Privacy Policy — Application
Effective Date: March 20, 2026 | Version 2.0
1. Introduction & Scope
This Privacy Policy applies exclusively to the Teams Concierge App (https://app.teamsconcierge.com), a multi-tenant SaaS platform for Microsoft Teams management, automation, permission management, compliance monitoring, usage analytics and the self-service Concierge chatbot. Operated by dotCLOUD LLC (“we”, “us”, “our”).
We comply fully with the Swiss Federal Act on Data Protection (FADP/DSG) and the EU General Data Protection Regulation (GDPR) where applicable.
2. Data Controller
dotCLOUD LLC
Zürich, Switzerland
Email: contact@teamsconcierge.com
3. Data We Collect and Process
3.1 Account & Authentication Data
- Name, email, company name
- Microsoft Entra ID tenant ID, user object ID, roles
3.2 Microsoft Graph API Data (only administrative metadata)
With your explicit admin consent we process via Microsoft Graph API (application + delegated permissions):
- Users, groups, teams, channels, membership lists
- Permission settings, conditional access policies, compliance configurations
- Usage analytics & adoption reports (activity statistics, no personal content)
- Automation logs (e.g. permission changes, policy enforcement)
We never access, read or store: emails, chat messages, meeting content, files, recordings or any personal user content.
3.3 Technical, Usage & Audit Data
- IP address, browser/device info (security & functionality only)
- Feature usage, performance metrics, error logs
- Audit trail of all admin actions in the app
3.4 Payment Data
Processed exclusively by our Swiss payment partner – we never store card details.
4. Purposes of Processing
- Providing the full Teams Concierge functionality (management, automation, analytics, chatbot)
- Generating organisation-specific dashboards and reports
- Customer support, billing, account security
- Product improvement and security (anonymised analytics)
- Legal compliance and fraud prevention
5. Legal Basis
Contract performance (Art. 6(1)(b) GDPR / Art. 13 FADP), legitimate interest, and explicit consent for Graph permissions.
6. Subprocessors & Sharing
We use only the following subprocessors (all under strict Data Processing Agreements):
| Subprocessor | Purpose | Location | Safeguards |
|---|---|---|---|
| Microsoft Ireland Operations Ltd. / Azure | Graph API, hosting, authentication | Switzerland (tenant) | EU Model Clauses + Swiss adequacy |
| Development & Support Partner | Technical support & updates | Estonia | Standard Contractual Clauses + no data storage |
| Stripe Payment Provider | Billing | Switzerland | Swiss data protection law |
We never sell data. Data is only shared with authorities when legally required.
7. International Data Transfers & Storage
All customer data remains in a Microsoft tenant physically located in Switzerland. Any processing in Estonia is limited to support/development and occurs under strict contractual safeguards with no permanent storage.
8. Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & tenant data | Duration of contract + 30 days after termination | Contract |
| Audit & action logs | 12 months (or longer if required by law) | Security & compliance |
| Usage analytics (anonymised) | 24 months | Product improvement |
| Payment records | 10 years (legal requirement) | Tax law |
9. Your Rights (DSG & GDPR)
You have the right to access, rectification, erasure (“right to be forgotten”), restriction, portability, objection and withdrawal of consent. To exercise any right, simply email contact@teamsconcierge.com. We answer within 30 days (free of charge in most cases).
10. Data Security & Technical Measures
- End-to-end TLS 1.3 encryption
- Multi-factor authentication + role-based access
- Strict tenant isolation (multi-tenant architecture)
- Regular penetration tests & security audits
- Microsoft Defender for Cloud + Azure Sentinel monitoring
- Incident response plan with 72-hour notification (GDPR) / immediate under DSG
11. Cookies & Tracking
The App uses only essential session cookies and Microsoft’s secure analytics. No third-party tracking cookies.
12. Changes to this Policy
Material changes will be announced via in-app banner and email at least 30 days in advance.
13. Contact & Data Protection Officer
dotCLOUD LLC
Zürich, Switzerland
Email: contact@teamsconcierge.com
© 2026 dotCLOUD LLC — Zürich, Switzerland
