1. Start here: in normal operation, we are not your processor
Our products run in your tenant, on your infrastructure. Your data does not flow to us as part of using them, and there is no SSS-operated service holding a copy of it. In the ordinary course of a subscription there is therefore no processing by us to govern.
This agreement exists for the exceptions — chiefly support access — and because your procurement team needs a DPA on file regardless. It is deliberately short about our obligations, because our exposure is deliberately small.
| Product | Where the data lives | Does it reach us? |
|---|---|---|
| SSS DocGen | Your Dataverse; rendering happens in a container in your Azure subscription | No customer data. Documents are returned to the caller and, unless Attach is used, stored nowhere. |
| SSS DMS | Your Dataverse and your SharePoint, read in place | No customer data. It does not migrate, copy or move anything. |
| PSA Hub | Your Dataverse, native tables | No customer data. The app runs on the Power Platform under your Entra ID. |
Licensing telemetry is the one thing that does leave your tenant in ordinary operation. It carries no customer data and is described in section 3.
2. Roles
You are the controller. You decide what personal data goes into the products, why, and for how long. You are responsible for having a lawful basis for it and for informing your own data subjects. You are responsible for the lawfulness of your instructions to us and for the accuracy of the data you put into the products.
We are a processor only in the specific circumstances in section 3, and only to the extent of them.
For our own website visitors and business contacts we are an independent controller — that is the Privacy Policy, not this document.
3. When we process your data, and why
The complete list:
| Situation | What we may see | Duration |
|---|---|---|
| Support access — diagnosing a case you have raised | Whatever is visible in the environment or record concerned, which may include personal data of your staff or clients | For the case only. Access is granted by you and ends when it closes. |
| Diagnostic material you send us — a log, a screenshot, a failing record id, an exported template | Only what you chose to include | Deleted within 90 days of the case closing. |
| Assessment, implementation and migration services, where an Order includes them | The data in scope of that engagement | For the engagement. Working copies are deleted within 30 days of completion. |
| Licensing telemetry — reported automatically by the Products | Counts of Production Environments and Users, and the tenant and environment identifiers needed to attribute them to your organisation. No document contents, no record contents, no user identifiers. | For the life of the subscription and 12 months after, for licensing and invoicing. |
Outside these, we do not access your environments. We have no standing credentials into your tenant, and we do not want any.
Licensing telemetry is the one item on that list for which we are not your processor: we determine that purpose ourselves, so for it we are an independent controller. It is on the list anyway, because a list that says it is complete has to be.
3.1 Categories of data subject and data
Determined by you, not us. In practice: your employees and contractors (identity and contact details, time and expense records, utilisation), and your clients' business contacts (names, addresses, billing details) as they appear in documents and project records. We do not require special-category data and none of the products is designed for it. If your use involves special-category data, tell us before an engagement so we can agree the extra measures.
4. Our obligations as processor
Where section 3 applies, we will:
- process personal data only on your documented instructions, including for transfers, unless required otherwise by EU or member-state law — in which case we tell you first, unless that law prohibits it;
- ensure everyone authorised to process it is bound by confidentiality;
- apply the security measures in section 5;
- not engage a sub-processor except as set out in section 6;
- assist you, taking into account the nature of the processing, in responding to data-subject requests under Chapter III GDPR;
- assist you with your obligations under Articles 32 to 36 — security, breach notification, impact assessments and prior consultation — proportionate to the information available to us;
- on your choice, delete or return the personal data at the end of the engagement, and delete existing copies unless law requires retention;
- make available the information reasonably necessary to demonstrate compliance with this section, and allow and contribute to audits under section 8;
- tell you immediately if we consider an instruction infringes the GDPR or other data protection law.
5. Security measures
The measures we apply to any of your data we hold, in the terms of Art. 32:
- Minimisation by architecture. The single largest control is that the products do not send us your data. We cannot lose what we never hold.
- Access control. Least privilege, multi-factor authentication on every account, no shared credentials, no standing access to customer environments.
- Encryption. In transit (TLS 1.2 or better) and at rest, through our platform providers.
- Secrets. Held in Key Vault or an equivalent, never in source control and never in logs. Where a product requires a secret to be held as a plain configuration value in your own environment, this is documented on the product page and in the technical documentation, with the compensating control you should apply.
- Segregation. Diagnostic material from one customer is never mixed with another's.
- Deletion. On the timescales in section 3, not "when convenient".
- Resilience. Our own systems are backed up by the platform providers in section 6. Backup of your environments remains yours, as the Terms of Service section 6 says.
6. Sub-processors
You give general authorisation for the sub-processors below. They are the same processors listed in the Privacy Policy, because we do not run a separate estate for customer data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Ireland Operations Ltd | Email, file storage and collaboration, where a support case involves material you sent us | Ireland (EU) |
| XXXXX (hosting provider) | Serving this website. Holds no customer data. | EU |
Plausible is not listed here: it never touches customer personal data, only aggregate website statistics, and it is covered by the Privacy Policy instead.
We will give you 30 days' notice before adding or replacing a sub-processor, by email to your billing contact. If you reasonably object on data-protection grounds within that period, we will work with you to find an alternative; if none is workable, you may terminate the affected Product and receive a pro-rata refund for the unexpired term.
We remain fully liable to you for a sub-processor's performance of its data-protection obligations.
7. International transfers
Our sub-processors are established in the EU and data stays in the EU. Where a sub-processor's group could access data from outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to sub-processor), with a transfer impact assessment and supplementary measures where the assessment calls for them.
Where the SCCs apply and this document conflicts with them, the SCCs prevail.
UK customers. Where you are subject to the UK GDPR, references in this agreement to the GDPR include the UK GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland, and references to a supervisory authority include the Information Commissioner. Personal data reaching us from the United Kingdom is covered by the UK's adequacy finding for the EEA, so no transfer mechanism is needed for it; where a restricted transfer under the UK GDPR does arise, the parties will enter into the ICO's International Data Transfer Addendum to the EU SCCs.
8. Audit
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and respond to a security questionnaire once in any twelve-month period. Our security and compliance review is available on request under NDA.
Where that is genuinely not enough for your regulator, you may audit — on 30 days' notice, no more than once a year unless a breach or a regulator requires otherwise, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost — save that we bear the reasonable cost of an audit that reveals a material breach by us of this agreement.
9. Personal data breach
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours of becoming aware. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed — to the extent we know them, with updates as we learn more rather than a delay until we know everything.
Notifying your supervisory authority and your data subjects is your decision as controller. We will give you what you need to make it and to make it on time.
10. Return and deletion
At the end of an engagement, or on your written request, we delete or return any of your personal data we hold and delete existing copies — except where EU or member-state law requires retention, in which case we tell you what and why.
Your production data is unaffected by any of this, because it is in your own tenant and was never anywhere else.
11. Liability and precedence
Liability under this agreement is subject to the limits in section 10 of the Terms of Service, except where the GDPR does not permit that.
This agreement takes precedence over the Terms of Service on data protection matters, and the SCCs take precedence over this agreement, as section 7 says.
12. Getting a signed copy
These terms apply automatically to every customer without signature. If your procurement or compliance process requires a countersigned DPA, or your own paper, email info@simplesmoothsafe.com and we will sign or review it. We do not treat a DPA as a negotiation.