
This policy explains how TheLogic IT Solutions (“we”, “us”) collects and uses personal data when you use the 365 Licence Audit service at 365licenceaudit.co.uk (the “Service”). We are the data controller for that data under the UK GDPR and the Data Protection Act 2018.
TheLogic IT Solutions, Munro House, Quarrywood Court, Livingston, EH54 6AX, United Kingdom. Contact: [email protected] · +44 (0) 1506 533 100.
The Service produces a read-only Microsoft 365 licence health check. With the consent of your tenant’s Global Administrator, we read licensing and usage information from your Microsoft 365 tenant, generate a report showing potential savings, and present it to you. The Service does not change any setting in your tenant and cannot read mailbox contents, files, or messages.
a. Details you give us. When you start an audit you provide your firm name, your name, and a contact email address.
b. Microsoft 365 tenant data. After your Global Administrator grants consent, we read the following from your tenant using Microsoft Graph, on a read-only basis only:
We request these four permissions and nothing else. We do not request, and cannot access, the contents of mailboxes, files, chats, or any other user content.
c. Technical and anti-abuse data. To protect the Service from automated abuse we use Cloudflare Turnstile, which processes limited technical signals (including your IP address) on our behalf. Our hosting and content-delivery provider, Cloudflare, processes connection metadata such as IP address for security and delivery. We store a small amount of data in your browser’s session storage to carry your request between pages; it is cleared when you close the tab.
Audit results derived from your tenant are deleted once you download your report, and in any event are not retained beyond a short processing window. The contact details you submit are retained so we can deliver your report and, where relevant, follow up, until you unsubscribe or ask us to delete them. We will not keep personal data for longer than necessary for the purposes above.
We do not sell your data. We share it only with service providers acting on our instructions:
We may also disclose data where required by law.
Some of our providers may process data outside the UK. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
Under UK data protection law you have the right to access, correct, erase, restrict, or object to our processing of your personal data, and the right to data portability. To exercise any of these, email [email protected]. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk) if you are unhappy with how we have handled your data.
We use the official Microsoft consent flow — we never see or handle your Microsoft credentials. Data is transmitted over encrypted connections (HTTPS), and access to audit data is restricted and short-lived. No online service can be guaranteed completely secure, but we take reasonable measures to protect your information.
We do not use advertising or tracking cookies. Cloudflare Turnstile and our hosting may set strictly necessary cookies/tokens to operate and secure the Service. We use your browser’s session storage only to pass your request between the sign-up and results pages.
We may update this policy from time to time. The “last updated” date above shows the current version.
Questions about this policy or your data: [email protected].