Privacy Policy - Tenaxis
Effective date: 8 June 2026
Version: 1.0
1. Introduction
This Privacy Policy describes how 4ATE90 B.V., trading as Tenaxis ("Tenaxis", "we", "us", "our"), registered with the Dutch Chamber of Commerce (KvK) under number 87875160, processes personal data when you visit our website, create an account, or use the Tenaxis platform ("Service").
We are committed to protecting your privacy and complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and any other applicable data protection legislation.
If you have questions about this Policy, contact us at privacy@tenaxis.nl.
2. Who is this Policy for?
This Policy applies to:
- Administrators and account users – individuals who register for and manage a Tenaxis account on behalf of their organisation.
- Website visitors – individuals who visit tenaxis.io or related pages.
Note for end-users of customer organisations: If your employer or another organisation uses Tenaxis to manage its Microsoft 365 environment, that organisation is the controller of your personal data (e.g. your name, email address) within the Service. Please refer to your employer's privacy notice. Tenaxis processes such data as a processor on behalf of the customer organisation and is bound by the Data Processing Agreement with that organisation.
3. Personal Data We Collect
3.1 Account and Registration Data
When you sign up for Tenaxis via Microsoft OAuth2, we receive from Microsoft:
| Data | Purpose |
|---|---|
| Full name (displayName) | Identify the user in the admin interface |
| Work email / UPN (userPrincipalName) | Authentication and communication |
| Microsoft Object ID (userId) | Link your Microsoft identity to your Tenaxis account |
| Microsoft Tenant ID | Associate your account with your organisation's Microsoft 365 tenant |
3.2 Usage Data
We collect information about how you use the Service, including:
- Pages visited and features used within the platform
- Actions performed (e.g. sites created, policies applied, reports generated)
- Timestamps and session identifiers
- IP address, browser type and operating system
3.3 Microsoft 365 Data (via Graph API)
With your organisation's consent, the Service reads and processes Microsoft 365 data, including:
- SharePoint site metadata (name, URL, status, sharing settings)
- Microsoft Teams metadata
- Group and team membership (display names, UPNs, roles)
- User account status (
accountEnabled) - SharePoint permissions and sharing links
This data is processed to provide governance, risk-scoring and access management features on behalf of your organisation (as processor).
3.4 Payment Data
Billing is handled by Stripe. Tenaxis does not store full card details. We receive from Stripe: subscription plan, billing status, and anonymised payment confirmation.
3.5 Communication Data
If you contact us by email or support channels, we store your contact details and the content of the communication.
4. Legal Bases for Processing
We process personal data on the following legal bases under the GDPR:
| Processing activity | Legal basis |
|---|---|
| Creating and managing your Tenaxis account | Performance of a contract (Art. 6(1)(b)) |
| Providing the Service and syncing Microsoft 365 data | Performance of a contract (Art. 6(1)(b)) |
| Billing and payment processing | Performance of a contract (Art. 6(1)(b)) |
| Sending service-related notifications and emails | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and improving the Service | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (with consent) | Consent (Art. 6(1)(a)) |
5. How We Use Your Personal Data
We use your personal data to:
- Provide and operate the Service – authenticate you, connect your Microsoft 365 tenant, and deliver the governance features.
- Send service communications – transactional emails such as access review invitations, lifecycle renewal notices, and security alerts.
- Billing and account management – process subscriptions, send invoices, and manage plan changes.
- Improve the Service – analyse usage patterns to identify bugs and develop new features. Analytics data is aggregated and anonymised where possible.
- Security and compliance – detect and prevent abuse, respond to security incidents, and fulfil legal obligations.
- Support – respond to enquiries and resolve issues.
6. Sharing Personal Data
We do not sell your personal data. We share it only as follows:
| Recipient | Location | Safeguard | Purpose | Basis |
|---|---|---|---|---|
| Microsoft | USA / EEA | SCCs + adequacy decision | OAuth2 authentication and Graph API calls | Contract necessity |
| Stripe | USA | SCCs | Payment processing | Contract necessity |
| Vercel | USA (data in EEA) | SCCs | Web application hosting | Data processing agreement |
| Railway | USA (data in EEA) | SCCs | Worker / background job hosting | Data processing agreement |
| Neon | USA (data in EEA) | SCCs | Database hosting | Data processing agreement |
| Redis / BullMQ provider | USA / EEA | SCCs | Job queue for background processing | Data processing agreement |
| Resend | USA | SCCs | Transactional emails | Data processing agreement |
| ImprovMX | USA | SCCs | Inbound email forwarding | Data processing agreement |
| Analytics tools | EEA | - | Aggregated usage analytics | Legitimate interests (anonymised) |
| Legal / regulatory authorities | - | - | Where required by law | Legal obligation |
All third-party processors are required to maintain adequate data protection measures and are contractually bound by equivalent obligations.
7. International Data Transfers
Tenaxis is based in the Netherlands and operates within the European Economic Area ("EEA"). Where personal data is transferred outside the EEA (for example, to US-based sub-processors), we ensure adequate safeguards are in place, such as the European Commission's Standard Contractual Clauses (SCCs) or an adequacy decision.
8. Data Retention
| Category | Retention period |
|---|---|
| Account and identity data | Duration of the account + 90 days after deletion |
| Microsoft 365 governance data | Duration of active Subscription + 90 days |
| Audit logs | 2 years |
| Payment records | 7 years (statutory obligation) |
| Support communications | 2 years |
| Website analytics | 13 months |
After the retention period, data is securely deleted or irreversibly anonymised.
9. Your Rights
Under the GDPR you have the following rights regarding your personal data:
- Right of access – request a copy of the personal data we hold about you.
- Right to rectification – request correction of inaccurate or incomplete data.
- Right to erasure – request deletion of your data, subject to legal retention obligations.
- Right to restriction – request that we limit processing in certain circumstances.
- Right to data portability – receive your data in a structured, machine-readable format.
- Right to object – object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent – where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email privacy@tenaxis.nl. We will respond within 30 days (extendable by 2 months for complex requests). We may verify your identity before fulfilling a request.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl or with the supervisory authority in your country of residence.
10. Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration or destruction, including:
- Encryption in transit (TLS) and at rest (AES-256-GCM)
- Access controls and role-based permissions
- Refresh tokens encrypted with AES-256-GCM before storage
- Session tokens signed with HMAC (HS256)
- Monitoring and alerting for anomalous activity
Despite these measures, no system is completely secure. If you discover a security vulnerability, please disclose it responsibly to security@tenaxis.nl.
11. Cookies and Tracking
The Tenaxis web application uses session cookies (HTTP-only, Secure) for authentication. We do not use advertising or cross-site tracking cookies. Website analytics may use first-party cookies with a retention period of 13 months.
You can manage cookies through your browser settings; disabling session cookies will prevent you from using the authenticated application.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least 14 days before the change takes effect. We encourage you to review this Policy periodically.
13. Contact
Data Controller:
4ATE90 B.V., trading as Tenaxis
Breda, Netherlands
KvK: 87875160
| Topic | Address |
|---|---|
| Privacy & data protection | privacy@tenaxis.nl |
| Security disclosures | security@tenaxis.nl |
| Technical support | support@tenaxis.nl |
| Legal & contracts | legal@tenaxis.nl |