Skip to content
TenantMCP
How it works Modules Pricing DPA Portal

Legal

Privacy Policy

Last updated: 21 July 2026  ·  Controller / provider: Circle of Bytes ApS, Denmark

This Privacy Policy explains how Circle of Bytes ApS ("Circle of Bytes", "we", "us"), a company registered in Denmark, handles personal data in connection with the TenantMCP service ("the Service") available at tenantmcp.com and mcp.tenantmcp.com.

TenantMCP is a business-to-business service. It gives a customer's AI assistants (such as Claude, Claude Code, or another Model Context Protocol client) approval-gated, audited access to that customer's own Microsoft 365 tenant. We designed the Service to relay Microsoft 365 data on demand rather than to warehouse the contents of your tenant.

This policy covers two situations that are legally distinct, described in section 2:

  • where we act as a data processor on behalf of a customer (the Microsoft 365 data your assistant reads through the Service, and the operational records we keep about its use); and
  • where we act as a data controller in our own right (account, billing, and website data).

Contents

  1. Who we are and how to contact us
  2. Our role: processor vs controller
  3. What data we process
  4. Purposes and legal bases
  5. The relay model: what we do not store
  6. Who can access the Service
  7. Sub-processors
  8. International data transfers
  9. Retention
  10. Security measures
  11. Your data protection rights
  12. Children
  13. Changes to this policy
  14. Contact and complaints

1. Who we are and how to contact us

The provider of the Service is Circle of Bytes ApS, a company incorporated in Denmark. For any privacy question, request, or complaint about the Service, contact us at privacy@tenantmcp.com.

We have not appointed a statutory Data Protection Officer. Privacy matters are handled by the contact above.

2. Our role: processor vs controller

As a processor. When your AI assistant reads data from your Microsoft 365 tenant through TenantMCP, and when we record operational metadata about that activity (see section 3), we act as a data processor on behalf of the customer organisation, which is the controller of that data. We process it only on the customer's documented instructions, which are given through the configuration of the Service and, where applicable, the Data Processing Addendum. Our Data Processing Addendum governs this relationship.

As a controller. For the limited data we need to run our business - account records for the administrators who sign in, billing and subscription data, support correspondence, and basic website operation - we act as a data controller. Sections 3 and 4 identify which basis applies to each category.

3. What data we process

3.1 Microsoft 365 data relayed on demand (processor)

When an administrator's assistant calls a tool, the Service uses a per-tenant Microsoft Graph token to fetch the requested data from Microsoft, shapes it into a concise response, and returns it to the assistant. This can include personal data present in your tenant, such as device names and hardware details, user principal names and display names, compliance and configuration state, and installed-software inventory. This data is fetched to answer the request and is not written into a long-term store of tenant contents by TenantMCP (see section 5).

3.2 Operational records we retain (processor)

To provide the approval workflow, the audit trail, and metering, we store operational records, not tenant content. These include:

  • Approval decisions - pending write actions proposed by an assistant, the intended change, the identity of the administrator who approved or rejected it, the reason given, and the outcome.
  • Audit metadata - a record of who did what and when: which administrator or assistant invoked which tool, the timestamp, the tenant, and the result status. This is the defensible trail described on our home page.
  • Metering counts - per-call usage counters used to enforce the free-tier call cap and to support billing.
  • Tenant and configuration records - the tenant's identifier from Microsoft Entra, which modules are enabled, and the consent status.

3.3 Account, authentication, and billing data (controller)

  • Administrator sign-in data - the identifier, name, and email address that Microsoft returns for an administrator who signs in to the portal or authorises an MCP client, and whether that person holds an administrator role in the tenant.
  • OAuth token material - TenantMCP issues its own OAuth tokens to MCP clients. We store these as hashes, together with expiry and rotation state, so that tokens can be validated and revoked. We do not store OAuth tokens issued to clients in plaintext. Per-tenant Microsoft Graph credentials are held in a secured secret store (see section 10).
  • Billing data - subscription tier and status. Card payments, if any, are handled by our payment processor; we do not store full card numbers.
  • Support correspondence - messages you send us and our replies.

3.4 Website and technical data (controller)

The marketing site (tenantmcp.com) is a static page and does not use tracking or advertising cookies. Our hosting and infrastructure produce standard technical logs (for example request and error logs) used to operate and secure the Service.

4. Purposes and legal bases

Where we act as controller, we rely on the following legal bases under the EU General Data Protection Regulation (GDPR):

PurposeDataLegal basis (GDPR Art. 6)
Authenticate administrators and operate the portal and MCP endpointSign-in data, OAuth token hashesArt. 6(1)(b) - performance of a contract
Provide and support the Service; keep it secure and availableAccount, configuration, technical logsArt. 6(1)(b) contract; Art. 6(1)(f) legitimate interests in security and reliability
Billing and subscription managementBilling dataArt. 6(1)(b) contract; Art. 6(1)(c) legal obligation (accounting)
Respond to enquiries and support requestsSupport correspondenceArt. 6(1)(f) legitimate interests in supporting our customers

Where we act as processor (sections 3.1 and 3.2), the customer organisation determines the purposes and the legal basis for the underlying personal data. We process it only to provide the Service on that customer's instructions.

