OT Olyteck Trust Center →
Legal home Terms of Service Privacy Policy Cookie Policy Data Processing (DPA) Security overview Legal Notice

Product Schedule — Olyteck Cyber

Last updated: 19 June 2026

This Schedule sets out the product-specific particulars for Olyteck Cyber and forms part of the Olyteck Data Processing Agreement. The framework (processor obligations, security measures, audit, transfers, change procedure) is in the master DPA; this page is the authoritative, version-dated list of the facts that differ between products.

1. Processing

Purpose: Read-only Microsoft 365 security posture, asset-hygiene and storage-cost scanner for SharePoint, OneDrive, Teams and Entra ID.

Data minimisation: Counts findings, never files. Cyber reads configuration and permission metadata via Microsoft Graph and stores only aggregate findings; detailed evidence stays in the administrator's browser. No message bodies, file contents or attachments are read.

AI / LLM: AI used only for report text and optional voice-over; not for processing customer file contents.

Microsoft Graph scopes:

  • Read-only configuration and permission metadata (no content read scopes)

2. Categories of personal data

  • Microsoft 365 configuration and permission metadata (aggregate findings, counts, severities)
  • Account and billing data

3. Retention

DataRetention window
Account dataWhile the account is active, plus 30 days after deletion

Billing records are kept 10 years (French accounting law); audit logs 24 months — see master DPA §7.

4. Sub-processors

Each is bound by a written contract imposing data-protection obligations equivalent to the master DPA. This list is authoritative and version-dated.

Sub-processorServiceRegion
Microsoft Ireland Operations Ltd. Authentication (Entra ID) + read-only Microsoft Graph metadata
provider DPA →
EU (Ireland) / customer tenant region
Scaleway SAS EU hosting (application, database, backups) France (PAR1)
Mistral AI
no training on API data
Report text generation
provider DPA →
EU (France)
ElevenLabs Inc.
opt-in
Text-to-speech (only when voice-over is requested) US (SCCs)
Stripe Payments Europe, Ltd. Card payment processing & billing
provider DPA →
EU / Ireland

5. Changes to this Schedule

Any addition or replacement of a sub-processor that materially handles Customer personal data is posted here at least 30 days before it takes effect, so the Customer can review and object on reasonable grounds. Customers may subscribe to e-mail notifications, or raise an objection, by emailing [email protected]. See the master DPA §6 for the full procedure, and the Trust Center for the company-wide view.