Saario
How it works Vitals we check Copilot The Report Why it matters Pricing
Sign in Get your free checkup
How it works Vitals we check Copilot The Report Why it matters Pricing
Legal

Privacy Statement

Last updated: 3 August 2026  ·  Version 1.0

This Privacy Statement explains how Saario ("Saario", "we", "us", "our") collects, uses, shares and protects personal data when you visit saario.app, subscribe to our cyber auditing services for Microsoft 365 (the "Services"), or otherwise interact with us. We are committed to handling personal data lawfully, fairly and transparently, in accordance with the UK GDPR and the Data Protection Act 2018.

Contents

  1. Who is responsible for your data
  2. Personal data we collect
  3. Data from Microsoft 365 tenants
  4. How and why we use personal data
  5. Lawful bases for processing
  6. Who we share data with
  7. International transfers
  8. How long we keep data
  9. How we protect data
  10. Your rights
  11. Cookies
  12. Children
  13. Changes to this statement
  14. How to contact us

1. Who is responsible for your data

For personal data about our website visitors, prospective customers, customer contacts and billing contacts, Saario is the data controller.

For personal data contained in a customer's Microsoft 365 tenant that we read in order to deliver the Services, we act as a data processor on the instructions of that customer, who is the controller. If you are an employee or user of an organisation that uses Saario, that organisation decides why and how your data is processed, and its own privacy notice applies alongside this statement.

2. Personal data we collect

Information you provide to us

  • Identity and contact data — name, work email address, job title, company name and telephone number when you register, request a checkup, subscribe or contact us.
  • Billing data — subscription plan, billing contact and payment history. Card payments are processed directly by Stripe; we do not receive or store full card numbers.
  • Communications — the content of emails, support requests and enquiry forms you send us.

Information collected automatically

  • Technical data — IP address, browser type and version, operating system, device identifiers.
  • Usage data — pages visited, features used, actions taken in the Services, dates and times of access.

We do not intentionally collect special category data (such as health, religious or biometric data), and ask that you do not send it to us.

3. Data from Microsoft 365 tenants

When an authorised administrator connects a Microsoft 365 tenant, the Services read security-relevant signals through the Microsoft Graph API using read-only application permissions granted through Microsoft's own consent process. Depending on the areas audited, this may include personal data such as:

  • user names, email addresses, roles, licence assignments and MFA status;
  • sign-in and audit log events, including times, locations, IP addresses and risk indicators;
  • device names, enrollment and compliance status from Microsoft Intune;
  • mailbox configuration signals such as forwarding rules (not the content of emails);
  • sharing metadata for SharePoint and OneDrive, including file names, sensitivity labels and link types (not the content of files);
  • Microsoft Copilot usage metadata, including which labelled files were referenced in prompts;
  • Microsoft Secure Score values and security recommendations.

Read-only by design. Saario cannot change your tenant, does not read the contents of emails or documents, and never receives or stores Microsoft passwords. An administrator can revoke Saario's access at any time in Microsoft Entra ID.

4. How and why we use personal data

  • Delivering the Services — running audits, calculating the Saario Score, generating reports and recommendations, and displaying results to authorised users.
  • Account administration — creating and managing accounts, processing subscriptions and payments, and providing customer support.
  • Security and integrity — authenticating users, preventing fraud and abuse, monitoring for unauthorised access, and maintaining audit logs.
  • Service improvement — analysing how the Services are used, fixing faults, and developing features. We may create aggregated, anonymised statistics and industry benchmarks that do not identify any person, customer or tenant.
  • Communications — sending service messages (such as reports, alerts, billing and security notices) and, where permitted, occasional updates about our products; you can opt out of marketing at any time.
  • Legal compliance — meeting our accounting, tax and regulatory obligations and establishing or defending legal claims.

We do not sell personal data, and we do not use tenant data for advertising or to train third-party models.

5. Lawful bases for processing

PurposeLawful basis
Providing the Services and managing your accountPerformance of a contract
Processing tenant data on a customer's behalfProcessor acting on the controller's documented instructions
Securing and improving the Services; business communicationsLegitimate interests
Tax, accounting and regulatory record-keepingLegal obligation
Optional marketing and non-essential cookies (if any)Consent, which you may withdraw at any time

6. Who we share data with

We share personal data only where necessary, with:

  • Service providers (sub-processors) who host and support the Services under contracts requiring appropriate protection — including Microsoft (Graph API and cloud hosting), Stripe (payment processing) and our email provider.
  • Professional advisers — lawyers, accountants, auditors and insurers, where reasonably necessary.
  • Authorities — courts, regulators and law enforcement where disclosure is required by law.
  • A buyer or successor — in connection with a merger, acquisition or sale of our business, in which case this statement will continue to apply to your data.

7. International transfers

Personal data is stored and processed primarily in the UK and European Economic Area. Where a transfer outside the UK or EEA is necessary — for example, to a sub-processor operating in the United States — we ensure appropriate safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses.

8. How long we keep data

CategoryRetention period
Tenant audit dataDuration of the subscription (to enable score trends), then deleted within 30 days of tenant disconnection or account closure
Account and contact dataDuration of the account, plus up to 12 months
Billing and transaction records6 years, as required for UK tax and accounting purposes
Support correspondenceUp to 2 years after the matter is closed
Aggregated, anonymised statisticsIndefinitely (not personal data)

9. How we protect data

We apply technical and organisational measures appropriate to a security company, including encryption of data in transit and at rest, least-privilege and role-based access controls, segregation of customer data, encrypted storage of API tokens scoped to read-only access, and logging and monitoring of access to production systems. While no service can be guaranteed to be completely secure, if we become aware of a personal data breach affecting you we will notify affected customers and, where required, the Information Commissioner's Office without undue delay.

10. Your rights

Under data protection law you have rights, in certain circumstances, to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data;
  • restrict or object to processing, including processing based on legitimate interests and direct marketing;
  • data portability — receive data you provided in a structured, machine-readable format;
  • withdraw consent at any time, where processing is based on consent.

To exercise any right, email info@saario.app. We will respond within one month. If your request concerns data we process on behalf of your organisation as a customer, we may refer the request to that organisation, as the controller of that data.

You also have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk, or with your local supervisory authority.

11. Cookies

Our website uses only strictly necessary cookies and similar technologies required for the site and the Services to function, such as session and security cookies used for sign-in. We do not use advertising or third-party tracking cookies. If we introduce optional analytics or marketing cookies in future, we will update this statement and request your consent where required. You can control cookies through your browser settings; blocking strictly necessary cookies may affect how the Services work.

12. Children

The Services are designed for business use and are not directed at children. We do not knowingly collect personal data from children as customers or users of our website.

13. Changes to this statement

We may update this Privacy Statement from time to time to reflect changes in our practices, the Services or the law. The current version will always be published on this page with its "last updated" date. For material changes we will notify customers by email or an in-service notice before the change takes effect.

14. How to contact us

For any questions about this Privacy Statement or how we handle personal data, contact us at info@saario.app.

Saario

Search · Audit · Analyse · Report · Intelligent · Orchestration — designed for Microsoft 365 tenants, powered by the Microsoft Graph API.

Product

How it works Vitals we check Copilot Governance The Report Pricing

Company

Why it matters Contact

Trust

Security & permissions Privacy statement Terms and conditions

© 2026 Saario. Not affiliated with or endorsed by Microsoft. Microsoft, Microsoft 365, Intune, SharePoint and OneDrive are trademarks of the Microsoft group of companies.