Skip to content

Privacy policy

Last updated: 7 July 2026.

EasyTenant places particular importance on the protection of personal data. This policy describes the data processed, the purposes pursued and the rights available to you, in accordance with the General Data Protection Regulation (GDPR).

Data controller

The data controller is the site publisher, identified in the legal notice.

EasyTenant acts as data controller for its clients’ data (the MSP providers and their technicians) and as a processor, within the meaning of Article 28 GDPR, for the end-user data processed in its clients’ Microsoft 365 tenants.

Data collected

Collection is limited to what is strictly necessary to provide the service:

  • Technician accounts: Entra identifier (oid), tenant identifier (tid), work email address, display name, role.
  • MSP account: company name and billing identifiers managed by Stripe.
  • Audit log: operation performed, tenant concerned, technician, timestamp, result, pseudonymized IP address (HMAC hash, never in clear text).
  • Technical data: server logs required for security and proper operation.

What we do not keep

EasyTenant keeps no password, no access token (they remain in memory for the duration of the operation) and no mailbox content. End-user data stays in the client’s Microsoft tenant.

Purposes and legal bases

Your data is processed for the following purposes:

  • Providing the Microsoft 365 administration service (performance of the contract).
  • Billing and subscription management (performance of the contract, legal accounting obligation).
  • Audit log and security (legitimate interest: traceability and abuse prevention; security obligation under the GDPR).
  • Support and service-related communication (performance of the contract, legitimate interest).

Hosting and location

The application database is hosted in the European Union. The application is deployed on Vercel infrastructure, with execution in the Paris region (France).

Some subprocessors are located outside the European Union; any transfers are governed by the European Commission’s standard contractual clauses.

Retention period

Data is retained for the following periods:

  • Account data (MSP, technicians): for the entire duration of the subscription.
  • Audit log: a rolling 12 months from each entry.
  • After cancellation: account and tenant data deleted within 30 days.
  • Accounting records and invoices: 10 years, in accordance with legal obligations.

Subprocessors

EasyTenant relies on the following subprocessors, each bound by contractual guarantees compliant with the GDPR:

  • Microsoft (Microsoft Graph, Exchange Online) — execution of operations on client tenants.
  • Vercel — hosting and execution of the application (Paris region).
  • Neon — PostgreSQL database (European Union).
  • Stripe — payment processing and billing.
  • Resend — transactional email delivery.

Commitments as a processor (Article 28 GDPR)

For end-user data processed on behalf of its MSP clients, EasyTenant commits to:

  • Notify the relevant MSP without undue delay after becoming aware of a personal data breach.
  • Give the MSP at least 30 days’ notice before engaging any further subprocessor, allowing it to object.
  • Assist the MSP in handling requests to exercise data subjects’ rights.
  • Delete or return, at the MSP’s choice, all relevant data at the end of the contractual relationship, subject to legal retention obligations.
  • Allow the MSP, or an auditor it appoints, to verify compliance with these commitments, subject to reasonable notice.

Security

Access to tenants relies on X.509 certificate authentication in a Client Credentials flow, with no client secret and no persisted token. Every operation verifies that the tenant belongs to the MSP before acting (strict isolation). Audit-log IP addresses are pseudonymized by HMAC hashing and exchanges are encrypted in transit (HTTPS).

Your rights (GDPR)

You have the following rights over your personal data:

  • Right of access and rectification.
  • Right to erasure and to restriction of processing.
  • Right to object and right to data portability.
  • Right to set directives on the fate of your data after your death.

Exercising your rights and complaints

To exercise these rights, write to contact@easytenant.fr. For end-user data processed within their tenant, requests must be addressed to the responsible MSP, for whom EasyTenant is the processor.

You have the right to lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris — www.cnil.fr.

Cookies

The site uses only the cookies strictly necessary for authentication and operation of the service. No advertising cookie or third-party marketing tracker is placed.