GDPR · Privacy · Sovereignty

Your tenant does not belong to us.

SYAGA Audit audits your Microsoft 365 security with least privilege. We retain neither your users, nor your files, nor your emails - only the audit result, in a minimal and deletable form (GDPR).

SYAGA Audit does not retain any of your content.

The audit is carried out at least privilege. We keep neither your emails, nor your files, nor the content of your mailboxes. Only the audit result - your score and your gaps - is retained in a minimal and protected form in your client area, deletable on request (GDPR).

Hosted in France · Data never resold · Consent revocable at any time
Our commitments

Three non-negotiable principles.

Least privilege, zero writes

The permissions granted to SYAGA Audit are strictly read-only. We cannot modify your settings, your users or your data. The Microsoft 365 consent explicitly lists the rights granted.

Automatic erasure

The raw data collected during the audit (user list, rule configuration, logs) is deleted as soon as the report is generated. No persistent storage of tenant content.

Hosting in France

Our entire infrastructure is hosted in France. The audit runs in memory (RAM) and raw data is never written to disk. Your results are deleted as soon as you tick the discharge box, and no later than 2 hours after the end of the scan (24 hours for the information you send us yourself). No data is transferred outside the European Union.

Infrastructure hosted in France - European Union Hosted in France · Audit in memory, erased on your discharge · No transfer outside the EU · GDPR Art. 44 compliant
Detail

Exactly what we collect.

Data collected during the audit

During the audit, we read via Microsoft Graph:

  • Number and configuration of users (not the content of their mailboxes)
  • Microsoft 365 security settings (MFA, conditional access, Exchange, SharePoint…)
  • Configuration of compliance and data protection policies

This data is used solely to calculate your score and generate the report. It is never resold or shared.

Graph API · Least privilege Automatic deletion

What we retain in your client area

After the raw data is deleted, we keep only:

  • Your overall score (44%) and the scores by domain
  • The number of urgent issues detected (2 critical, etc.)
  • The audit date and the tenant name
  • The generated PDF report (if Pro offer)

This data remains in your client area for as long as you remain a client. You can request its deletion at any time.

Revoking Microsoft 365 consent

You can revoke SYAGA Audit's access to your Microsoft 365 tenant at any time from the Azure Entra portal:

  • Open portal.azure.com → Enterprise applications
  • Search for "SYAGA Audit" → Remove permissions

This action is immediate and irreversible for future audits. Reports already generated remain accessible in your area.

Your rights

Exercise your GDPR rights.

Export my data

Download all the data we hold about you (scores, reports, account information) in JSON format.

Request export

Delete my data

Request the complete deletion of your account and all associated data. This action is irreversible. Your subscription will be terminated.

A question about your data?

The point of contact for your GDPR rights is the managing director of SYAGA CONSULTING, the data controller. The appointment of a data protection officer is not mandatory within the meaning of Article 37 of the GDPR.

Contact us
SYAGA CONSULTING · 2 Impasse Paul Langevin, 13110 Port-de-Bouc · France
Regulatory framework

The regulations that concern you

The regulatory scope applicable to your organisation, for guidance only. Each reference links to its official source.

Applicable European regulation

National specifics · Ireland

Data protection authority : DPC (Data Protection Commission) · https://www.dataprotection.ie/

Cybersecurity authority : NCSC-IE (National Cyber Security Centre (Ireland)) · https://www.ncsc.gov.ie/

National transposition of NIS2

Indicative content, not legal advice. Review by a local lawyer is required.