SYAGA AuditMicrosoft 365 Edition
Home Features Security How it works Pricing
Log in Lancer mon audit gratuit

Privacy policy

Version 1.0 - Last updated: 25 June 2026


Preamble

The purpose of this Privacy Policy is to inform the users and clients of the SYAGA Audit service how their personal data is collected, processed and protected, in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR) and with the Act No. 78-17 of 6 January 1978, as amended, on information technology, data files and civil liberties.

SYAGA Audit is a security and compliance audit service for the Microsoft 365 environment, operating in read-only mode on the configurations and metadata of the client's Microsoft 365 tenant. The Service does not access the content of messages, files or emails of the audited tenant's users, and stores no passwords.

This document fulfils the information obligation provided for in Articles 13 (direct collection) and 14 (indirect collection) of the GDPR.


1. Identity and contact details of the data controller

The data controller for account data and customer relationship management data is:

SYAGA CONSULTING

  • Form: Limited liability company (EURL) with share capital of EUR 20 000
  • SIREN: 518 489 471 -- RCS Aix-en-Provence
  • Registered office: 2 Impasse Paul Langevin, 13110 Port-de-Bouc
  • Intra-EU VAT number: FR93 518489471
  • Email: contact@syaga.eu

Processor / controller relationship: for the configuration data and metadata of the Microsoft 365 tenant collected during the audit, SYAGA acts as a processor within the meaning of Article 28 of the GDPR, the client remaining the controller of its own M365 data. This policy covers the scope for which SYAGA acts as controller (account data, billing, support). The processing carried out on behalf of the client is governed by the Data Processing Agreement (DPA).

Data protection contact

For any request relating to data protection: dpo@syaga.eu

The appointment of a data protection officer is not mandatory within the meaning of Article 37 of the GDPR; the data controller, in the person of the manager, is the point of contact for any question relating to personal data.


2. Personal data collected

2.1 Account data and customer relationship management data

SYAGA collects, as data controller:

  • Contact identity: last name, first name, position
  • Professional contact details: email address, company name
  • Service authentication data (Microsoft OAuth token -- no password stored on the SYAGA Audit side)
  • Billing and contract management data
  • Support data and communications
  • Technical connection logs (IP addresses, timestamps)

2.2 Audit data (Microsoft 365 configuration and metadata)

As part of the audit, the Service accesses, on a read-only basis and via the Microsoft Graph API, the configuration data and metadata of the client's M365 tenant, in particular:

  • Security configuration settings (conditional access policies, MFA settings, sharing settings)
  • Metadata relating to user accounts (UPN, roles, MFA status, Entra ID directory attributes)
  • Security posture indicators and metadata (Secure Score, configuration alerts)

What the Service does not collect: the content of emails, files, documents, messages, passwords, or sensitive data within the meaning of Article 9 of the GDPR.

Ephemeral architecture: the audit runs in memory inside a disposable scan container (no disk storage). Your results disappear at the earlier of two events: you tick the discharge box on your report page, once you have downloaded your files, and deletion is triggered by that action; failing that, by automatic expiry, no later than 2 hours after the end of the scan for your score, your findings and your report, and no later than 24 hours after you send them for the information you provide yourself (company profile, declarative questionnaire). The Microsoft session token is encrypted at rest (Fernet) and does not live longer than 58 minutes; the technical token used during the scan expires automatically no later than 3 hours after it is issued. You can revoke access at any time from your Microsoft Enterprise Applications, without asking us. SYAGA then retains only billing data, for 10 years from the close of the financial year, as the law requires of any company.

2.3 Cookies and trackers

The syaga.eu website uses only strictly necessary cookies for the operation of the Service:

  • __jsc: anti-bot security cookie, session duration
  • syaga_audit: session cookie, session duration

No audience-measurement cookies (Google Analytics, Matomo or equivalent) or advertising cookies are placed. These strictly necessary cookies are exempt from prior consent in accordance with the CNIL guidelines of 4 July 2023 (source: cnil.fr -- cookies and trackers). An information notice about these cookies is sufficient.


3. Purposes and legal bases of processing

In accordance with Article 6 of the GDPR, each processing operation is based on an identified legal basis:

PurposeLegal basis (GDPR Art. 6)
Provision and delivery of the audit Service; creation and management of the client accountPerformance of the contract -- Art. 6.1.b
Invoicing, accounting, debt recoveryLegal obligation (French Commercial Code art. L.123-22) and performance of the contract -- Art. 6.1.c and 6.1.b
Support and technical assistancePerformance of the contract -- Art. 6.1.b
Security of the Service, fraud prevention, loggingLegitimate interest -- Art. 6.1.f
Strictly necessary cookiesExempt from consent (CNIL guidelines)

For the tenant's audit data (section 2.2), SYAGA acts on the client's instructions (data controller). See the DPA.


