Privacy Policy
Last updated 2026-09-08
This Privacy Policy explains how LogiSam Ltd ("LogiSam", "we") processes personal data through the Tenant Storage Optimizer (the "Service"). It applies to users of the Service and to the Microsoft 365 tenant data those users cause the Service to process.
1. Who we are
LogiSam Ltd, a company registered in England & Wales. Contact: hello@logisam.com.
2. What data we process
Two distinct categories, treated differently:
a. Account data (about you as a user of the Service)
- Identity
- Display name, email address, Microsoft Entra object id and tenant id — collected on first sign-in via Microsoft SSO.
- Session data
- JWT session cookie, browser + IP for security event logging, MFA state for platform admins.
- Workspace membership
- Which workspace(s) you belong to and your role in each.
- Audit trail
- Actions you take inside the Service (scans triggered, exports generated, invitations sent).
b. Customer Data (about your Microsoft 365 tenant)
- Site + drive metadata
- SharePoint site titles, URLs, sizes, activity dates. OneDrive account owners and quotas. Never file contents.
- User metadata
- Display names, principal names, disabled/deleted state — used to detect departed-user OneDrives and no-owner sites.
- Mailbox metadata
- Exchange mailbox display names, sizes, activity dates.
- Recommendations
- Derived findings — no-owner sites, inactive OneDrives, oversized files, version bloat.
The Service never reads the CONTENTS of files, emails, or messages. All Graph scopes are strictly READ-only.
3. Legal basis
- Account data: performance of contract (Article 6(1)(b) UK/EU GDPR) — we need it to provide you the Service.
- Customer Data: legitimate interest of the customer organisation (Article 6(1)(f)) — you have chosen to have your tenant audited by us.
- Analytics: legitimate interest, minimised and non-identifying.
4. How we use it
- Provide the Service — scan, analyse, and report on your Microsoft 365 tenant.
- Bill you and provide customer support.
- Protect the Service — detect abuse, honour rate limits, respond to security events.
- Comply with legal obligations.
- Improve the Service using aggregated, non-identifying usage patterns.
5. Who we share it with
We do not sell personal data. We share only with the subprocessors named below, and only to the extent necessary to deliver the Service:
- Microsoft Azure
- Hosting infrastructure — App Service, SQL, Blob Storage — in UK South by default. Customer Data is stored here.
- Microsoft Graph
- Data source. Customer Data is READ from your tenant via Graph API calls; nothing is written back.
- Google Analytics
- Aggregate marketing-site usage. No Customer Data is sent to GA; user identifiers on the marketing site are anonymised.
- Stripe
- Payment processing for direct-billed customers. Card details go to Stripe directly; we never see them.
- Microsoft Commercial Marketplace
- Subscription lifecycle for marketplace-billed customers.
- Postmark / SendGrid (or configured SMTP relay)
- Transactional email delivery.
A full, current subprocessor list is available on request. We notify customers 30 days before adding a new subprocessor.
6. Where we store it
By default, all Customer Data is stored in Microsoft's UK South Azure region. Enterprise or MSP customers on the self-hosted path store data in the region they choose for their own Azure subscription.
7. How long we keep it
- Scan results — for the life of the workspace. You may delete a scan (and all rows it produced) from the portal at any time.
- Report exports (PDF, Excel) — kept for 30 days by default, then permanently deleted.
- Audit logs — 24 months.
- Account data — for the life of your account. Delete the workspace to trigger cascade deletion, subject to a 30-day grace period.
8. Security
- All data in transit is protected by TLS 1.2 or higher.
- Secrets (Stripe API keys, SMTP passwords, TOTP secrets) are encrypted at rest with AES-256-GCM.
- Database connections are private-endpoint / firewall-restricted.
- Only strictly READ Microsoft Graph scopes are ever requested.
- Platform admins are gated by TOTP MFA + trusted-device cookies.
9. Your rights
Under the UK GDPR / EU GDPR you have rights to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Erase data (subject to lawful retention obligations).
- Restrict or object to processing.
- Portability of data you have provided.
- Lodge a complaint with the ICO (UK) or your local supervisory authority.
Requests: hello@logisam.com.
10. Cookies
The Service uses:
- Session cookies — the NextAuth session token, strictly necessary for sign-in.
- Preference cookies — active-workspace, nav-collapsed. Strictly necessary for the portal to function.
- Trusted-device cookie — platform admins only, to skip the MFA challenge on a browser you have previously MFA'd from.
- Google Analytics — marketing site only; we do not currently gate GA behind a consent banner.
11. Changes to this policy
Material changes will be notified via the portal or by email at least 30 days before they take effect.
12. Contact
hello@logisam.com or the contact form.
