Privacy Policy
Last updated: 2 July 2026 (rev 9) · M365Clarity (sole trader)
Who we are
M365Clarity is a trading name operated by Stephen Bennett as a sole trader. We operate the M365Clarity platform at m365clarity.com. For data protection purposes, we are the data controller. We are registered with the Information Commissioner's Office (ICO) under registration number ZC173030. You can verify this at ico.org.uk.
Contact: support@m365clarity.com
What data we collect
When you sign in with your Microsoft 365 account, we receive and store:
- IP addresses and browser fingerprints: we do not store these. Rate limiting is handled in memory at request time by Cloudflare. No IP address is written to the database.
- Account data: your name, email address, and Microsoft tenant ID
- Licence data: your Microsoft 365 subscription SKUs and plan name
- Configuration data: the results of Microsoft Graph API checks against your tenant settings (policy configurations, feature enablement status, Secure Score)
- OAuth tokens: Microsoft access and refresh tokens (encrypted at rest with AES-256-GCM) used to run scans on your behalf
- Billing data: Stripe customer ID and subscription status. We never store card numbers — payment is handled entirely by Stripe.
- Usage data: scan history, audit log of actions performed in the platform (action name, timestamp, and account ID only — no IP addresses; tiered retention of 30–90 days for operational events, indefinite retention for security-critical events), configuration snapshot data from Microsoft Graph (stored to power AI explanations — raw responses purged after 90 days, trimmed to 4KB per feature, never shared with third parties), AI explanation cache (purged after 60 days), AI chat conversation history per scan (up to 50 messages, stored in EU), autonomous agent alert logs (token health, score drop alerts, compliance milestones), product analytics events (e.g. upgrade button clicks — stored for up to 12 months to improve the product), diagnostic log data (optional — only collected when explicitly enabled by an M365Clarity administrator for support purposes, automatically deleted after 24 hours, limited to platform interaction events with no personal data beyond account identifiers)
- Guest account data: if your tenant has external guest users, the Guest Audit feature reads their display name, email address, and last sign-in date from Microsoft Graph. This data is used only to display the guest audit within your account and is not shared with other users or third parties. It is deleted when you delete your account or disconnect the tenant.
- Licence utilisation data: the number of assigned and consumed seats per Microsoft 365 SKU. No individual user assignment data is collected — only aggregate counts per subscription.
- Inactive user data: when Licence Waste Detection runs, M365Clarity reads each licensed user's display name, email address (userPrincipalName), last sign-in date, and licence count from Microsoft Graph. This data is used only to display the Licence Waste report within your account and is deleted when you delete your account or disconnect the tenant. This feature requires Azure AD P1 (Entra ID P1) on the scanned tenant — if not available, no sign-in data is collected.
- Workload adoption data: when the Workload Adoption tab is viewed, M365Clarity calls the Microsoft Graph activity reports API to retrieve per-user activity data for Teams, SharePoint, OneDrive, and Exchange Online over the previous 30 days. User Principal Names (UPNs) and display names are included in these reports. This per-user activity data is cached in the M365Clarity database for the duration of the scan and is deleted when you delete your account or disconnect the tenant. When the Adoption by Department feature is used, M365Clarity additionally calls the Microsoft Graph
/usersendpoint to retrieve thedepartmentfield for each user in your tenant. UPNs are joined to department names in memory to produce department-level adoption summaries; individual user-level data is not exposed in the UI. The department-aggregated result is cached per scan. This personal data (UPN, department) is used only to produce the adoption report within your account and is deleted when you delete your account or disconnect the tenant. - Copilot usage data: when the Copilot & AI tab is viewed, M365Clarity calls the Microsoft Graph Copilot usage reports API (
getMicrosoft365CopilotUsageUserDetail) to retrieve per-user last activity dates for Copilot apps (Teams, Word, Excel, PowerPoint, Outlook, OneNote, Loop, Copilot Chat) over the previous 30 days. Microsoft returns display names and userPrincipalNames in a hashed/pseudonymised format by default. This data is used only to display the adoption summary within your account session and is not persisted to our database. It is only available if your tenant has paid Microsoft 365 Copilot licences assigned. - Shared report data: when you generate a share link for a scan, the scan results (feature names, categories, and status only — no raw configuration data) are accessible via the share URL for up to 7 days. Share tokens are stored against your scan record and expire automatically. You can generate a new token to invalidate the previous link.
- MSP user data: if you use the Multi-Tenant MSP plan, M365Clarity stores your team members' email addresses, names, and roles, and the company names and domains of client tenants you connect. These fields are encrypted at the application layer using per-organisation AES-256-GCM encryption — encrypted values are stored in the database and cannot be read without a separate encryption key that is never stored alongside the data. The founding MSP admin's login email is not encrypted as it is required for authentication and billing. Invited users receive an email via Brevo and their details are retained until you remove them or cancel your MSP account. When an MSP adds a client tenant, a client contact email address is collected — this is provided by the MSP and is used to send a one-time connection notification email to the client informing them that their tenant has been connected. This email address is stored against the tenant record and retained for the duration of the MSP-client relationship.
- MSP logo: if you upload a company logo via the Manage Accounts tab, it is stored in private Cloudflare R2 object storage in the EU (WEUR region). It is never publicly accessible and is served only to authenticated MSP sessions. You can replace or remove it at any time from the Manage Accounts tab.
