Privacy Policy
Cloud Apps Mastery Ltd, a UK-based company and proud Microsoft AI startup backed and ISV partner, is committed to protecting your privacy while using our product, M365Chatbuddy. Below is an outline of how we handle data and ensure your security, especially in Microsoft Teams and SharePoint environments.
Data Collection
At Cloud Apps Mastery Ltd, we prioritise user privacy. We do not collect or process personal data beyond what is necessary for authentication purposes. When using M365Chatbuddy, the only data point we require is your account’s authentication to ensure valid access to our AI model. No personal data such as names, email addresses, or user activity logs are collected or stored.
Integration with Microsoft Teams and SharePoint
When our app is used within Microsoft Teams or SharePoint, the application operates with the permissions granted by your Microsoft tenant. M365Chatbuddy does not access any files, conversations, or other user-generated content within these platforms. It simply provides assistance by answering Microsoft 365-related queries without collecting or processing your internal data.
Data Usage
The interactions you have with M365Chatbuddy are session-based, meaning that questions asked are not stored. Each session starts anew, ensuring that no prior queries or interactions are retained or analysed for future use. Our system is built to be ephemeral — ensuring your queries remain confidential and are used solely to generate the immediate response needed for your query.
No Data Logging or Profiling
Unlike other AI or chatbot solutions, M365Chatbuddy does not log user activity or profile users based on their usage patterns. We respect your privacy by ensuring that each interaction with our assistant is entirely private and secure.
Data Security
Security is at the core of everything we do. We leverage Microsoft’s industry-leading security standards to protect your interactions with M365Chatbuddy. Your tenant is securely onboarded as a trusted guest to our AI backend, ensuring that the system remains isolated from your internal data.
Encryption: All communications between M365Chatbuddy and your Microsoft tenant are encrypted in transit and at rest using Microsoft's advanced encryption protocols.
Access Control: M365Chatbuddy operates under the principle of least privilege, meaning that the app will only have the minimum access rights needed to function effectively. Your tenant’s data and documents remain entirely off-limits.
Role-Based Permissions: You have control over which users in your organisation can access M365Chatbuddy. Admins can manage user permissions directly through Microsoft Teams or SharePoint settings.
Third-Party Sharing
We maintain a strict no data sharing policy. M365Chatbuddy operates solely within the confines of Azure AI and Azure OpenAI models, which are governed by Microsoft’s rigorous security standards. We do not share any user data with third parties, and we do not use public or open-source AI models.
Any data exchanged during interactions with M365Chatbuddy is confined to your immediate session and is not stored or shared with external parties. Our commitment to security means that your questions and the responses generated stay within your organisation.
User Rights
As a user of M365Chatbuddy, you have the right to use our services without concern for privacy breaches. Your organisation’s administrator will have control over the access rights to M365Chatbuddy and can revoke or grant access to specific users as needed.
Data Deletion: Since no user data is collected or stored, there is no requirement for data deletion requests. However, administrators can uninstall the app at any time, terminating all future interactions with M365Chatbuddy.
Custom Queries: Users are encouraged to ask M365-related questions, and M365Chatbuddy will assist without accessing personal data or internal documents.
Cookies
To be confirmed (TBC).
Compliance and Legal Requirements
We ensure that M365Chatbuddy adheres to GDPR and other data protection regulations relevant to the UK and the European Union. Since we do not process or store personal data, our compliance is straightforward. However, we stay updated with all legal requirements to ensure continued adherence as regulations evolve.