Skip to content
TenantMCP
How it works Modules Pricing Privacy Portal

Legal

Data Processing Addendum

Last updated: 21 July 2026  ·  Processor: Circle of Bytes ApS, Denmark

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", the controller) and Circle of Bytes ApS ("Circle of Bytes", the processor) for the use of the TenantMCP service ("the Service"). It sets out how Circle of Bytes processes personal data on the Customer's behalf and reflects Article 28 of the EU General Data Protection Regulation (GDPR).

This page is the standard TenantMCP DPA offered to Customers. For a countersigned copy, or to raise specific terms, contact privacy@tenantmcp.com. Where a separately signed data processing agreement exists between the parties, that signed agreement prevails over this page.

Contents

  1. Roles of the parties
  2. Subject matter and details of processing
  3. Processing on documented instructions
  4. Confidentiality
  5. Security of processing
  6. Sub-processors
  7. International transfers
  8. Assistance to the Customer
  9. Personal data breach
  10. Return and deletion
  11. Audits and information
  12. Liability and term
  13. Annexes

1. Roles of the parties

The Customer is the controller and Circle of Bytes is the processor in respect of the personal data processed through the Service on the Customer's behalf, as described in Annex 1. Each party complies with its own obligations under applicable data protection law. Where Circle of Bytes engages another party to process data on its behalf, that party acts as a sub-processor (section 6).

2. Subject matter and details of processing

The subject matter, nature and purpose of the processing, the categories of data subjects, and the types of personal data are described in Annex 1. In summary: Circle of Bytes processes personal data from the Customer's Microsoft 365 tenant, on demand, to answer requests made by the Customer's authorised AI assistants, and maintains operational records (approval decisions, audit metadata, and metering) to provide the approval workflow and audit trail. The Service relays tenant data on demand and does not warehouse the contents of the Customer's tenant. Processing continues for the duration of the Customer's subscription unless otherwise agreed.

3. Processing on documented instructions

Circle of Bytes processes the personal data only on the Customer's documented instructions, including as configured by the Customer's administrators through the Service, unless required to do otherwise by EU or Member State law (in which case Circle of Bytes will inform the Customer unless legally prohibited). The Service, its configuration, this DPA, and the Customer's order together constitute the Customer's documented instructions. Circle of Bytes will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law.

4. Confidentiality

Circle of Bytes ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality and access it only on a need-to-know basis under role-based access controls.

5. Security of processing

Circle of Bytes implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. These include, among others: EU-region hosting; managed identity for service authentication; secrets held in a managed key vault under role-based access control; per-tenant isolation derived from validated token claims; approval-gated writes; admins-only access; audit logging; hashing, audience-binding, lifetime-limiting and rotation of issued OAuth tokens; and encryption in transit and at rest.

6. Sub-processors

The Customer grants a general authorisation for Circle of Bytes to engage sub-processors to provide the Service. The current sub-processor is:

Sub-processorService providedLocation
Microsoft (Microsoft Azure)Cloud hosting: application compute, database, secret storage, loggingEU - North Europe (compute), Sweden Central (database)

Circle of Bytes imposes on each sub-processor data protection obligations no less protective than those in this DPA and remains fully liable to the Customer for the sub-processor's performance. Circle of Bytes will give the Customer reasonable prior notice of any intended addition or replacement of a sub-processor and an opportunity to object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.

7. International transfers

Circle of Bytes hosts and processes the personal data in EU Azure regions. Circle of Bytes will not transfer personal data outside the EU/EEA except where an appropriate transfer mechanism under Chapter V of the GDPR is in place, such as the European Commission's Standard Contractual Clauses together with any necessary supplementary measures.

8. Assistance to the Customer

Taking into account the nature of the processing and the information available to it, Circle of Bytes provides reasonable assistance to the Customer in: responding to data subject requests (Chapter III of the GDPR); and meeting the Customer's obligations regarding security, breach notification, data protection impact assessments, and prior consultation (Articles 32 to 36). Because the Service records approval decisions and audit metadata and relays tenant data on demand, much of the information needed to respond to a data subject request resides in the Customer's own Microsoft 365 tenant.

9. Personal data breach

Circle of Bytes notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and provides the information reasonably available to it to help the Customer meet its own notification obligations.

10. Return and deletion

On termination of the Service, and at the Customer's choice, Circle of Bytes deletes or returns the personal data processed on the Customer's behalf and deletes existing copies, unless EU or Member State law requires continued storage. Relayed tenant data is not retained as tenant content; operational records (approval decisions, audit metadata) are deleted or anonymised after the retention period agreed in the order or Annex 1, subject to legal retention requirements.

11. Audits and information

Circle of Bytes makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable prior notice, during business hours, subject to confidentiality, and without unreasonably disrupting Circle of Bytes' operations or the security of other customers.

12. Liability and term

This DPA takes effect when the Customer starts using the Service or on the effective date of the parties' agreement, whichever is earlier, and remains in force for as long as Circle of Bytes processes personal data on the Customer's behalf. The liability of each party under this DPA is governed by the limitations and exclusions of liability in the parties' agreement. This DPA is governed by Danish law, without prejudice to the GDPR and any mandatory data protection law of the Customer's jurisdiction.

13. Annexes

Annex 1 - Details of processing

  • Nature and purpose: providing approval-gated, audited access for the Customer's AI assistants to the Customer's Microsoft 365 tenant; relaying tenant data on demand; and maintaining approval, audit, and metering records.
  • Duration: for the term of the Customer's subscription, plus the agreed audit-log retention period.
  • Categories of data subjects: the Customer's administrators and end users whose data appears in the Customer's Microsoft 365 tenant (for example device owners and directory users).
  • Types of personal data (relayed on demand): device identifiers and hardware details, user principal names and display names, compliance and configuration state, and installed-software inventory, as returned by Microsoft Graph in response to a request.
  • Types of personal data (retained as operational records): administrator identifiers, names and email addresses; administrator role status; approval decisions and reasons; tool-call audit metadata (actor, tool, timestamp, tenant, result); metering counts; tenant identifier and configuration; and hashed OAuth token records.
  • Special categories: the Service is not intended to process special categories of personal data; the Customer should not direct it to do so.

Annex 2 - Technical and organisational measures

  • Hosting in EU Azure regions (North Europe compute, Sweden Central database).
  • Managed identity for service-to-service authentication where supported.
  • Secrets stored in a managed key vault protected by role-based access control.
  • Per-tenant isolation: tenant identity and Graph credentials derived from a validated token claim mapped to a database record, never from client input.
  • Approval-gated writes: no change to a tenant without a recorded human approval.
  • Admins-only access: MCP access tokens issued only to directory administrators; role-based access controls for Circle of Bytes staff.
  • Audit logging of tool calls and approval decisions.
  • OAuth tokens issued to clients stored as hashes, audience-bound, lifetime-limited, with rotating and revocable refresh tokens.
  • Encryption in transit (TLS) and at rest on the underlying platform.

Annex 3 - Sub-processors

As listed in section 6: Microsoft (Microsoft Azure), for EU-region cloud hosting.

Circle of Bytes ApS

Denmark

DPA and privacy contact: privacy@tenantmcp.com

TenantMCP

The safe bridge between AI assistants and your Microsoft tenant.

A Circle of Bytes ApS product. Denmark, EU.

How it works Modules Pricing FAQ Portal Contact Privacy DPA
© 2026 Circle of Bytes ApS. All rights reserved. Microsoft 365 and Intune are mentioned for compatibility only. TenantMCP is not affiliated with or endorsed by Microsoft.