Privacy Statement
Last updated: 3 August 2026 · Version 1.0
This Privacy Statement explains how Saario ("Saario", "we", "us", "our") collects, uses, shares and protects personal data when you visit saario.app, subscribe to our cyber auditing services for Microsoft 365 (the "Services"), or otherwise interact with us. We are committed to handling personal data lawfully, fairly and transparently, in accordance with the UK GDPR and the Data Protection Act 2018.
Contents
- Who is responsible for your data
- Personal data we collect
- Data from Microsoft 365 tenants
- How and why we use personal data
- Lawful bases for processing
- Who we share data with
- International transfers
- How long we keep data
- How we protect data
- Your rights
- Cookies
- Children
- Changes to this statement
- How to contact us
1. Who is responsible for your data
For personal data about our website visitors, prospective customers, customer contacts and billing contacts, Saario is the data controller.
For personal data contained in a customer's Microsoft 365 tenant that we read in order to deliver the Services, we act as a data processor on the instructions of that customer, who is the controller. If you are an employee or user of an organisation that uses Saario, that organisation decides why and how your data is processed, and its own privacy notice applies alongside this statement.
2. Personal data we collect
Information you provide to us
- Identity and contact data — name, work email address, job title, company name and telephone number when you register, request a checkup, subscribe or contact us.
- Billing data — subscription plan, billing contact and payment history. Card payments are processed directly by Stripe; we do not receive or store full card numbers.
- Communications — the content of emails, support requests and enquiry forms you send us.
Information collected automatically
- Technical data — IP address, browser type and version, operating system, device identifiers.
- Usage data — pages visited, features used, actions taken in the Services, dates and times of access.
We do not intentionally collect special category data (such as health, religious or biometric data), and ask that you do not send it to us.
3. Data from Microsoft 365 tenants
When an authorised administrator connects a Microsoft 365 tenant, the Services read security-relevant signals through the Microsoft Graph API using read-only application permissions granted through Microsoft's own consent process. Depending on the areas audited, this may include personal data such as:
- user names, email addresses, roles, licence assignments and MFA status;
- sign-in and audit log events, including times, locations, IP addresses and risk indicators;
- device names, enrollment and compliance status from Microsoft Intune;
- mailbox configuration signals such as forwarding rules (not the content of emails);
- sharing metadata for SharePoint and OneDrive, including file names, sensitivity labels and link types (not the content of files);
- Microsoft Copilot usage metadata, including which labelled files were referenced in prompts;
- Microsoft Secure Score values and security recommendations.
Read-only by design. Saario cannot change your tenant, does not read the contents of emails or documents, and never receives or stores Microsoft passwords. An administrator can revoke Saario's access at any time in Microsoft Entra ID.
4. How and why we use personal data
- Delivering the Services — running audits, calculating the Saario Score, generating reports and recommendations, and displaying results to authorised users.
- Account administration — creating and managing accounts, processing subscriptions and payments, and providing customer support.
- Security and integrity — authenticating users, preventing fraud and abuse, monitoring for unauthorised access, and maintaining audit logs.
- Service improvement — analysing how the Services are used, fixing faults, and developing features. We may create aggregated, anonymised statistics and industry benchmarks that do not identify any person, customer or tenant.
- Communications — sending service messages (such as reports, alerts, billing and security notices) and, where permitted, occasional updates about our products; you can opt out of marketing at any time.
- Legal compliance — meeting our accounting, tax and regulatory obligations and establishing or defending legal claims.
We do not sell personal data, and we do not use tenant data for advertising or to train third-party models.
5. Lawful bases for processing
| Purpose | Lawful basis |
|---|---|
| Providing the Services and managing your account | Performance of a contract |
| Processing tenant data on a customer's behalf | Processor acting on the controller's documented instructions |
| Securing and improving the Services; business communications | Legitimate interests |
| Tax, accounting and regulatory record-keeping | Legal obligation |
| Optional marketing and non-essential cookies (if any) | Consent, which you may withdraw at any time |
7. International transfers
Personal data is stored and processed primarily in the UK and European Economic Area. Where a transfer outside the UK or EEA is necessary — for example, to a sub-processor operating in the United States — we ensure appropriate safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses.
8. How long we keep data
| Category | Retention period |
|---|---|
| Tenant audit data | Duration of the subscription (to enable score trends), then deleted within 30 days of tenant disconnection or account closure |
| Account and contact data | Duration of the account, plus up to 12 months |
| Billing and transaction records | 6 years, as required for UK tax and accounting purposes |
| Support correspondence | Up to 2 years after the matter is closed |
| Aggregated, anonymised statistics | Indefinitely (not personal data) |
9. How we protect data
We apply technical and organisational measures appropriate to a security company, including encryption of data in transit and at rest, least-privilege and role-based access controls, segregation of customer data, encrypted storage of API tokens scoped to read-only access, and logging and monitoring of access to production systems. While no service can be guaranteed to be completely secure, if we become aware of a personal data breach affecting you we will notify affected customers and, where required, the Information Commissioner's Office without undue delay.
10. Your rights
Under data protection law you have rights, in certain circumstances, to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data;
- restrict or object to processing, including processing based on legitimate interests and direct marketing;
- data portability — receive data you provided in a structured, machine-readable format;
- withdraw consent at any time, where processing is based on consent.
To exercise any right, email info@saario.app. We will respond within one month. If your request concerns data we process on behalf of your organisation as a customer, we may refer the request to that organisation, as the controller of that data.
You also have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk, or with your local supervisory authority.
12. Children
The Services are designed for business use and are not directed at children. We do not knowingly collect personal data from children as customers or users of our website.
13. Changes to this statement
We may update this Privacy Statement from time to time to reflect changes in our practices, the Services or the law. The current version will always be published on this page with its "last updated" date. For material changes we will notify customers by email or an in-service notice before the change takes effect.
14. How to contact us
For any questions about this Privacy Statement or how we handle personal data, contact us at info@saario.app.