4. Recipients and subcontractors

The data is disclosed only to authorised persons within SYAGA CONSULTING as well as to the sub-processors acting under the conditions of Article 28 of the GDPR:

  • Microsoft Corporation: provider of the Microsoft Graph API, used on a read-only basis to access the configuration data of the customer's tenant. The data audited is that of the Customer's own Microsoft 365 tenant, accessed on a read-only basis on their behalf via Microsoft Graph. Microsoft acts as the Customer's provider; SYAGA is not its sub-processor.
  • Stripe Payments Europe, Limited: payment provider for processing billing data. Transfers to Stripe are governed by the EU-U.S. Data Privacy Framework, to which Stripe is certified, and, on a subsidiary basis, by the European Commission's Standard Contractual Clauses (2021) incorporated into Stripe's Data Transfers Addendum (sources: stripe.com/legal/dpa and stripe.com/legal/dta).
  • Host: OVH SAS, 2 rue Kellermann, 59100 Roubaix, France (RCS Lille Métropole 424 761 419). The service is hosted in France by OVH SAS (a French host), technical subcontractor of SYAGA CONSULTING. SYAGA CONSULTING only receives pseudonymised data (tokens).

No data is sold or transferred to third parties for commercial purposes.

Data may be disclosed to administrative or judicial authorities where required by law.


5. Retention periods

Data is retained for a period no longer than that necessary for the purposes pursued (art. 5.1.e GDPR):

Data categoryRetention period
Raw audit data (findings, access token)Nothing is written to disk: your results live in memory only. They are deleted as soon as you tick the discharge box on your report, and in any event no later than 2 hours after the end of the scan (24 hours for the information you send us yourself).
Active client account dataDuration of the contractual relationship, then deletion within 30 days of termination
Billing data and accounting records10 years from the close of the financial year (legal obligation, art. L.123-22 Commercial Code)
Technical logs (connection logs)12 months (CNIL recommendation)
Proof that you accepted our contractual documents (DPA, terms of sale, privacy policy) and that your Microsoft administrator authorised the read access5 years at most after the end of the contractual relationship. That is how long a claim can still be brought between businesses (French Commercial Code, art. L. 110-4; French Civil Code, art. 2224): beyond that, the proof serves no purpose and we have no reason to keep it.

What we keep, and what we never keep

Zero-knowledge covers what we must not know: the contents of your information system. It does not cover the fact that you are our customer, nor the proof that you authorised us to work. Those two things, the law requires us to be able to demonstrate (GDPR, art. 5.2 and 24.1).

We keep, within the retention periods above:

  • Proof that you accepted our contractual documents: your organisation reference, our server date and time, and the version number of the document accepted. For documents accepted on the website, we also record the digital fingerprint of the exact text displayed to you: years later, it answers the only question that matters, which version exactly.
  • Proof that the administrator of your Microsoft tenant authorised us to read it: the tenant identifier and the date of that authorisation. We do not record the name of the person who clicked: the organisation is enough to identify the contracting party, and one less item of personal data is one less item of personal data.
  • The withdrawal of one of those acceptances, should it occur: its date, and its reason if you tell us. Withdrawal dates the record, it does not erase it. Erasing it would destroy the proof that the agreement existed during the period when we worked, which would harm you as much as us.
  • Your billing details and your invoices, for the period imposed by the French Commercial Code.

We never keep:

  • The result of the analysis: the list of your weaknesses, their severity, their location.
  • The data read in your tenant: accounts, addresses, groups, mailboxes, settings. It is pseudonymised on your own machine before it reaches us, and what reaches us is deleted at the latest two hours after the scan ends (usually sooner, as soon as you have collected your report).
  • No password, and no authentication secret from your tenant.

The dividing line, in one sentence: we keep what proves the work was authorised and invoiced; we keep nothing of what the work revealed.

You may ask us for a copy of the register entry concerning you, at the address given in section 10.


6. Data transfers outside the European Union

The infrastructure hosting the SYAGA Audit Service is located in France. In principle, no data transfer is carried out outside the EU / EEA by SYAGA.

Regarding Microsoft: the Data Controller acknowledges that the Microsoft Graph API is operated by Microsoft Corporation (United States). Any transfers involving Microsoft are governed by its standard contractual clauses approved by the European Commission and, where applicable, by its participation in the EU-U.S. Data Privacy Framework. The data audited is that of the Client's own Microsoft 365 tenant, accessed read-only on their behalf via Microsoft Graph. Microsoft acts as the Client's supplier. Any transfers involving Microsoft's infrastructure are governed by the standard contractual clauses approved by the European Commission and Microsoft's participation in the EU-U.S. Data Privacy Framework.

Stripe Payments Europe, Limited carries out transfers outside the EU governed by mechanisms compliant with Chapter V of the GDPR. Transfers to Stripe are governed by the EU-U.S. Data Privacy Framework, to which Stripe is certified, and, in the alternative, by the European Commission's Standard Contractual Clauses (2021) incorporated into Stripe's Data Transfers Addendum.


