Legal · tenantwizards.com

Privacy Policy

Last updated: September 22, 2026

  1. 01

    Who we are

    Tenant Wizards operates tenantwizards.com, a blog covering Microsoft 365 security for IT professionals.

    Chamber of Commerce (KvK): 42031543 · The Netherlands
    info@tenantwizards.com

  2. 02

    Data we collect

    Mollie (payment processor): if you purchase a full Risky User Analyzer report, your billing details (company name, email, VAT number if provided) and payment status are shared with Mollie B.V. to process the transaction. Mollie handles your card/bank details directly; we never see or store them. Mollie's privacy policy.

    Email contact: Your address and message, to respond to your inquiry.

  3. 03

    Legal basis (GDPR)

    Legitimate interest: site security (e.g. abuse and rate-limit prevention on the free scan tool).

    Contract: billing and payment data, to process a Risky User Analyzer report purchase and meet our invoicing obligations.

    Contract / instructions of the controller: Risky User Analyzer scan data, processed as instructed by the scanning organization.

    Legitimate interest: anonymous scoring telemetry, which is aggregated and non-identifying and therefore not personal data under GDPR in the first place.

  4. 04

    Cookies

    This site does not set any cookies of its own. Purchasing a report takes you to Mollie's own checkout page (a separate site), which sets its own cookies under Mollie's privacy policy, not ours.

  5. 05

    Data retention

    Email correspondence: until your inquiry is resolved. Invoices and payment records: 7 years, as required by Dutch tax law (fiscal retention duty).

  6. 06

    Your rights (GDPR)

    You have the right to access, correct, or delete your data, and to object to processing. Contact us at info@tenantwizards.com.

    You may also lodge a complaint with the Dutch DPA at autoriteitpersoonsgegevens.nl.

  7. 07

    Risky User Analyzer

    What it processes: when an organization's administrator authorizes Risky User Analyzer to scan their Microsoft 365 tenant, we process data about that organization's employees: sign-in activity (timestamps, IP addresses, approximate location, device type), audit log entries, inbox rule configurations, mailbox forwarding settings, MFA registration status, directory role assignments, and OAuth app consent grants. We never read the content of emails, only rule and forwarding metadata that could indicate a compromised account.

    Who is the controller: the organization that authorizes the scan (via its own Global Administrator) is the data controller for its employees' data. Tenant Wizards acts as a data processor on that organization's instructions. Individual employees should direct data requests to their own IT administrator, though we'll always help route them correctly if contacted directly.

    Retention: sign-in and audit data analyzed is a rolling 30-day window, read live at scan time, not stored separately. The generated report is automatically deleted from our storage 2 days after the scan completes.

    Third parties: Microsoft Graph (the customer's own tenant, no data leaves Microsoft's boundary except to us). AbuseIPDB: bare IP addresses seen in sign-in logs, with no username or other identifying context attached, are checked against AbuseIPDB's reputation database to flag known-malicious IPs. AbuseIPDB's privacy policy.

    Security: scan credentials and generated reports are stored in Azure Key Vault and Azure Storage (EU West, encrypted at rest and in transit), reachable only by the scanning service itself.

    Anonymous scoring telemetry: after each scan, we record which security checks passed or failed and the resulting score, to improve our scoring logic over time. This record never includes your organization's identity, domain, users, IP addresses, or configuration details, only the check outcomes, the score, and a coarse organization-size bucket, with no field that stays the same across two scans from the same organization, so records can't be linked back to you or to each other. This is aggregated, non-identifying data, not personal data, and there is no opt-out because it never carries anything personal to opt out of.

  8. 08

    Changes

    We update this policy as needed. The date at the top reflects the latest version.