Legal basis for processing
- Contract: processing necessary to provide the service you have signed up for
- Legitimate interests: security logging, fraud prevention, and service improvement
- Legal obligation: compliance with UK GDPR and ICO requirements
How we use your data
- To run Microsoft Graph API scans against your tenant on your behalf
- To provide AI-powered analysis of your scan results
- To send scan completion and configuration change notifications (if enabled)
- To send ticket emails to your nominated IT helpdesk address (if you use the Ticket Export feature) — sent via Brevo from noreply@m365clarity.com
- To generate licence cost estimates using publicly available Microsoft pricing data
- To calculate score trend statistics based on your own scan history (your data is never aggregated with or compared against other organisations outside your own account)
- For Multi-Tenant (MSP) accounts: to provide portfolio-level benchmarking and comparison across the tenants you manage within your M365Clarity account. This compares tenants within your own managed portfolio only — your clients' data is never shared with, compared against, or visible to any other M365Clarity account or organisation. MSP users are responsible for ensuring they have appropriate authorisation from their clients to manage and analyse their Microsoft 365 environments.
- To process subscription payments via Stripe
- To maintain an audit log of actions performed in your account
- To detect and prevent abuse, fraud, and security incidents
- To understand how the product is used in aggregate (e.g. which features are most used) in order to improve it — using pseudonymous per-account analytics events stored in our own database, never a third-party analytics service
Data storage and security
All data is stored in Cloudflare D1 (SQLite) in the WEUR region (Amsterdam, Netherlands). No data is transferred outside the European Economic Area. Cloudflare's infrastructure is ISO 27001 certified and SOC 2 Type II compliant.
Microsoft OAuth tokens are encrypted with AES-256-GCM before storage. All data in transit is protected by TLS 1.3. Access to production systems requires multi-factor authentication.
Data retention
- Scan results: retained for as long as your account is active. Raw Microsoft Graph API responses within scan results are purged after 90 days.
- AI explanation cache: purged after 60 days
- Audit log: tiered retention — security-critical events (login, signup, billing, role changes, data export requests) are retained indefinitely; user-facing events (scan activity, feature explanations, share links) are retained for 90 days; internal platform events (admin dashboard views, token generation) are retained for 30 days; all other events are retained for a maximum of 12 months. All audit log entries are automatically purged by a nightly scheduled process.
- Error log: retained for 90 days, then automatically deleted
- Product analytics events: retained for 12 months, then automatically deleted
- OAuth tokens: deleted when you disconnect a tenant or delete your account
- Account data: anonymised immediately on account deletion (email replaced, name cleared). All associated scan data, tenant connections, audit logs, and cached AI outputs are permanently and irreversibly deleted within 30 days by an automated nightly process.
- IP addresses: not stored — Cloudflare handles rate limiting in memory at the edge
MSP account data
On cancellation of an MSP account: MSP user records, invite records, and OTP codes are retained for 30 days then permanently deleted. Tenant scan data linked to MSP users follows the standard 90-day raw data purge and tiered audit log retention policy. Company logos are deleted immediately on account cancellation.
Third-party processors
- Cloudflare — infrastructure, edge compute, and database storage (DPA covered by Cloudflare's standard terms)
- Stripe — payment processing (DPA covered by Stripe's standard terms)
- Brevo (Sendinblue) — transactional email delivery (DPA covered by Brevo's standard terms)
- Anthropic — AI analysis of scan results. Feature names and configuration statuses are sent to generate explanations, guides, summaries, narratives, and adoption action plans. For the What If feature specifically, your scan results (feature names, configuration statuses, and RAG ratings) are sent to the Anthropic API along with your question to generate impact analysis. For the Adoption Coach feature, workload adoption percentages and feature statuses for underperforming workloads are sent to generate action plans. For the Change Management feature, adoption percentages, feature statuses, and Copilot adoption data (when available from the Copilot & AI tab) are sent to infer active organisational transitions and generate ADKAR-positioned guidance. No email content, file content, personal data about individuals in your tenant, or raw Microsoft Graph API responses are sent to Anthropic. Anthropic does not use API data to train models under standard API terms. What If conversation history is stored in the M365Clarity database (EU region) for session continuity only — up to 50 messages per scan — and is purged when you disconnect your tenant or delete your account.
- Microsoft — OAuth authentication and Graph API access
- Sentry — error tracking and performance monitoring. Unhandled exceptions from the Cloudflare Worker are reported to Sentry. Reports may include request paths, error stack traces, and platform metadata. No personal data, tenant scan data, or Microsoft Graph API responses are included in Sentry reports. 10% of requests are traced for performance monitoring. Data is retained per Sentry's standard terms and processed in the EU.
Your rights
Under UK GDPR you have the right to:
- Access: export all your data as JSON via Account → Export My Data
- Erasure: delete your account and all data via Account → Delete Account (permanent removal within 30 days)
- Rectification: contact us to correct inaccurate personal data
- Portability: receive your data in a machine-readable format
- Object: object to processing based on legitimate interests
- Restrict: request restriction of processing in certain circumstances
To exercise any right or to make a complaint, contact support@m365clarity.com. You also have the right to lodge a complaint with the ICO at ico.org.uk.
Cookies
M365Clarity does not use tracking cookies or advertising cookies. We use a session token stored in your browser's localStorage to maintain your login state. This is essential for the service to function and does not require consent.
Changes to this policy
We will notify registered users by email of any material changes to this policy. The current version is always available at m365clarity.com/privacy.