7. Rights of data subjects

In accordance with Articles 15 to 22 of the GDPR, every data subject has the following rights:

  • Right of access (Art. 15 GDPR): to obtain confirmation that data concerning them is being processed and to obtain a copy of it
  • Right to rectification (Art. 16): to have inaccurate or incomplete data corrected
  • Right to erasure (art. 17): to obtain deletion in the cases provided for by the GDPR
  • Right to restriction of processing (art. 18)
  • Right to data portability (art. 20): receive your data in a structured, machine-readable format
  • Right to object (Art. 21): to object to processing on grounds relating to your particular situation, and at any time to direct marketing
  • Right to withdraw consent (Art. 7.3) at any time where processing is based on consent
  • Post-mortem right (art. 85 of the French Data Protection Act): to set directives concerning the fate of the data after death

Important regarding audit data: for the tenant's configuration data and metadata, requests to exercise rights must be addressed to the client (data controller), who will call on SYAGA if necessary (Art. 28.3.e GDPR).

How to exercise your rights

These rights may be exercised by sending a request to dpo@syaga.eu or by post to SYAGA CONSULTING 2 Impasse Paul Langevin, 13110 Port-de-Bouc. A reply is provided within one month (art. 12.3 GDPR), extendable by two months in the event of complexity.

Complaint to the CNIL

Any data subject has the right to lodge a complaint with the CNIL (art. 77 GDPR):

CNIL -- 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 -- www.cnil.fr


8. Data security (Art. 32 GDPR)

SYAGA implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (art. 32 GDPR):

  • Ephemeral architecture: audit run in RAM, disposable scan container with no disk storage; data deleted as soon as you discharge, and no later than 2 hours after the end of the scan
  • Least privilege: connection via Microsoft OAuth with the narrowest permissions offered by Microsoft for each audited scope; the Service never writes, modifies or deletes any tenant data
  • Encryption in transit: TLS 1.2/1.3 on all communications; SPF, DKIM and DMARC enabled on emails
  • Encryption at rest: access token encrypted (Fernet) for the duration of the audit
  • Hosting in France: OVH infrastructure (France)
  • Access control: principle of least privilege; named authorisations
  • Anti-abuse protection: cap of 2 audits/day/tenant, anti-DDoS measures
  • Breach notification: procedure compliant with GDPR art. 33 and 34 (CNIL notification within 72 hours)

Multi-framework alignment

SYAGA Audit's security measures are designed in line with several recognised security frameworks. SYAGA claims no formal certification against these frameworks the measures are aligned with the requirements of the ISO/IEC 27001 standard, with a certification process under way but no certification obtained to date; the measures are aligned with and inspired by these frameworks:

  • GDPR (Regulation EU 2016/679): directly applicable regulatory basis -- eur-lex.europa.eu CELEX:32016R0679
  • NIS2 Directive (EU Directive 2022/2555): risk management measures, security of networks and information systems -- eur-lex.europa.eu CELEX:32022L2555. SYAGA, whose headcount and turnover are below the thresholds for important entities within the meaning of Directive (EU) 2022/2555 (50 employees or EUR 10M), does not fall within the scope of entities subject to NIS2. SYAGA Audit nevertheless helps its clients measure their compliance with this framework (source: monespacenis2.cyber.gouv.fr).
  • DORA (EU Regulation 2022/2554): digital operational resilience for the financial sector -- eur-lex.europa.eu CELEX:32022R2554. As SYAGA is not a regulated financial entity, Regulation (EU) 2022/2554 (DORA) does not apply to it directly; however, contractual obligations may apply on a case-by-case basis where a customer is a financial entity subject to DORA (source: eur-lex.europa.eu DORA).
  • ISO/IEC 27001: reference framework for information security management systems (ISMS) -- iso.org/standard/27001. SYAGA Audit's measures are aligned with the requirements of the ISO/IEC 27001 standard, with a certification process under way but no certification obtained to date.
  • ANSSI recommendations: IT hygiene guide and recommendations of the French National Agency for the Security of Information Systems -- ssi.gouv.fr.

SYAGA Audit precisely helps its clients measure their own compliance with these frameworks (GDPR, NIS2, ANSSI) within their Microsoft 365 environment.


9. Amendments to this policy

This Policy may be updated to reflect legal, regulatory or technical developments. The version in force is the one published on https://syaga.eu/confidentialite.html. In the event of a substantial change, registered users will be informed by email within a reasonable period before the changes take effect.


10. Contact

For any question relating to this policy or to the protection of your data:

  • Email: contact@syaga.eu
  • Address: SYAGA CONSULTING -- 2 Impasse Paul Langevin, 13110 Port-de-Bouc

Legal and documentary references

  • Regulation (EU) 2016/679 (GDPR) -- full text: eur-lex.europa.eu CELEX:32016R0679
  • Amended Act No. 78-17 of 6 January 1978: Légifrance
  • CNIL -- individuals' rights: cnil.fr
  • CNIL -- cookies: cnil.fr
  • NIS2 Directive (EU) 2022/2555: eur-lex.europa.eu CELEX:32022L2555
  • DORA Regulation (EU) 2022/2554: eur-lex.europa.eu CELEX:32022R2554
  • ISO/IEC 27001: iso.org/standard/27001
  • ANSSI -- IT hygiene guide: ssi.gouv.fr
SYAGA Audit
Security Privacy Terms of Use DPA Collector privacy policy Terms and Conditions of Sale Refund and Withdrawal Policy Legal notice © 2026 SYAGA