1. Who we are and what this Policy covers
This Privacy Policy describes how Unify365 LLC ("Unify365", "we", "us"), a California limited liability company, collects, uses, shares, and protects personal information in connection with:
- our website at unify365.ai (the "Site");
- the Unify365 application, the UnifyQ assistant, the optional Unify365 Connector, and related support services (together with the Site, the "Service"); and
- our communications with customers, prospects, and people who contact us.
It applies to three groups of people, and our role is different for each:
| Who you are | Examples of your data | Our role |
|---|---|---|
| A visitor to our Site | server logs, a message you send us | Controller |
| A User — someone who signs in to the Service for a customer organization | name, email, tenant, role, actions you take, questions you ask UnifyQ | Controller for your account, usage, and communications data; processor for what you do inside your organization's tenant |
| A person whose data is in a customer's tenant or on-premises systems — for example, an employee of an organization that uses Unify365 | directory record, device, licenses, sign-in and audit events, group memberships | Processor / service provider. The customer organization is the controller. We process this data only on its instructions, and requests about it should go to that organization (see Section 10). |
Our customers are organizations. If you are a consumer, the Service is not intended for you.
2. Information we collect
2.1 Account and sign-in information (from Microsoft)
When you sign in with your Microsoft work account, Microsoft sends us your display name, email address / user principal name, your user's Entra object ID, your tenant's ID, display name and primary domain, and the permissions the sign-in was granted. We store these to identify you and your organization's workspace, and we record when you last signed in and the role you hold in Unify365. We also receive OAuth access and refresh tokens scoped to the permissions your organization consented to; we store them so the Service can act for you between sign-ins, and they expire or are refreshed as Microsoft dictates. We never receive or store your password. Sign-in sessions expire after at most eight hours or when you sign out.
2.2 Customer tenant data we process on your organization's behalf
The Service is an administration console. Through the Microsoft Graph permissions your organization grants (read-only at install; changes only after a separate administrator consent), it reads:
- Directory data: users, groups, guests, devices, administrative roles, licenses and subscriptions, organization settings, applications and service principals.
- Configuration: policies and settings across the Microsoft 365 admin portals — for example, Conditional Access, authentication methods, Intune configuration and compliance policies, Exchange mailbox settings (such as forwarding rules), Teams and SharePoint tenant settings, and Purview policies.
- Security and audit signals: sign-in and audit logs, risk detections, security incidents and alerts, Secure Score, service-health messages, and usage reports.
- Collaboration-service metadata: inventory and settings of sites, teams, and call records.
What we do not read. The Service reads configuration, inventory, and signals about your tenant. It does not open or store the contents of your users' mailboxes, chats, meetings, or documents. Where a permission technically reaches such content (for example, site access used to inventory SharePoint), we use it only for settings and inventory.
Retrieved live versus stored. Most tenant data is retrieved from Microsoft Graph when you view a screen and is not kept. The Service does store the following operational copies so that history, drift detection, and reporting work:
- point-in-time configuration snapshots of the policy and settings surfaces we watch, and the differences between them (drift records), bounded by your plan's retention window;
- an access graph — which users, groups, and applications hold which roles, memberships, and application grants — refreshed on a schedule;
- a correlated device inventory (directory, Intune, and Autopilot records for each device, including assigned user and compliance state);
- a SaaS usage estate derived from application sign-in events and app assignments (which apps are used, by whom, how recently);
- daily aggregate metrics used to detect anomalies (for example, counts of sign-ins or license assignments per day);
- findings from governance policies, compliance checks, and access reviews, with the decisions your reviewers record;
- proposed and executed changes, including the target's name, a before/after preview, who proposed, approved, ran, or reversed them, and when;
- an audit trail of significant events (see 2.5);
- change-notification subscriptions we register with Microsoft so the Service learns about changes without polling.
