to protect the personal data, as required by Article 32, including those in Annex B. We may update them provided the overall level of protection is not reduced. More detail is in the trust centre and on the data protection page.
5. Sub-processors
You give general authorisation for us to use the sub-processors listed in Annex C. We will give you at least 30 days' notice by email before adding or replacing one. You may object on reasonable data protection grounds within that period; if we cannot reasonably address the objection, you may end the affected service without penalty. We impose data protection terms on each sub-processor that are no less protective than these, and remain responsible for their performance.
6. Assistance
Taking into account the nature of the processing, we will help you respond to requests from individuals exercising their rights, and help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36). If we receive a request from an individual about your data, we will pass it to you and not respond ourselves unless you ask us to.
7. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data. We will provide the information you need to meet your own obligations as it becomes available, and take reasonable steps to contain and remedy the breach.
8. Deletion at the end
During the service, assessment data is kept for your plan's history period and then deleted automatically, as described on the data protection page. When the service ends, you can export reports before access stops, and we delete the personal data within 30 days of the workspace closing, unless the law requires us to keep it. Backups roll off on their normal cycle.
9. Information and audit
We will make available the information reasonably needed to demonstrate compliance with this agreement. We will answer reasonable security questionnaires, and allow audits by you or an independent auditor you appoint, on reasonable notice, no more than once a year (or after a breach), during business hours and subject to confidentiality. We may first offer relevant independent reports or certifications where they cover the request.
10. International transfers
We do not transfer the personal data outside the UK and the European Economic Area except to a sub-processor listed in Annex C. Where a transfer goes to a country without UK adequacy regulations, we will use a transfer mechanism recognised under UK law, such as the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
11. General
This agreement lasts while we process personal data for you. Each party's liability under it is subject to the limits in the Terms of service, except where the law does not allow them to apply. It is governed by the law of England and Wales. To request a signed copy, contact [privacy contact email].
Annex A: Processing details
| Subject matter | Assessment of the security and configuration of Microsoft 365 tenants connected by the customer. |
|---|---|
| Duration | For the term of the Terms of service, and afterwards until deletion as set out in section 8. During the term, each assessment is kept for the plan's history period. |
| Nature and purpose | Reading configuration and directory metadata through Microsoft Graph with permissions granted by the tenant administrator; storing a trimmed snapshot; evaluating it against security controls; producing findings, reports, baselines and readiness views; and, only when enabled and approved, making changes to the tenant. |
| Personal data | User principal names, display names, account state and type, assigned licences, last sign-in dates, MFA and authentication-method registration, department and job title where set; directory role assignments and group membership; device names, models, serial numbers, operating systems and compliance state; risky-user status; the names and external recipients of mail-forwarding rules (with the optional permission). Not email, files, chats, calendars, passwords or authentication secrets. |
| Data subjects | Staff, contractors and guest users of the connected tenants. |
| Special category data | None is intended or requested. |
Annex B: Security measures
- Least privilege: read-only application permissions by default, granted and revocable by the tenant administrator; write permissions only by separate consent.
- Data minimisation: only the fields the checks use are stored; message, file and chat content is never requested.
- Isolation: each workspace's records are accessed only through code that refuses other organisations' data.
- Encryption: HTTPS for all connections; stored tenant credentials encrypted with AES-256-GCM; passwords stored as salted scrypt hashes; tokens and share links stored only as hashes.
- Access control: two-step verification and Sign in with Microsoft for users; workspaces can require two-step verification; role-based access within each workspace.
- Change control: tenant changes require a successful dry run and approval by someone other than the proposer, with rollback where possible.
- Accountability: an audit log of sign-ins, consents, assessments, exports, approvals, changes and automatic deletions.
- Retention: assessment history is deleted automatically after the plan's period.
- Resilience: managed hosting, with daily backups of the production database.
Annex C: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Render | Application and database hosting | the EU (Frankfurt) |
| [email delivery provider] | Sending notification and invitation emails (recipient addresses, tenant names and summary results) | As stated by the provider |
Stripe processes billing details for your subscription, for which we are the controller (see the privacy notice); it receives no tenant data. Microsoft is not our sub-processor: the tenant data is held by Microsoft under your own agreement with it, and SurePosture reads it with the access your administrator grants.