Sentsai← Legal
Sentsai

Privacy Policy

Effective date: June 2025

1.About this Policy

This Privacy Policy explains how Sentsai ("we", "us", "our") collects, uses, stores, and shares personal data when you use our Microsoft 365 licensing audit service.

Sentsai operates in a dual capacity. When you connect your Microsoft 365 tenant and run a scan, your organization is the data controller for the personal data of your employees (Microsoft 365 users), and Sentsai acts as a data processor, processing that data only to provide the contracted service under your documented instructions. The binding terms of that processor relationship are set out in our Data Processing Agreement.

Separately, for data relating to you personally as a platform user (your email address, account activity, and usage of our platform), Sentsai is the data controller and this policy explains how we handle that data.

2.Data Controller vs Processor

The distinction matters for your rights and our obligations:

  • Your employees' data (Microsoft 365 user data): Your organization controls this data. Sentsai only processes it to run the scan and produce a report. We follow your instructions, retain the data only for the configured period (default 90 days), and delete it on request. The full terms are in the DPA.
  • Your personal data as an administrator: Sentsai controls this data. We collected it when you signed in and we use it to manage your account, deliver the service, and communicate with you. The sections below explain our practices in full.

3.What Data We Collect

(a) Account data - collected when you authenticate with Microsoft:

  • Your Microsoft account email address (user principal name)
  • Your display name
  • Your Microsoft tenant ID
  • The name and email address of the person who runs each scan, recorded for accountability and shown on that scan’s report. Held on the scan record and deleted with it at the end of your retention period.
  • A Microsoft OAuth access token - held exclusively in a server-side session store (Redis in production). The browser receives only an opaque, cryptographically random session ID cookie. The access token is never written to the database or sent to the browser.

(b) Microsoft 365 tenant data - retrieved via the Microsoft Graph API during a scan:

  • User display names and user principal names (UPNs / email addresses)
  • Microsoft internal user object IDs
  • License assignment records (which SKUs and service plans are assigned to which users)
  • Last interactive sign-in timestamps
  • MFA method registration status (whether each user has registered authenticator methods)
  • Mailbox storage usage (in bytes)
  • Guest account type flags
  • Directory role assignments (e.g., Global Admin, Exchange Admin)

(c) Usage and platform data - logged automatically:

  • Timestamps of scan requests and report access events
  • IP address of requests
  • Browser user-agent string
  • API endpoint access logs (automatically rotated on a bounded schedule; not retained long-term)

(d) Payment data - processed by Stripe on our behalf. We receive from Stripe a payment confirmation and a link to the receipt Stripe issues for that payment, which we store so you can open it from your billing page. If you choose optional automatic renewal, Stripe stores your payment method and creates a customer record, and we hold only Stripe's reference identifiers for them, together with a record of your renewal consent (when you agreed, from which IP address, and under which Terms version). If you do not choose automatic renewal, each payment is a one-off charge and we hold no customer record or stored payment method at Stripe. In every case we do not store payment card numbers, CVVs, or bank account details, and we never will - the card is held by Stripe, not by us. Turning automatic renewal off, or erasing your account, removes these records as described in this policy; erasure also removes the stored receipt links, so the financial record we are required to retain no longer leads back to you.

4.How We Use Your Data

We use the data we collect for the following purposes:

  • Delivering the service: to authenticate you, connect to your tenant, run a license audit scan, and generate a report with findings and recommendations.
  • Security and fraud prevention: to detect and investigate unauthorized access, abuse, or fraudulent activity on our platform.
  • Compliance and legal obligations: to maintain audit logs as required by applicable data protection, financial, and security laws and regulations.
  • Service improvement: we may use aggregate, anonymized, and de-identified usage statistics (e.g., how many scans are run, average report size) to improve the service. This data cannot be linked back to individual users or organizations.
  • Communications: to provide you with transactional notifications within the product (scan status, report availability, terms updates). Receipts for card payments are issued and emailed to you by our payment processor, Stripe, not by us.
  • Advertising measurement: if you reach us by clicking one of our online ads, the advertising platform (for example Google or Microsoft) adds a click identifier to the landing-page address. We read that identifier from the address itself - not from a cookie - and, if you go on to sign up, may report that conversion and its value back to the advertising platform so we can measure how effective our advertising is. This sets no cookie of any kind, uses no tracking or advertising cookies, and does not follow your browsing across other websites.

