Tenaxis/Privacy Policy

Privacy Policy - Tenaxis

Effective date: 8 June 2026
Version: 1.0


1. Introduction

This Privacy Policy describes how 4ATE90 B.V., trading as Tenaxis ("Tenaxis", "we", "us", "our"), registered with the Dutch Chamber of Commerce (KvK) under number 87875160, processes personal data when you visit our website, create an account, or use the Tenaxis platform ("Service").

We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any other applicable data protection legislation.

If you have questions about this Policy, contact us at privacy@tenaxis.nl.


2. Who is this Policy for?

This Policy applies to:

  • Administrators and account users – individuals who register for and manage a Tenaxis account on behalf of their organisation.
  • Website visitors – individuals who visit tenaxis.io or related pages.

Note for end-users of customer organisations: If your employer or another organisation uses Tenaxis to manage its Microsoft 365 environment, that organisation is the controller of your personal data (e.g. your name, email address) within the Service. Please refer to your employer's privacy notice. Tenaxis processes such data as a processor on behalf of the customer organisation and is bound by the Data Processing Agreement with that organisation.


3. Personal Data We Collect

3.1 Account and Registration Data

When you sign up for Tenaxis via Microsoft OAuth2, we receive from Microsoft:

DataPurpose
Full name (displayName)Identify the user in the admin interface
Work email / UPN (userPrincipalName)Authentication and communication
Microsoft Object ID (userId)Link your Microsoft identity to your Tenaxis account
Microsoft Tenant IDAssociate your account with your organisation's Microsoft 365 tenant

3.2 Usage Data

We collect information about how you use the Service, including:

  • Pages visited and features used within the platform
  • Actions performed (e.g. sites created, policies applied, reports generated)
  • Timestamps and session identifiers
  • IP address, browser type and operating system

3.3 Microsoft 365 Data (via Graph API)

With your organisation's consent, the Service reads and processes Microsoft 365 data, including:

  • SharePoint site metadata (name, URL, status, sharing settings)
  • Microsoft Teams metadata
  • Group and team membership (display names, UPNs, roles)
  • User account status (accountEnabled)
  • SharePoint permissions and sharing links

This data is processed to provide governance, risk-scoring and access management features on behalf of your organisation (as processor).

3.4 Payment Data

Billing is handled by Stripe. Tenaxis does not store full card details. We receive from Stripe: subscription plan, billing status, and anonymised payment confirmation.

3.5 Communication Data

If you contact us by email or support channels, we store your contact details and the content of the communication.


4. Legal Bases for Processing

We process personal data on the following legal bases under the GDPR:

Processing activityLegal basis
Creating and managing your Tenaxis accountPerformance of a contract (Art. 6(1)(b))
Providing the Service and syncing Microsoft 365 dataPerformance of a contract (Art. 6(1)(b))
Billing and payment processingPerformance of a contract (Art. 6(1)(b))
Sending service-related notifications and emailsPerformance of a contract (Art. 6(1)(b))
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f))
Product analytics and improving the ServiceLegitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Marketing communications (with consent)Consent (Art. 6(1)(a))

5. How We Use Your Personal Data

We use your personal data to:

  1. Provide and operate the Service – authenticate you, connect your Microsoft 365 tenant, and deliver the governance features.
  2. Send service communications – transactional emails such as access review invitations, lifecycle renewal notices, and security alerts.
  3. Billing and account management – process subscriptions, send invoices, and manage plan changes.
  4. Improve the Service – analyse usage patterns to identify bugs and develop new features. Analytics data is aggregated and anonymised where possible.
  5. Security and compliance – detect and prevent abuse, respond to security incidents, and fulfil legal obligations.
  6. Support – respond to enquiries and resolve issues.

6. Sharing Personal Data

We do not sell your personal data. We share it only as follows:

RecipientLocationSafeguardPurposeBasis
MicrosoftUSA / EEASCCs + adequacy decisionOAuth2 authentication and Graph API callsContract necessity
StripeUSASCCsPayment processingContract necessity
VercelUSA (data in EEA)SCCsWeb application hostingData processing agreement
RailwayUSA (data in EEA)SCCsWorker / background job hostingData processing agreement
NeonUSA (data in EEA)SCCsDatabase hostingData processing agreement
Redis / BullMQ providerUSA / EEASCCsJob queue for background processingData processing agreement
ResendUSASCCsTransactional emailsData processing agreement
ImprovMXUSASCCsInbound email forwardingData processing agreement
Analytics toolsEEA-Aggregated usage analyticsLegitimate interests (anonymised)
Legal / regulatory authorities--Where required by lawLegal obligation

All third-party processors are required to maintain adequate data protection measures and are contractually bound by equivalent obligations.


7. International Data Transfers

Tenaxis is based in the Netherlands and operates within the European Economic Area ("EEA"). Where personal data is transferred outside the EEA (for example, to US-based sub-processors), we ensure adequate safeguards are in place, such as the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision.


8. Data Retention

CategoryRetention period
Account and identity dataDuration of the account + 90 days after deletion
Microsoft 365 governance dataDuration of active Subscription + 90 days
Audit logs2 years
Payment records7 years (statutory obligation)
Support communications2 years
Website analytics13 months

After the retention period, data is securely deleted or irreversibly anonymised.


9. Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access – request a copy of the personal data we hold about you.
  • Right to rectification – request correction of inaccurate or incomplete data.
  • Right to erasure – request deletion of your data, subject to legal retention obligations.
  • Right to restriction – request that we limit processing in certain circumstances.
  • Right to data portability – receive your data in a structured, machine-readable format.
  • Right to object – object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent – where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, email privacy@tenaxis.nl. We will respond within 30 days (extendable by 2 months for complex requests). We may verify your identity before fulfilling a request.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl or with the supervisory authority in your country of residence.


10. Security

We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration or destruction, including:

  • Encryption in transit (TLS) and at rest (AES-256-GCM)
  • Access controls and role-based permissions
  • Refresh tokens encrypted with AES-256-GCM before storage
  • Session tokens signed with HMAC (HS256)
  • Monitoring and alerting for anomalous activity

Despite these measures, no system is completely secure. If you discover a security vulnerability, please disclose it responsibly to security@tenaxis.nl.


11. Cookies and Tracking

The Tenaxis web application uses session cookies (HTTP-only, Secure) for authentication. We do not use advertising or cross-site tracking cookies. Website analytics may use first-party cookies with a retention period of 13 months.

You can manage cookies through your browser settings; disabling session cookies will prevent you from using the authenticated application.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least 14 days before the change takes effect. We encourage you to review this Policy periodically.


13. Contact

Data Controller:
4ATE90 B.V., trading as Tenaxis
Breda, Netherlands
KvK: 87875160

TopicAddress
Privacy & data protectionprivacy@tenaxis.nl
Security disclosuressecurity@tenaxis.nl
Technical supportsupport@tenaxis.nl
Legal & contractslegal@tenaxis.nl