16 articles
Reference·10 min

Effective date: July 16, 2026

Provider: M365Suite LLC, entity ID 12047339, an active Virginia-qualified limited liability company.

This Privacy Policy explains how M365Suite LLC ("M365Suite," "we," "us," or "our"), handles personal information when you visit our websites, use the M365Suite service, contact support, or interact with our documentation.

1. Information we collect

We collect the following categories of information:

  • Account and identity data: name, work email, organization, account identifiers, role, authentication events, and account preferences.
  • Service data: SharePoint site URLs and metadata, navigation structures, backup versions, recovery and change-monitoring records, tenant settings, audit events, and support requests.
  • Billing data: plan, subscription status, billing email, invoices, payment status, and Stripe customer or subscription identifiers. Stripe processes payment-card details on our behalf; M365Suite does not store full card numbers.
  • Technical data: IP address, browser and device information, timestamps, diagnostic and security information, approximate region, and security logs.
  • Communications: information you provide in support requests, invitations, feedback, or business inquiries.

We do not intentionally collect passwords, private keys, or unrelated sensitive personal information through ordinary Service use. Do not place such information in navigation labels, site metadata, or support requests.

2. How we use information

We use information to:

  • authenticate users and protect account and tenant access;
  • discover, back up, compare, monitor, export, and restore SharePoint navigation data at your direction;
  • provide account administration, invitations, support, notifications, and documentation;
  • create and manage subscriptions, payments, invoices, tax handling, and entitlement limits;
  • secure the Service, detect abuse, investigate incidents, prevent fraud, and maintain audit records;
  • troubleshoot, measure reliability, improve the Service, and communicate operational notices; and
  • comply with law, enforce agreements, and protect rights and safety.

We do not sell Customer Data. We do not use Customer Data from connected Microsoft tenants for advertising.

3. Roles and instructions

For Customer Data that you place in or connect to the Service, your organization generally acts as the controller or business and M365Suite acts as a processor or service provider. M365Suite processes that data on your documented instructions to provide the Service. The Data Processing Addendum contains the processing terms and security commitments for customers that require them.

For account, billing, website, and direct business-contact information, M365Suite may act as a controller or business. The applicable law and relationship determine the role.

4. Sources

We receive information from you, your organization, authorized Microsoft services, Stripe for billing events, service providers that support hosting and operations, your browser, and publicly available or business contact sources.

5. Sharing and service providers

We share information only as needed to operate the Service, including with:

  • cloud hosting, storage, monitoring, and security providers that support the Service;
  • Microsoft services to authenticate and perform requested tenant operations;
  • Stripe for checkout, subscription management, payment processing, invoices, and billing events;
  • email and notification providers for invitations, access requests, and operational messages;
  • security, analytics, support, legal, accounting, and professional advisers under confidentiality obligations; and
  • authorities or other parties when required by law, legal process, safety needs, or a business transaction such as a merger or asset sale.

We require service providers to protect information appropriate to their role. A current subprocessor list and contact for subprocessor questions are available from contact@m365suite.com.

6. Microsoft permissions and third-party privacy

When an administrator grants consent, M365Suite uses the Microsoft permissions displayed in the consent flow and documentation. Microsoft processes identity and Microsoft 365 data under Microsoft's own terms and privacy statement. Revoking consent or changing tenant permissions may stop some Service features.

Stripe processes payment information under Stripe's terms and privacy notice. Links to third-party services may take you to policies we do not control.

7. Retention and deletion

We retain account and Service data for as long as needed to provide the Service, satisfy the organization's configured backup/version policy, resolve disputes, maintain security and audit records, comply with law, and enforce agreements. Backup version retention is subject to the tenant's configured policy and plan limits; the Service may retain limited deletion, billing, security, and audit records after content deletion where reasonably necessary.

A tenant administrator can use the Service's disconnect, delete, purge, or other available controls as applicable. Deletion requests are processed according to the Service configuration, technical recovery windows, legal obligations, and the DPA. The default operational retention is 30 backup versions, subject to the tenant's plan and settings; deletion and purge requests are targeted for completion within 30 days after a valid request, subject to recovery windows and required records.

8. Security

We use reasonable administrative, technical, and organizational measures including encrypted transport, protected storage, tenant isolation, role-based authorization, access controls, audit records, backup durability controls, and incident monitoring. No transmission or storage system is guaranteed to be completely secure.

9. International transfers

M365Suite and its providers may process information in countries where we or they operate. Where required, we use an approved transfer mechanism such as an adequacy decision, standard contractual clauses, or another lawful safeguard. Customer-specific transfer terms can be included in the DPA.

10. Cookies and analytics

We use cookies and similar technologies required for sign-in, session security, preferences, load balancing, and abuse prevention. We may use limited operational analytics to understand reliability and product use. We will provide any consent choices required by applicable law and will not use non-essential tracking in authenticated areas without the required notice or consent.

Current analytics disclosure: M365Suite uses essential session and security cookies. Non-essential analytics is not required for the Service and is not enabled in authenticated portal workflows unless separately disclosed and consented to where required.

11. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing is based on consent. You may also have a right to appeal a decision or complain to a data protection authority.

Requests about Customer Data should normally be directed to the organization that controls that data. Requests about M365Suite's own account or business-contact processing may be sent to contact@m365suite.com. We may verify identity and coordinate with your organization before responding.

12. Children

The Service is intended for business users and is not directed to children. We do not knowingly collect personal information from children through the Service.

13. Changes

We may update this Policy when our practices, Service, or legal obligations change. We will post the revised version with a new effective date and provide additional notice where required.

14. Contact

Privacy contact: contact@m365suite.com

Legal entity: M365Suite LLC, entity ID 12047339

Postal address: M365Suite LLC, Virginia, United States. Email contact: contact@m365suite.com