We do not sell your data. We do not use your data or your employees' data for any purpose other than producing your report and operating, supporting, and securing the Service, and we never use it to train machine-learning models. Support access is deliberately narrow: our administrative console is read-only and shows account records (such as the administrator contact email and subscription state), billing records, and de-identified report aggregates. It is built so it cannot display the names or email addresses of the people in your directory, nor the text of any finding. Every administrative view of your account is written to the same tamper-evident audit log you can export, including the identity of the person who looked.

5.Legal Basis for Processing (GDPR)

We rely on the following legal bases under Article 6 of the UK GDPR / EU GDPR:

  • Contract performance (Art. 6(1)(b)): Processing your account data (name, email, tenant ID, OAuth token) and running the Microsoft 365 scan is necessary to perform the contract you entered into when you accepted these Terms. Without this processing, we cannot provide the service.
  • Legitimate interests (Art. 6(1)(f)): Security logging (IP addresses, access timestamps, user-agent strings), fraud prevention, aggregate usage analytics, and measuring the effectiveness of our own advertising (attributing a sign-up to the ad click that led to it, via a click identifier carried in the URL rather than any cookie). Our legitimate interest is in operating a secure, reliable service and in understanding which of our marketing works. We have assessed that these interests are not overridden by your interests or fundamental rights.
  • Legal obligation (Art. 6(1)(c)): Retaining certain records (e.g., payment records, security logs) for the periods required by applicable law.

6.Data Retention

  • Scan findings (employee data): PII fields are automatically nulled after your configured retention period (90 days by default, configurable between 30 and 365 days) by an automated job that runs every 24 hours. You can change the retention period via account settings or PUT /gdpr/retention. You can trigger immediate deletion at any time via DELETE /gdpr/erase. Deletion is permanent and irreversible.
  • Account data: retained for the duration of your relationship with Sentsai and deleted within 30 days of account closure or erasure request, unless a legal retention obligation applies (e.g., financial records).
  • Aggregate summary figures: for each scan we retain three non-personal totals beyond the scan retention period above - the account count, the identified-savings figure, and the compliance-gap count - so you can see your progress over time and so we can personalise the optional annual re-audit reminder. These are account-level figures about your own licensing (not employee data); they contain no employee personal data, are included in your data export, and are deleted immediately on erasure or account deletion.
  • Audit log (action records): action, timestamp, and resource reference fields are retained indefinitely as an immutable audit trail - they are never deleted. The IP address and user-agent string within audit entries are anonymized (set to null) after your configured retention period has elapsed, in accordance with the GDPR storage limitation principle (Article 5(1)(e)).
  • Payment records: a transaction record (amount, date, payment method, refund status, and a link to the Stripe receipt) is retained for at least 7 years, as required by applicable financial record-keeping regulations. On erasure or account deletion these records are stripped of personal data and de-linked from your account; the resulting de-identified transaction record may be kept beyond that period as a financial record. It contains no employee personal data and no scan findings.

7.Sub-Processors

We share data with the following sub-processors to deliver the service. We have a Data Processing Agreement or equivalent safeguard in place with each sub-processor.

MicrosoftUnited States
Microsoft Graph API - data retrieval from your tenant
Microsoft AzureUnited States
Database hosting and compute infrastructure for the Sentsai application
StripeUnited States
Payment processing and issuing your payment receipts
Resend (Plus Five Five, Inc.)United States
Delivery of transactional and lifecycle emails (report-ready notices, subscription renewal reminders, and optional re-audit reminders). Shared with Resend: your email address and the message itself. A message may name your organization and state the annual savings figure from your report, both of which are organization-level information. No employee-level data is ever included - no user names, sign-in addresses, account identifiers, licence assignments, sign-in times, multi-factor status, mailbox sizes or directory roles.

Email communications. We use Resend to send you two kinds of email. Service (transactional) emails, such as report-ready notices and reminders that your subscription is about to expire, are part of the service and are always sent. Receipts for card payments come from Stripe rather than from us. Marketing emails, such as occasional reminders that it may be time to re-run your audit, are sent on the basis of our legitimate interest in keeping existing customers informed about a service they have used. Every marketing email includes a one-click unsubscribe link; unsubscribing stops all marketing email while leaving service emails unaffected. We never share your data with any third party for that third party's own marketing.

