1) Who we are & roles
Customer (Controller): The legal entity that acquires and uses our SaaS and determines the purposes of processing within its environment.
AccurDigital (Processor/Controller): We generally act as a processor of Customer Data inside the subscribed workspace and as a controller for our own business operations (e.g., billing records we receive from Microsoft, product telemetry, support).
Microsoft (Independent Controller): Microsoft processes data to enable Marketplace transactions and access. Microsoft’s privacy statement applies separately.
2) Data we collect
From Microsoft Marketplace (at purchase/fulfillment): Subscriber/company name, contact name, business email, Azure subscription/tenant identifiers, plan/SKU, quantity, region, and transaction or metering information that Microsoft shares with us to provision and support the offer.
From website visitors and users of our apps: account details (name, work email), authentication and authorization data, product usage and telemetry (feature use, error logs, performance metrics, device/browser metadata, and IP for security), support communications (tickets, attachments, call/chat transcripts), and configuration/content uploaded by the Customer (e.g., asset hierarchies, inspection data, documents). We do not intentionally collect sensitive categories unless provided by the Customer.
3) Purposes of processing
- Provisioning, activation, license/metering, and entitlement management for Marketplace purchases.
- Authentication and authorization for access control in our applications (no specific identity provider required).
- Operating and improving the service (reliability, performance, UX), security monitoring, and abuse prevention.
- Customer support and incident response.
- Compliance with law and contractual obligations.
4) Legal bases (GDPR/EU/UK)
Contract necessity to deliver the subscribed SaaS; legitimate interests for service security and improvement; legal obligation for recordkeeping and compliance; and consent where required (e.g., optional communications).
5) Sharing & recipients
Sub‑processors: Microsoft Azure (regions selected by the Customer) and limited service providers for logging/monitoring, email/ticketing, and support tooling—each governed by DPAs.
Microsoft: Acts as a separate controller for Marketplace commerce; we may receive customer information from Microsoft to fulfill and support the offer.
Website analytics & advertising providers: This website shares limited technical information with Google (Analytics and Ads), Microsoft (Clarity and Microsoft Advertising) and LinkedIn, each for their own purposes under their own terms. Clarity, LinkedIn and Microsoft Advertising receive nothing unless you consent; Google receives basic request information with all storage denied even before you choose. See §11.
Contact form & Google Ads attribution: When you submit our contact form, your email address and name are shared with Google in hashed (one‑way encrypted) form so that Google Ads can attribute the enquiry to the advertisement that led to it. This happens only if you have accepted advertising cookies in our consent banner. We do not share the message content or company name with Google.
Professional services/partners (optional): If engaged by the Customer, access is limited and governed by the services agreement. We do not sell personal data.
6) International transfers & residency
We support hosting in Azure regions appropriate to the Customer (e.g., EU, UAE, or other available regions). Data may be processed in and transferred to countries where we or our sub‑processors operate, with appropriate safeguards (e.g., SCCs) when required. Customers can request region options during onboarding.
7) Security
We apply administrative, technical, and physical controls including role‑based access, encryption in transit and at rest, environment segregation, backup/retention policies, audit logging, and vulnerability management. Customers can configure MFA and least‑privilege roles within their environment. We can provide a current Security Overview or certifications under NDA upon request.
8) Retention
- Customer Data in the SaaS: retained for the subscription term and deleted or returned within [30–90 days] after termination, per contract.
- Operational records/telemetry: kept for [up to 13 months] unless longer is required for security, audit, or legal obligations.
- Support records: kept for [up to 3 years] from ticket closure unless law requires longer.
9) Individual rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, or portability. Where we act as a processor, we will forward requests to the Customer (controller) and support fulfillment.
10) Customer responsibilities
Customers are responsible for configuring identity, roles, and data retention; providing a lawful basis for any personal data inserted into business content; and honoring data subject requests within their organization.
11) Cookies, analytics & advertising
Our web apps use strictly necessary cookies (session, security) and, where enabled by the Customer, analytics/telemetry to improve reliability and performance.
On this website specifically, the following applies. We ask for your choice on your first visit. If your browser sends a Global Privacy Control signal we treat that as a refusal automatically and do not ask.
Strictly necessary — always active. Session and security cookies, and Cloudflare Turnstile, which checks that our contact form is being completed by a person rather than an automated script. Turnstile is required for the form to function and is not optional. It is not used for analytics or advertising.
Loaded only if you accept. If you choose “Accept all”, we load:
- Microsoft Clarity — to understand which pages are read and where visitors encounter difficulty.
- LinkedIn Insight Tag — to measure the response to our campaigns on LinkedIn and to build advertising audiences.
- Microsoft UET, for Microsoft Advertising — to measure the response to our campaigns on Microsoft’s search network.
If you choose “Necessary only”, none of these three is requested at all — the scripts are never added to the page.
Google Analytics and Google Ads work differently, and you should know how. These two load on every page view, including before you have chosen. They start with all storage denied using Google Consent Mode, which means that before you accept they set no analytics or advertising cookies and do not track you across websites. Google does still receive basic information that accompanies any web request — the page address, your IP address and your browser type — which it uses in aggregate to estimate campaign results. If you accept, these tags are upgraded in place and may then set cookies. If you refuse, they stay denied for the remainder of your visit.
When you send us an enquiry. Submitting the contact form takes you to a confirmation page, which records once that an enquiry was made and which product module you came from, so that we know which page prompted you to get in touch. It does not record anything you typed into the form.
Changing or withdrawing your choice. Your choice is stored locally in your browser, not in a cookie, and you can change it at any time using the Cookie settings link in the footer of any page. Withdrawing consent takes effect from your next page view: scripts already running in the page you are on continue until you navigate or reload, after which nothing further is loaded. Cookies already set by those services can be removed through your browser’s settings.
12) Third‑party links
Our apps may link to Microsoft or other third parties (e.g., documentation). Their policies apply to their properties.
13) Changes
We may update this Policy to reflect operational, legal, or regulatory changes. Material changes will be notified via product banner, email to Customer admins, or release notes. The effective date is shown at the top of this page.
14) Contact
AccurDigital – Privacy
Email: privacy@accurdigital.com
Registered office: [Accur Digital, The 47 Building, N' 90th St 5th Settlement, New Cairo 1, Cairo, Egypt]