Privacy Policy
This Privacy Policy explains how AccurDigital ("we", "us", "our") collects, uses, and protects personal data for our public website and our SaaS products (including transactable offers listed on Microsoft Commercial Marketplace).
Effective date: 1 - 11 - 2025
1) Who we are & roles
Customer (Controller): The legal entity that acquires and uses our SaaS and determines the purposes of processing within its environment.
AccurDigital (Processor/Controller): We generally act as a processor of Customer Data inside the subscribed workspace and as a controller for our own business operations (e.g., billing records we receive from Microsoft, product telemetry, support).
Microsoft (Independent Controller): Microsoft processes data to enable Marketplace transactions and access. Microsoft’s privacy statement applies separately.
2) Data we collect
From Microsoft Marketplace (at purchase/fulfillment): Subscriber/company name, contact name, business email, Azure subscription/tenant identifiers, plan/SKU, quantity, region, and transaction or metering information that Microsoft shares with us to provision and support the offer.
From website visitors and users of our apps: account details (name, work email), authentication and authorization data, product usage and telemetry (feature use, error logs, performance metrics, device/browser metadata, and IP for security), support communications (tickets, attachments, call/chat transcripts), and configuration/content uploaded by the Customer (e.g., asset hierarchies, inspection data, documents). We do not intentionally collect sensitive categories unless provided by the Customer.
3) Purposes of processing
- Provisioning, activation, license/metering, and entitlement management for Marketplace purchases.
- Authentication and authorization for access control in our applications (no specific identity provider required).
- Operating and improving the service (reliability, performance, UX), security monitoring, and abuse prevention.
- Customer support and incident response.
- Compliance with law and contractual obligations.
4) Legal bases (GDPR/EU/UK)
Contract necessity to deliver the subscribed SaaS; legitimate interests for service security and improvement; legal obligation for recordkeeping and compliance; and consent where required (e.g., optional communications).
5) Sharing & recipients
Sub‑processors: Microsoft Azure (regions selected by the Customer) and limited service providers for logging/monitoring, email/ticketing, and support tooling—each governed by DPAs.
Microsoft: Acts as a separate controller for Marketplace commerce; we may receive customer information from Microsoft to fulfill and support the offer.
Professional services/partners (optional): If engaged by the Customer, access is limited and governed by the services agreement. We do not sell personal data.
6) International transfers & residency
We support hosting in Azure regions appropriate to the Customer (e.g., EU, UAE, or other available regions). Data may be processed in and transferred to countries where we or our sub‑processors operate, with appropriate safeguards (e.g., SCCs) when required. Customers can request region options during onboarding.
7) Security
We apply administrative, technical, and physical controls including role‑based access, encryption in transit and at rest, environment segregation, backup/retention policies, audit logging, and vulnerability management. Customers can configure MFA and least‑privilege roles within their environment. We can provide a current Security Overview or certifications under NDA upon request.
8) Retention
- Customer Data in the SaaS: retained for the subscription term and deleted or returned within [30–90 days] after termination, per contract.
- Operational records/telemetry: kept for [up to 13 months] unless longer is required for security, audit, or legal obligations.
- Support records: kept for [up to 3 years] from ticket closure unless law requires longer.
9) Individual rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, or portability. Where we act as a processor, we will forward requests to the Customer (controller) and support fulfillment.
10) Customer responsibilities
Customers are responsible for configuring identity, roles, and data retention; providing a lawful basis for any personal data inserted into business content; and honoring data subject requests within their organization.
11) Children
Our services are not intended for children under 16 and we do not knowingly collect their data.
12) Cookies
Our web apps use strictly necessary cookies (session, security) and, where enabled by the Customer, analytics/telemetry to improve reliability and performance. You can control non‑essential cookies where presented.
13) Third‑party links
Our apps may link to Microsoft or other third parties (e.g., documentation). Their policies apply to their properties.
14) Changes
We may update this Policy to reflect operational, legal, or regulatory changes. Material changes will be notified via product banner, email to Customer admins, or release notes. The effective date is shown at the top of this page.
15) Contact
AccurDigital – PrivacyEmail: privacy@accurdigital.com
Registered office: [Accur Digital, The 47 Building, N' 90th St 5th Settlement, New Cairo 1, Cairo, Egypt]