8.International Transfers

Some of our sub-processors are based in the United States, which is outside the UK and EEA. Transfers of personal data to these sub-processors are covered by one or more of the following safeguards:

  • The EU-US Data Privacy Framework and UK Extension, where the recipient is certified;
  • Standard Contractual Clauses (SCCs) as approved by the European Commission or UK ICO, incorporated into our data processing agreements with sub-processors;
  • Other equivalent appropriate safeguards as recognized under applicable data protection law.

You may request details of the specific transfer mechanism applicable to any sub-processor by contacting privacy@sentsai.com.

9.Your Rights

Under the UK GDPR, EU GDPR, and equivalent data protection laws, you have the following rights regarding your own personal data (account data). For rights relating to your employees' data, see our Data Processing Agreement.

  • Right of access: request a copy of the personal data we hold about you - GET /gdpr/export
  • Right to rectification: request correction of inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten"): request deletion of your account and all associated data - DELETE /gdpr/erase. For full account deletion: DELETE /account/delete.
  • Right to restriction: request that we restrict the processing of your data in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.

Rights that affect your whole organization - erasure, consent withdrawal, and changing the retention period - require a Microsoft 365 administrator, because a Sentsai account belongs to the tenant rather than to an individual and those actions apply to everyone in it. Access and data export are available to any signed-in user. To exercise any of these rights, use the self-service API endpoints above or contact privacy@sentsai.com. We will respond within 30 days. We may need to verify your identity before processing certain requests.

To exercise rights on behalf of your employees (as data controller), use the same self-service endpoints with your administrator credentials, or contact us and we will assist.

10.Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration, including:

  • Encryption in transit using TLS 1.2 or higher for all traffic between your browser and Sentsai and between Sentsai and third-party services; internal component traffic runs on a private network that is not reachable from the internet;
  • Field-level encryption at rest (Fernet: AES-128-CBC with HMAC-SHA256 authentication) for scan findings and generated reports - the columns containing your employees' personal data. Account profile fields and audit-log entries are protected by strict access controls, tenant isolation, and automated anonymization rather than field-level encryption;
  • Strict row-level access controls ensuring each organization can only access its own data;
  • Comprehensive audit logging of all access to personal data;
  • Automatic deletion of scan data after the configured retention period;
  • Vulnerability management, dependency patching, and regular security reviews;
  • A written confidentiality agreement for any personnel granted access to personal data, before that access is granted. Sentsai currently has no employees or contractors with such access.

If you discover a security vulnerability, please report it responsibly to security@sentsai.com.

Data breach notification. Despite these measures, if a personal data breach occurs we act in line with applicable data protection law. Where we process data on behalf of a customer (as processor), we notify that customer without undue delay and in any event within 72 hours of becoming aware of the breach, so they can meet their own notification duties (see our Data Processing Agreement, clause 9). Where we act as controller of the affected data (for example, account administrator details), we notify affected individuals and the relevant supervisory authority where required by law, without undue delay. In all cases we maintain an internal record of personal data breaches - their nature, effect, and the remedial action taken - as required by Article 33(5) GDPR.

11.Cookies

We use only strictly necessary session cookies to maintain your authenticated session. These cookies are:

  • Set as httpOnly - not accessible to JavaScript running on the page;
  • Set as Secure - transmitted only over HTTPS;
  • Scoped to our domain and not shared with third parties.

We do not use tracking cookies, advertising cookies, or analytics cookies. No cookie consent banner is required under applicable law for strictly necessary functional cookies.

12.Contact and Complaints

For privacy-related questions or to exercise your rights, contact our Data Protection contact:

Email: privacy@sentsai.com

If you are not satisfied with our response, you have the right to lodge a complaint with your data protection supervisory authority:

  • Canada (federal / PIPEDA): Office of the Privacy Commissioner of Canada - priv.gc.ca
  • Quebec (Law 25): Commission d'accès à l'information - cai.quebec.gouv.qc.ca
  • California (CCPA/CPRA): California Privacy Protection Agency - cppa.ca.gov
  • EU: The supervisory authority in the EU member state where you reside or work.
  • UK: Information Commissioner's Office (ICO) - ico.org.uk