Data Processing Addendum
Last updated 2026-09-08
This Data Processing Addendum (the "DPA") forms part of the Terms of Service between LogiSam Ltd ("LogiSam", "Processor") and the customer identified in the Service ("Customer", "Controller") governing use of the Tenant Storage Optimizer (the "Service"). In the event of a conflict, this DPA controls with respect to Personal Data.
1. Definitions
"Personal Data", "Data Subject", "Controller", "Processor", "Sub-processor", "processing" have the meanings given in the UK GDPR and Regulation (EU) 2016/679 ("EU GDPR"). "Customer Data" means data derived from Customer's Microsoft 365 tenant and processed by the Service on Customer's behalf.
2. Roles
Customer is the Controller of Personal Data contained in Customer Data. LogiSam is the Processor. Where LogiSam acts as Controller of Personal Data about its own users of the Service (e.g. authentication metadata), the Privacy Policy applies to that processing.
3. Nature and purpose of processing
- Subject matter
- Storage-audit and reporting of Customer's Microsoft 365 tenant.
- Duration
- For the term of the underlying Service subscription, plus a 30-day grace period for exports.
- Nature
- Reading metadata via Microsoft Graph; producing recommendations and reports; storing scan history and derived artefacts.
- Purpose
- To enable Customer to identify storage waste, reclaim opportunities, and inactive content in its Microsoft 365 tenant.
- Categories of Data Subjects
- Customer's users (name, email, group memberships), Customer's administrators (as Service users).
- Categories of Personal Data
- Directory metadata (name, email, principal name, object id), site + drive ownership, activity dates. No file contents are ever read.
- Special categories
- None processed by design.
4. Processor obligations
LogiSam:
- Processes Personal Data only on Customer's documented instructions, including with regard to transfers, unless required by law.
- Ensures persons authorised to process Personal Data are bound by confidentiality.
- Implements appropriate technical and organisational measures (see §7).
- Assists Customer with data-subject requests (see §8).
- Assists Customer with data-protection impact assessments and prior consultations, taking into account the nature of processing.
- Notifies Customer without undue delay of a Personal Data Breach (see §9).
- At Customer's choice, deletes or returns Personal Data on termination.
- Makes available all information necessary to demonstrate compliance, and allows for reasonable audits.
5. Sub-processors
Customer authorises LogiSam to engage the following Sub-processors:
- Microsoft Azure (UK South)
- Hosting: App Service, SQL Database, Blob Storage.
- Microsoft Graph
- Read-only data source for tenant metadata.
- Stripe
- Payment processing for direct-billed customers.
- Microsoft Commercial Marketplace
- Subscription lifecycle for Marketplace-billed customers.
- Transactional email provider
- The relay configured under SmtpSetting (default: Postmark or SendGrid).
LogiSam will notify Customer at least 30 days before adding a new Sub-processor. Customer may object on reasonable data-protection grounds, in which case the parties will discuss in good faith.
6. International transfers
Where Personal Data is transferred outside the UK / EEA, the parties rely on:
- The UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses (SCCs), or
- The EU SCCs 2021/914 Module 2 (controller to processor) or Module 3 (processor to processor), as applicable.
By default, no Personal Data is transferred outside the UK South Azure region unless required by a Sub-processor above. Self-hosted MSP customers pick their own region.
7. Security measures
- TLS 1.2+ for all data in transit; HTTPS-only.
- Encryption at rest for the database (Azure SQL TDE) and all Blob artefacts (Azure SSE).
- AES-256-GCM envelope encryption of application secrets and MFA seeds (APP_DATA_KEY).
- Principle-of-least-privilege access controls for LogiSam personnel; MFA required for administrative access.
- Only READ Microsoft Graph scopes are ever requested from Customer.
- Regular vulnerability scans of the container images and dependency graph.
- Structured audit logging retained 24 months.
- Incident-response playbook with named on-call rotation.
8. Data-subject rights
Where a Data Subject exercises rights under the UK / EU GDPR against Customer, LogiSam will assist Customer to respond, at Customer's cost, by providing tools, exports, or manual intervention as required. Requests received directly by LogiSam will be routed to Customer without response.
9. Personal Data Breach
LogiSam will notify Customer without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data Breach affecting Customer Data. Notification will include the nature of the breach, approximate number of records affected, likely consequences, and mitigation steps taken or proposed.
10. Return or deletion
On termination of the Service, LogiSam will, at Customer's choice, either delete or return all Customer Data. Exports remain available for a 30-day grace period, after which they are permanently deleted from Blob storage. Backups follow the underlying cloud-provider retention (30 days).
11. Audits
LogiSam makes available to Customer, on reasonable request, the information necessary to demonstrate compliance with this DPA, including summaries of penetration-test findings and Azure infrastructure certifications. On-site audits are available for Enterprise + MSP customers on 60 days' notice, no more than once per year, at Customer's cost.
12. Term
This DPA is effective from the date Customer accepts the Terms of Service and remains in force for the duration of the Service subscription, plus any post-termination retention period necessary to comply with §10.
13. Contact
Privacy and DPA matters: hello@logisam.com.