2.3 Data collected by the Unify365 Connector (only if you install it)
The Connector is optional software your organization may install on a Windows server it controls, to extend the Service to systems Microsoft Graph cannot reach. It communicates outbound-only over HTTPS to Unify365 and collects only from the collection domains your organization enables, which can include: Active Directory objects and configuration (users, computers, groups, organizational units, trusts, replication and domain-controller health); Group Policy objects and their settings; Configuration Manager (SCCM/MECM) site, client, deployment, and update-compliance data; server inventory and health; DNS and DHCP configuration; certificate services and certificate inventory; hybrid-identity component state (for example, synchronization service status); and event-log entries relevant to a finding. Every collector in use and every batch sent is listed in a transparency log in the Service, and your organization can disable or redact collectors at any time. The Connector never stores domain-administrator credentials, and its service account is provisioned by your organization with the permissions your organization chooses.
If your organization separately enables sensitive-data discovery on file servers, the Connector reports counts, file locations, and hashes of pattern matches (such as apparent government-ID or payment-card numbers). It does not upload file contents.
2.4 Content you provide
We collect the questions you ask UnifyQ and the answers, plans, and recommendations it produces; notes you attach to a tenant; saved queries; report definitions, including the email addresses of report recipients; alert and integration destinations you configure (for example a Microsoft Teams channel or a SIEM endpoint; secrets for those integrations are referenced by name and are not stored in our database); role and scope assignments for your Users; and anything you send us in support, sales, or security correspondence.
2.5 Usage, device, and log information
The Service keeps an audit trail of significant events for your organization: the action, the resource affected, a small amount of contextual metadata, the acting User, the IP address and browser user-agent of the request, and the time. UnifyQ questions are recorded in the audit trail as short summaries. Our hosting providers also keep standard server and error logs (request paths, status codes, IP addresses, timestamps, and error diagnostics) that we use to operate and secure the Service.
2.6 Billing information
When your organization purchases through the Microsoft commercial marketplace, Microsoft is the merchant of record. Microsoft sends us the subscription identifier, plan, quantity, status, and the purchasing tenant and purchaser contact details it holds; we never receive payment-card or bank details. For subscriptions we invoice directly, we collect the billing contact and address you give us and keep invoice and payment records.
2.7 Cookies and similar technologies
The Service uses only strictly necessary cookies: the session cookie that keeps you signed in and a token that protects against cross-site request forgery. Your theme and layout preferences are kept in your browser's local storage and are never sent to us. Our Site does not use advertising cookies, third-party analytics, or tracking pixels, and does not load fonts or scripts from third-party domains at run time. Because we do not track visitors across sites, the Site does not respond differently to "Do Not Track" or Global Privacy Control signals; there is no tracking to opt out of.
2.8 Information we do not collect
We do not collect passwords, payment-card numbers, or precise geolocation, and we do not knowingly collect information from children (Section 11).
3. How we use information
We use the information above to:
- provide the Service — authenticate you, connect you to your organization's tenants, display and analyze tenant data, generate UnifyQ answers, and execute the changes your organization approves;
- keep records your organization relies on — the audit trail, history, and before/after previews that make every change reviewable and reversible;
- secure the Service — detect, investigate, and prevent unauthorized access, abuse, and security incidents, and enforce tenant isolation and role-based access;
- bill and administer subscriptions, meter plan limits and UnifyQ allowances, and communicate about your account, service changes, and security;
- support you and respond to your requests;
- improve the Service, using aggregated or de-identified usage statistics, product telemetry, and feedback — never by training AI models on Customer Data;
- comply with law, enforce our Terms, and protect our rights and the rights of others; and
- market to organizations, in a limited way: we may send account owners and administrators information about new features or plans. Every marketing email includes an unsubscribe link, and we do not use Customer Data for marketing.
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar rules, our legal bases are: performance of our contract with your organization (or with you, for your account); our legitimate interests in operating, securing, and improving the Service and communicating with customers, balanced against your rights; your consent, where we ask for it; and compliance with legal obligations. Where we act as a processor, the customer organization is responsible for its own legal basis.
