Legal

Data Processing Addendum

Last updated 2026-09-08

Working template. This document is drafted from the product's technical facts so a customer's counsel can review it efficiently. It is not a substitute for legal review under your jurisdiction. Contact hello@logisam.com for the counter-signed final.

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between LogiSam Ltd ("LogiSam", "Processor") and the customer identified in the Service ("Customer", "Controller") governing use of the Tenant Storage Optimizer (the "Service"). In the event of a conflict, this DPA controls with respect to Personal Data.

Countersigned copies are available on request from hello@logisam.com. For customers who require the LogiSam-signed original, we return it within two working days.

1. Definitions

"Personal Data", "Data Subject", "Controller", "Processor", "Sub-processor", "processing" have the meanings given in the UK GDPR and Regulation (EU) 2016/679 ("EU GDPR"). "Customer Data" means data derived from Customer's Microsoft 365 tenant and processed by the Service on Customer's behalf.

2. Roles

Customer is the Controller of Personal Data contained in Customer Data. LogiSam is the Processor. Where LogiSam acts as Controller of Personal Data about its own users of the Service (e.g. authentication metadata), the Privacy Policy applies to that processing.

3. Nature and purpose of processing

Subject matter
Storage-audit and reporting of Customer's Microsoft 365 tenant.
Duration
For the term of the underlying Service subscription, plus a 30-day grace period for exports.
Nature
Reading metadata via Microsoft Graph; producing recommendations and reports; storing scan history and derived artefacts.
Purpose
To enable Customer to identify storage waste, reclaim opportunities, and inactive content in its Microsoft 365 tenant.
Categories of Data Subjects
Customer's users (name, email, group memberships), Customer's administrators (as Service users).
Categories of Personal Data
Directory metadata (name, email, principal name, object id), site + drive ownership, activity dates. No file contents are ever read.
Special categories
None processed by design.

4. Processor obligations

LogiSam:

  • Processes Personal Data only on Customer's documented instructions, including with regard to transfers, unless required by law.
  • Ensures persons authorised to process Personal Data are bound by confidentiality.
  • Implements appropriate technical and organisational measures (see §7).
  • Assists Customer with data-subject requests (see §8).
  • Assists Customer with data-protection impact assessments and prior consultations, taking into account the nature of processing.
  • Notifies Customer without undue delay of a Personal Data Breach (see §9).
  • At Customer's choice, deletes or returns Personal Data on termination.
  • Makes available all information necessary to demonstrate compliance, and allows for reasonable audits.

5. Sub-processors

Customer authorises LogiSam to engage the following Sub-processors:

Microsoft Azure (UK South)
Hosting: App Service, SQL Database, Blob Storage.
Microsoft Graph
Read-only data source for tenant metadata.
Stripe
Payment processing for direct-billed customers.
Microsoft Commercial Marketplace
Subscription lifecycle for Marketplace-billed customers.
Transactional email provider
The relay configured under SmtpSetting (default: Postmark or SendGrid).

LogiSam will notify Customer at least 30 days before adding a new Sub-processor. Customer may object on reasonable data-protection grounds, in which case the parties will discuss in good faith.

6. International transfers

Where Personal Data is transferred outside the UK / EEA, the parties rely on:

  • The UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses (SCCs), or
  • The EU SCCs 2021/914 Module 2 (controller to processor) or Module 3 (processor to processor), as applicable.

By default, no Personal Data is transferred outside the UK South Azure region unless required by a Sub-processor above. Self-hosted MSP customers pick their own region.

7. Security measures

  • TLS 1.2+ for all data in transit; HTTPS-only.
  • Encryption at rest for the database (Azure SQL TDE) and all Blob artefacts (Azure SSE).
  • AES-256-GCM envelope encryption of application secrets and MFA seeds (APP_DATA_KEY).
  • Principle-of-least-privilege access controls for LogiSam personnel; MFA required for administrative access.
  • Only READ Microsoft Graph scopes are ever requested from Customer.
  • Regular vulnerability scans of the container images and dependency graph.
  • Structured audit logging retained 24 months.
  • Incident-response playbook with named on-call rotation.

8. Data-subject rights

Where a Data Subject exercises rights under the UK / EU GDPR against Customer, LogiSam will assist Customer to respond, at Customer's cost, by providing tools, exports, or manual intervention as required. Requests received directly by LogiSam will be routed to Customer without response.

9. Personal Data Breach

LogiSam will notify Customer without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data Breach affecting Customer Data. Notification will include the nature of the breach, approximate number of records affected, likely consequences, and mitigation steps taken or proposed.

10. Return or deletion

On termination of the Service, LogiSam will, at Customer's choice, either delete or return all Customer Data. Exports remain available for a 30-day grace period, after which they are permanently deleted from Blob storage. Backups follow the underlying cloud-provider retention (30 days).

11. Audits

LogiSam makes available to Customer, on reasonable request, the information necessary to demonstrate compliance with this DPA, including summaries of penetration-test findings and Azure infrastructure certifications. On-site audits are available for Enterprise + MSP customers on 60 days' notice, no more than once per year, at Customer's cost.

12. Term

This DPA is effective from the date Customer accepts the Terms of Service and remains in force for the duration of the Service subscription, plus any post-termination retention period necessary to comply with §10.

13. Contact

Privacy and DPA matters: hello@logisam.com.

Related documents