5. The relay model: what we do not store

TenantMCP is built as a relay. When an assistant asks a question about your tenant, we call Microsoft Graph, shape the result, and return it. We do not maintain a mirror or warehouse of your directory, devices, or documents, and we do not use your tenant data to train any machine-learning model. What persists on our side is the operational record described in section 3.2: approval decisions, audit metadata, metering counts, and configuration. This design keeps the amount of personal data we hold to the minimum needed to run the approval and audit features.

Note on write actions: an assistant can never change your tenant on its own. A proposed write is queued as a pending action and executed only after a human administrator approves it in the portal. The proposed change and the approval decision are recorded in the audit trail.

6. Who can access the Service

Access to a customer tenant through TenantMCP is restricted to directory administrators. The Service issues an access token to an MCP client only when the signed-in user holds an administrator role in the tenant. Non-administrator members of a tenant cannot obtain tenant-wide data through the Service. On our side, access to production systems and customer data is limited to authorised Circle of Bytes personnel on a need-to-know basis, under role-based access controls.

7. Sub-processors

We use the following sub-processor to provide the Service:

Sub-processorPurposeLocation of processing
Microsoft (Microsoft Azure)Cloud hosting and platform: application compute, database, secret storage, and loggingEuropean Union - compute in the North Europe region (Ireland); database in the Sweden Central region

Note that Microsoft is also the operator of the customer's own Microsoft 365 / Entra tenant, which is the source system the Service relays from. Our payment processing is handled by a third-party payment provider that acts as an independent controller for the payment transaction. We will give affected customers advance notice of any new or changed sub-processor as set out in the Data Processing Addendum.

8. International data transfers

We host and process personal data for the Service in European Union Azure regions (North Europe for compute, Sweden Central for the database). We select EU regions specifically to keep processing within the EU. Where a provider such as Microsoft may, for support or platform operation, process limited data outside the EU/EEA, such transfers are covered by appropriate safeguards under Chapter V of the GDPR, including the European Commission's Standard Contractual Clauses and the providers' own data protection commitments.

9. Retention

  • Relayed Microsoft 365 data (3.1) - processed transiently to answer a request and not retained by TenantMCP as tenant content.
  • Approval decisions and audit metadata (3.2) - retained for the life of the customer's subscription to provide the audit trail, and for a limited period after termination so the record remains available, after which it is deleted or anonymised. We will agree a specific audit-log retention period with the customer in the Data Processing Addendum or order.
  • Metering counts - retained as needed for cap enforcement and billing, then aggregated or deleted.
  • Account and OAuth token records - kept while the account is active; token hashes are deleted or invalidated on expiry, rotation, or revocation.
  • Billing records - retained as required by applicable accounting and tax law.
  • Technical logs - retained for a limited period for security and troubleshooting.

On termination, we delete or return customer personal data processed on the customer's behalf in accordance with the Data Processing Addendum, subject to any retention we are legally required to observe.

10. Security measures

We take technical and organisational measures appropriate to the risk, including:

  • Managed identity for service-to-service authentication where supported, in preference to stored credentials.
  • Secrets in a managed key vault protected by role-based access control, rather than in application configuration or source code.
  • Per-tenant isolation - each tenant's identity and Graph credentials are derived from a validated token claim mapped to a database record, never from client-supplied input, so one tenant cannot reach another's data.
  • Approval-gated writes - no path from a tool call to a change in your tenant without a recorded human approval.
  • Admins-only access and role-based access controls for both customer administrators and our own staff.
  • Audit logging of tool calls and approval decisions.
  • Token hardening - OAuth tokens issued to clients are stored as hashes, are audience-bound and lifetime-limited, and refresh tokens rotate and can be revoked.
  • Encryption in transit (TLS) and at rest on the underlying Azure platform.

No system is perfectly secure. If we become aware of a personal data breach affecting customer data, we will notify affected customers without undue delay as required by the GDPR and the Data Processing Addendum.

11. Your data protection rights

Under the GDPR you have rights over your personal data, including the rights of access, rectification, erasure, restriction, objection, and data portability, and the right to withdraw consent where processing is based on consent.

Where we are the processor (data from your Microsoft 365 tenant and the operational records about it), you should usually direct requests to the customer organisation that controls that data. We will assist that controller in responding, as set out in the Data Processing Addendum.

Where we are the controller (account, billing, support), you can exercise your rights by contacting us at privacy@tenantmcp.com. We may need to verify your identity before acting on a request.

12. Children

The Service is a business tool intended for use by organisations and their administrators. It is not directed at children and we do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy as the Service evolves. We will change the "Last updated" date above and, for material changes affecting customers, provide notice through the portal or by email.

14. Contact and complaints

Circle of Bytes ApS

Denmark

Privacy contact: privacy@tenantmcp.com

If you are in the EU/EEA and believe we have not handled your personal data lawfully, you have the right to lodge a complaint with a supervisory authority. In Denmark this is the Danish Data Protection Agency (Datatilsynet).

TenantMCP

The safe bridge between AI assistants and your Microsoft tenant.

A Circle of Bytes ApS product. Denmark, EU.

How it works Modules Pricing FAQ Portal Contact Privacy DPA
© 2026 Circle of Bytes ApS. All rights reserved. Microsoft 365 and Intune are mentioned for compatibility only. TenantMCP is not affiliated with or endorsed by Microsoft.