4. UnifyQ and automated processing
When you ask UnifyQ a question or ask it to investigate or draft a change, your question and the tenant data its tools retrieve to answer it are sent to the UnifyQ inference service, which runs on AI infrastructure operated for us by an enterprise AI provider under contract. Those contracts require that your data is used only to generate the response, is not used to train or improve the provider's models, and is retained by the provider, if at all, only for a short period and solely to detect misuse of its service. UnifyQ shows you what each answer was grounded on. Customers on plans that support it may instead route UnifyQ processing through inference credentials they supply; that processing is then governed by the customer's own agreement with its provider.
UnifyQ does not make decisions that produce legal or similarly significant effects about individuals on its own. Every change it drafts is applied only after a person in your organization reviews and approves it, or within the limits of an automation that a person in your organization deliberately configured.
5. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- Microsoft. Microsoft Graph, Microsoft Entra ID, and the Microsoft commercial marketplace are integral to the Service; the calls we make to Microsoft on your behalf carry the data needed to make them, under Microsoft's terms.
- Subprocessors that host and run the Service. We use a cloud application-hosting platform, a managed PostgreSQL database provider, and the AI inference provider described in Section 4, each located in the United States and bound by written data-processing terms. Our current subprocessors are Vercel, Inc. (application hosting and edge network), Neon, Inc. (managed database), Microsoft Corporation (identity, Graph, and marketplace), and our AI inference provider. We will give customers at least thirty (30) days' notice before adding a subprocessor that processes Customer Data; a current list is available from hello@unify365.ai.
- Destinations your organization configures. Scheduled reports are sent from a mailbox in your own tenant using Microsoft Graph, not through a third-party email service. Alerts and audit events are delivered to the Microsoft Teams channels, webhooks, or SIEM endpoints your organization sets up, and exports go where your Users send them.
- Professional advisors and legal process. We may disclose information to our lawyers, accountants, and insurers; to comply with law, subpoenas, or court orders; to enforce our Terms; or to protect the safety, rights, or property of Unify365, our customers, or others. If we receive a legal demand for Customer Data, we will direct the requester to the customer where lawful, notify the customer unless legally prohibited, and disclose only what we are required to.
- Business transfers. If Unify365 is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
- With your direction or consent.
Aggregated or de-identified statistics that cannot reasonably identify any person or customer are not personal information and may be shared freely.
6. International transfers
The Service is hosted in the United States, and we process information there. If you or your organization are located outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those of your country. For customers in the European Economic Area, the United Kingdom, and Switzerland, we transfer personal data under the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), which are incorporated in our Data Processing Addendum, and we apply supplementary measures such as encryption in transit and at rest.
7. How long we keep information
| Information | Retention |
|---|---|
| Account records (name, email, tenant, role) | While the account is active, then deleted within 30 days of closure |
| OAuth tokens | Until they expire, are refreshed, or your organization revokes consent |
| Audit trail | At least the retention period of your organization's plan — 7 days (Free), 90 days (Team), 400 days (Business and MSP), or 7 years (Enterprise) — after which it may be deleted on a rolling basis |
| Configuration snapshots, drift records, and other history | Your plan's retention window, then deleted on a rolling basis |
| Access graph, device inventory, SaaS estate, findings | Refreshed on a schedule; superseded records are removed; deleted when the tenant is disconnected |
| Proposed and executed changes, before/after previews | While the tenant is connected (needed to reverse changes and for the audit trail), then per the audit retention above |
| UnifyQ questions and responses | Summaries in the audit trail per the retention above; full text is not retained by us beyond the session; our inference provider's short misuse-detection window applies (Section 4) |
| Marketplace and invoice records | As required by tax and accounting law — generally 7 years |
| Support and other correspondence | Up to 3 years after the last contact |
| Server and error logs | Up to 90 days |
| Backups | Retained for a limited rolling period for disaster recovery, then overwritten; data deleted from the live system is not restored from backup except to recover from a failure |
When your organization disconnects a tenant, revokes our permissions, or ends its subscription, we delete the Customer Data for that tenant within 30 days of the end of the export period described in the Terms, except where law requires longer retention. Your organization can ask us to delete sooner at any time.
