Last updated: April 2026
Privacy Policy
TenantIQ ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard information when you use our platform.
1. Information We Collect
We collect information you provide directly and data accessed through integrations:
- Account Information — name, email, organization details provided during registration.
- Microsoft 365 Tenant Data — users, groups, licenses, security events, audit logs, mail flow metadata, and policy configurations accessed via Microsoft Graph API with your delegated consent.
- Usage Data — pages visited, features used, session duration, and interaction patterns.
- Device & Browser Data — IP address, browser type, operating system, and screen resolution.
2. How We Use Your Information
- Provide, operate, and improve the TenantIQ platform.
- Run security scans, CIS benchmark assessments, and compliance checks on your tenant data.
- Generate AI-powered insights, anomaly detection, and optimization recommendations.
- Send security alerts, notifications, and operational updates.
- Process billing and manage your subscription.
- Respond to support requests and communicate about your account.
3. Data Storage & Security
Your data is stored on Cloudflare's global edge network using:
- Cloudflare D1 (SQLite) — structured tenant data with per-organization isolation.
- Cloudflare KV — cached tokens, scores, and session data.
- Cloudflare R2 — encrypted backups and exported reports (AES-256-GCM encryption).
All data is encrypted in transit (TLS 1.3) and at rest. Each tenant's data is strictly isolated — no cross-tenant data access is possible.
4. Third-Party Services
We integrate with the following services to deliver our platform:
- Microsoft Graph API — to read and manage your M365 tenant configuration with your consent.
- Anthropic Claude — AI analysis for security anomaly detection, optimization, and compliance insights. Tenant data sent to Claude is not used to train AI models.
- Resend — transactional email delivery (alerts, notifications).
- LemonSqueezy / Microsoft AppSource — payment processing and subscription management.
We do not sell, rent, or share your data with advertisers or data brokers.
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Specifically:
- Account data — retained until account deletion is requested.
- Tenant scan results — retained per your plan's history limits.
- Backups — retained per your plan terms, then permanently deleted.
- Audit logs — retained for 12 months for compliance purposes.
Upon account deletion request (DELETE /api/account or via Settings → Account), primary stores (D1, KV, R2) are purged immediately; encrypted infrastructure backups age out within 30 days and are not restored on customer request after deletion. See DATA_DELETION.md.
6. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the following rights:
- Access / Portability —
GET /api/account/exportreturns your organization, members, and connected tenants in JSON. - Rectification — edit profile in Settings or email [email protected].
- Deletion —
DELETE /api/accountwith body{"confirm":"DELETE"}triggers the cascade above. - Restriction — limit how we process your data.
- Objection — object to processing based on legitimate interests.
To exercise rights without using the API, email [email protected]. We respond within 30 days. Sub-processors are listed at SUB_PROCESSORS.md; the DPA is at DPA.md.
7. Children's Privacy
TenantIQ is a business-to-business platform and is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notification at least 30 days before they take effect.
9. Contact Us
If you have questions about this privacy policy or our data practices, contact us:
- Email: [email protected]
- Support: tenantiq.app/support