Legal

Privacy policy

Draft, not in force. This policy is being reviewed. It has not been checked by a lawyer; names in brackets are still to be filled in.

This policy explains what [legal entity, address] keeps when you use 365 Rewind, why, and for how long. The short version: we keep what the service needs to work and nothing to sell or track.

What we keep

  • Your account: name, work email address, organization, workspace membership and role, and a hash of your password if you set one.
  • Tenant records: the name and domain of each tenant you connect, and the computers running the app, as reported by the app when you connect it.
  • Hosted backups: the configuration of your tenant, encrypted on your computer before upload and stored encrypted. Configuration can include names of people and groups where settings refer to them, for example a policy that excludes a group.
  • Local vault tenants: when each backup ran, whether it succeeded, counts of items and the codes of any errors, with the tenant's name and domain and the names of the computer and the app that ran it. No settings and no names of items.
  • Activity: sign-ins, connections, backups, restores and changes to settings in your workspace, with who did them and when, so your team can see who did what. The activity log does not record the address a request came from.

What we never keep

Passwords, tokens, secrets or certificates for your Microsoft 365 tenant; mail, files, chats or other user content; payment card numbers; the key of a local vault.

This website

No analytics, no advertising, no tracking cookies and nothing loaded from other companies. The portal sets one cookie when you sign in, to keep you signed in; it ends after at most twelve hours.

Our access

The operator of the service manages it from a console that shows account, workspace, tenant and plan details and activity records, never the contents of your backups or anything in your tenant.

Why we use it

To provide the service you signed up for, to send the emails the service needs (sign-in codes, invoices, notices about your workspace), and to meet legal and accounting duties. [Name the legal bases where GDPR applies.]

Who else sees it

[Hosting provider, location of the servers, email relay.] We share nothing else, sell nothing, and disclose data to authorities only where the law requires it.

How long

Each tenant's backups are kept for its retention setting, 365 days unless an owner chooses 7 to 3,650 days; the newest complete backup is kept while the tenant exists, and a plan's history only hides older backups. Hosted backups are deleted 90 days after a plan ends. The activity log is kept for 400 days, restore plans for 400 days after their last change. A workspace is closed on request, and its records are deleted then, except invoices, which accounting law requires us to keep; the server's encrypted nightly archives hold deleted data for up to eight more weeks.

Your rights

You can ask to see, correct, export or delete the personal data we hold about you. Write to privacy@glacierpointtech.com.