8. How we protect information
We maintain a security program appropriate to the sensitivity of the data we handle. Measures include: encryption of data in transit (TLS) and at rest; isolation of each customer's data, with the tenant derived from the sign-in itself and never from a value a request can supply; least-privilege Microsoft Graph permissions with a separate consent for any write access; role-based access and optional two-person approval for changes; an audit trail that records who did what and when; secrets kept in managed secret storage rather than in code; automated security and tenant-isolation tests on every release; and a coordinated vulnerability-disclosure process (security@unify365.ai). Our Trust page describes these measures in more detail. No method of transmission or storage is completely secure; if we confirm a security incident affecting your data, we will notify affected customers without undue delay, and in any event within 72 hours of confirming it, with the information they need to meet their own obligations.
9. Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, to correct or delete it, to receive a copy in a portable format, to restrict or object to certain processing, to withdraw consent where processing is based on consent, and to lodge a complaint with a supervisory authority. You will not be discriminated against for exercising these rights.
How to exercise your rights. Email hello@unify365.ai from the address associated with your account, or ask an administrator of your organization to contact us. We will verify your identity (usually by confirming control of the account email) and respond within the time the applicable law allows — generally within 30 days, or 45 days for California residents, extendable where permitted. If we decline a request, we will explain why, and you may appeal by replying to our response.
Choices you can make directly:
- Revoke tenant access. An administrator of your organization can remove Unify365's permissions at any time from the Microsoft Entra admin center (Enterprise applications) or at myapps.microsoft.com. Individual users can remove their own delegated consent there too.
- Delete your account or your organization's data. Email hello@unify365.ai. Administrators can also disconnect a tenant in the Service.
- Marketing. Use the unsubscribe link in any marketing email. You cannot opt out of essential service notices (such as security or billing notices) while you have an account.
California residents. The California Consumer Privacy Act gives California residents the rights described above, including the right to know what categories of personal information we collect, use, and disclose (Sections 2, 3, and 5 describe them), the right to delete, the right to correct, and the right to opt out of "sales" and "sharing". We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes other than those permitted by law. In the past twelve months we have collected the categories of personal information described in Section 2 — identifiers, professional information, commercial information (billing), internet or network activity (audit and log data), and inferences drawn from tenant signals for the security and governance purposes described above — and disclosed them to the categories of recipients described in Section 5 for business purposes. When we process personal information in a customer's tenant, we do so as a service provider to that customer.
European Economic Area, United Kingdom, and Switzerland. You may complain to the data-protection authority in the country where you live or work. Where we act as a processor, please contact the customer organization first; we will help it respond.
10. If your data is in a customer's tenant
If you are an employee, contractor, or other member of an organization that uses Unify365, we process your information as that organization's processor or service provider, on its instructions and under our contract with it. That organization decides what is connected, what is collected, who can see it, what changes are made, and how long history is kept within the limits of its plan. To exercise your rights over that data, contact your organization; if you contact us, we will refer your request to it and help it respond.
11. Children
The Service is for organizations and their authorized administrators. It is not directed to children under 16, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact hello@unify365.ai and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version at unify365.ai/legal/privacy with a new effective date and, for material changes, notify account owners and administrators by email or through the Service at least thirty (30) days before the changes take effect. Continued use after the effective date means you accept the updated Policy.
13. Contact us
Privacy questions or requests: hello@unify365.ai. Security reports: security@unify365.ai. Support: support@unify365.ai. By mail: Unify365 LLC, San Jose, California, United States.