SYAGA Audit audits your Microsoft 365 security with least privilege. We retain neither your users, nor your files, nor your emails - only the audit result, in a minimal and deletable form (GDPR).
The audit is carried out at least privilege. We keep neither your emails, nor your files, nor the content of your mailboxes. Only the audit result - your score and your gaps - is retained in a minimal and protected form in your client area, deletable on request (GDPR).
The permissions granted to SYAGA Audit are strictly read-only. We cannot modify your settings, your users or your data. The Microsoft 365 consent explicitly lists the rights granted.
The raw data collected during the audit (user list, rule configuration, logs) is deleted as soon as the report is generated. No persistent storage of tenant content.
Our entire infrastructure is hosted in France. The audit runs in memory (RAM) and raw data is never written to disk. Your results are deleted as soon as you tick the discharge box, and no later than 2 hours after the end of the scan (24 hours for the information you send us yourself). No data is transferred outside the European Union.
During the audit, we read via Microsoft Graph:
This data is used solely to calculate your score and generate the report. It is never resold or shared.
Graph API · Least privilege Automatic deletionAfter the raw data is deleted, we keep only:
This data remains in your client area for as long as you remain a client. You can request its deletion at any time.
You can revoke SYAGA Audit's access to your Microsoft 365 tenant at any time from the Azure Entra portal:
This action is immediate and irreversible for future audits. Reports already generated remain accessible in your area.
Download all the data we hold about you (scores, reports, account information) in JSON format.
Request exportRequest the complete deletion of your account and all associated data. This action is irreversible. Your subscription will be terminated.
The point of contact for your GDPR rights is the managing director of SYAGA CONSULTING, the data controller. The appointment of a data protection officer is not mandatory within the meaning of Article 37 of the GDPR.
Contact usThe regulatory scope applicable to your organisation, for guidance only. Each reference links to its official source.
Data protection authority : DPC (Data Protection Commission) · https://www.dataprotection.ie/
Cybersecurity authority : NCSC-IE (National Cyber Security Centre (Ireland)) · https://www.ncsc.gov.ie/
National transposition of NIS2
Indicative content, not legal advice. Review by a local lawyer is required.