Legal

Data Processing Agreement

This DPA describes how TenantVigil processes customer data on behalf of customers when delivering the service, including processing scope, security measures, subprocessors, and customer rights.

Last updated: April 18, 2026
1

Scope and relationship to the service agreement

This Data Processing Agreement supplements the TenantVigil Terms of Service and any applicable commercial agreement between TenantVigil and the customer. It applies when TenantVigil processes personal data on the customer’s behalf in connection with the service.

To the extent of any conflict on data protection matters, this DPA controls over the general Terms unless a separate signed agreement says otherwise.

2

Subject matter, duration, and processing details

TenantVigil processes customer data for the limited purpose of providing Microsoft 365 security posture assessments, reporting, customer administration, support, and associated product operations for the duration of the customer relationship and any agreed post-termination handling period.

  • Data subjects may include customer users, administrators, employees, contractors, or other individuals whose data appears in customer-controlled Microsoft 365 evidence or account records.
  • Categories of data may include identity data, tenant metadata, configuration evidence, assessment outputs, audit history, support communications, and billing/account metadata.
3

Customer instructions and responsibilities

TenantVigil processes customer data only on documented instructions from the customer, as reflected in the service configuration, customer actions within the product, and the governing agreement, unless otherwise required by law.

The customer remains responsible for its own lawful basis for processing, notices to data subjects, security decisions inside Microsoft 365, and the accuracy of the instructions it gives to TenantVigil.

4

Security measures

TenantVigil maintains technical and organisational security measures appropriate to the nature of the service and the risks presented by the processing. These measures are intended to protect confidentiality, integrity, and availability of customer data.

  • Access controls, authentication safeguards, and least-privilege operational practices.
  • Encryption in transit and protection of sensitive stored credentials and tokens.
  • Tenant isolation controls, logging, and monitoring designed to reduce cross-tenant exposure risk.
  • Operational procedures for incident response, backups, and secure change management.
5

Subprocessors and international transfers

TenantVigil may use subprocessors to host, support, secure, or operate the service. We remain responsible for our subprocessors’ performance of the relevant processing obligations to the extent required by law and contract.

Where cross-border data transfers occur, the parties will rely on an appropriate transfer mechanism recognised under applicable law.

6

Data subject requests, incidents, and cooperation

Taking into account the nature of the processing, TenantVigil will provide reasonable assistance to help the customer respond to data subject requests and regulatory obligations where the customer cannot fulfil those obligations through the service itself.

If TenantVigil becomes aware of a confirmed personal data incident affecting customer data, we will notify the customer without undue delay and provide available information reasonably needed to support the customer’s response.

7

Return, deletion, and audits

At the end of the customer relationship, TenantVigil will handle customer data in accordance with the governing agreement, our operational retention obligations, and applicable law. Data may be returned, deleted, or retained for a limited period where needed for security, legal, billing, or dispute-resolution purposes.

Where required and appropriate, the parties may work together on reasonable information requests concerning TenantVigil’s security and data protection controls, subject to confidentiality, security, and proportionality limits.