Version: DPA v1.0
Effective date: July 16, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement between M365Suite LLC (entity ID 12047339, an active Virginia-qualified limited liability company) ("M365Suite," "Processor," "we," or "us"), and the customer identified in the applicable order ("Customer" or "Controller"). It applies when M365Suite processes Personal Data in Customer Data on Customer's behalf.
1. Definitions and roles
"Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Subprocessor" have the meanings given by applicable data-protection law. Customer is the Controller or business for Customer Data, and M365Suite is the Processor or service provider, except where M365Suite processes account, billing, security, or business-contact data for its own purposes as described in the Privacy Policy.
2. Processing instructions
M365Suite will process Personal Data only to provide, secure, support, maintain, and improve the Service as permitted by the agreement and Customer's documented instructions. The subject matter is hosted SharePoint navigation backup and recovery services. The duration is the term of the agreement plus the deletion period described below.
The purposes include authentication, site discovery, navigation capture, backup storage, recovery evidence, change monitoring, administration, notifications, support, security, billing administration, troubleshooting, and legal compliance. The categories of Data Subjects may include Customer employees, contractors, administrators, guests, and individuals whose names or identifiers appear in Customer's SharePoint data. The categories of Personal Data may include names, work email addresses, tenant and object identifiers, role and scope assignments, site URLs and metadata, navigation labels and links, audit events, IP addresses, device and login information, and support communications.
Customer is responsible for the lawfulness of its instructions, notices, consents, permissions, configuration, and use of the Service. Customer will not instruct M365Suite to process prohibited or highly regulated data unless the parties have agreed to the required additional terms.
3. Confidentiality
M365Suite will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate security training. M365Suite will not disclose Personal Data except to authorized personnel, approved Subprocessors, Customer's instructions, or as required by law.
4. Security measures
M365Suite will maintain reasonable technical and organizational measures appropriate to the risk, including:
- tenant and organization isolation;
- role-based access control, scope enforcement, and privileged-access safeguards;
- encrypted transport and protected cloud storage;
- protected credentials and controlled administrative access;
- backup durability checks, deletion workflows, and recovery procedures;
- audit records, operational monitoring, and incident response procedures; and
- personnel, access, change-management, and business-continuity controls appropriate to the Service.
M365Suite will periodically test or review these measures and address material weaknesses according to risk.
5. Subprocessors
Customer authorizes M365Suite to use the following categories of Subprocessors: cloud hosting and storage providers, Microsoft services, Stripe billing, email delivery, monitoring, security, and professional services providers. The current named list is available from contact@m365suite.com on request.
M365Suite will require Subprocessors to protect Personal Data through written obligations appropriate to their processing. M365Suite remains responsible for its Subprocessors' performance to the extent required by applicable law.
M365Suite will provide notice of material Subprocessor changes where required by law or the agreement. Customer may object on reasonable data-protection grounds within 30 days. The parties will work in good faith to resolve an objection; if no reasonable resolution is available, Customer may use the termination right in the agreement.
6. Data-subject requests
M365Suite will provide reasonable assistance, taking into account the nature of processing, for Customer to respond to Data Subject requests. Customer should direct requests to M365Suite at contact@m365suite.com and provide the information needed to locate the request. M365Suite will not respond directly except on Customer's documented instruction or where required by law.
7. Security incidents
M365Suite will notify Customer without undue delay after confirming a Personal Data breach affecting Customer Data. The notice will include available information about the nature of the incident, affected data, likely consequences, mitigation, and a contact for coordination. M365Suite will not make public statements identifying Customer without consent unless required by law. Customer remains responsible for legally required notices to its regulators and Data Subjects unless the parties agree otherwise.
Security contact: contact@m365suite.com
8. Assistance and audits
M365Suite will provide reasonable information needed to demonstrate compliance with this DPA, including available security documentation and relevant audit summaries. Customer may request an audit no more than once per year, with reasonable notice, during normal business hours, subject to confidentiality, security, and non-disruption requirements. Audits must not expose another customer's data, secrets, or security-sensitive infrastructure.
If an audit identifies a material deficiency, M365Suite will work with Customer on a reasonable corrective plan. Customer bears its audit costs unless the parties agree otherwise.
9. International transfers
Where Personal Data is transferred across borders, the parties will use a lawful transfer mechanism required by applicable law, such as an adequacy decision, the 2021 EU Standard Contractual Clauses, or an approved alternative. If standard contractual clauses are required, the parties will complete the applicable modules and annexes in the customer order or DPA signature package.
10. Return and deletion
At the end of the Service, M365Suite will, at Customer's choice and where technically available, return or delete Customer Data within 30 days, subject to backup cycles, recovery windows, legal retention, security records, billing records, and the Service's documented purge behavior. Data retained under an exception remains protected and is deleted when the retention reason ends.
Customer is responsible for exporting data it needs before termination and for confirming the deletion instruction. M365Suite may retain aggregated or de-identified information that does not identify Customer or a Data Subject.
11. Government requests and compelled disclosure
If legally permitted, M365Suite will notify Customer of a request for Customer Data and reasonably direct the requester to Customer. M365Suite will disclose only the information legally required and will use reasonable efforts to protect confidentiality.
12. Order of precedence
If this DPA conflicts with the Terms, this DPA controls for the subject of data protection. If the parties have signed a negotiated DPA or order with stricter terms, the negotiated document controls.
13. Signatures
Customer: The customer legal name shown in the applicable order or account record.
Name: ____________________ Title: ____________________ Date: ____________________
M365Suite provider: M365Suite LLC
Name: ____________________ Title: ____________________ Date: ____________________
Annex A — Processing details
- Subject matter: Hosted SharePoint navigation backup and recovery.
- Duration: Agreement term plus the agreed deletion period.
- Nature: Collection, organization, storage, retrieval, comparison, export, recovery support, deletion, and security monitoring.
- Frequency: On demand, scheduled, and administrative operations configured by Customer.
- Locations: Azure and approved Subprocessor locations listed in the current Subprocessor register.
Annex B — Security contacts and subprocessors
- Security contact: contact@m365suite.com
- Privacy contact: contact@m365suite.com
- Subprocessor list: Available from contact@m365suite.com on request.
- Incident response target: Without undue delay after confirmation; target notification within 72 hours where legally permitted.