Product Schedule — Olyteck Cyber
Last updated: 19 June 2026
This Schedule sets out the product-specific particulars for Olyteck Cyber and forms part of the Olyteck Data Processing Agreement. The framework (processor obligations, security measures, audit, transfers, change procedure) is in the master DPA; this page is the authoritative, version-dated list of the facts that differ between products.
1. Processing
Purpose: Read-only Microsoft 365 security posture, asset-hygiene and storage-cost scanner for SharePoint, OneDrive, Teams and Entra ID.
Data minimisation: Counts findings, never files. Cyber reads configuration and permission metadata via Microsoft Graph and stores only aggregate findings; detailed evidence stays in the administrator's browser. No message bodies, file contents or attachments are read.
AI / LLM: AI used only for report text and optional voice-over; not for processing customer file contents.
Microsoft Graph scopes:
Read-only configuration and permission metadata (no content read scopes)
2. Categories of personal data
- Microsoft 365 configuration and permission metadata (aggregate findings, counts, severities)
- Account and billing data
3. Retention
| Data | Retention window |
|---|---|
| Account data | While the account is active, plus 30 days after deletion |
Billing records are kept 10 years (French accounting law); audit logs 24 months — see master DPA §7.
4. Sub-processors
Each is bound by a written contract imposing data-protection obligations equivalent to the master DPA. This list is authoritative and version-dated.
| Sub-processor | Service | Region |
|---|---|---|
| Microsoft Ireland Operations Ltd. | Authentication (Entra ID) + read-only Microsoft Graph metadata provider DPA → |
EU (Ireland) / customer tenant region |
| Scaleway SAS | EU hosting (application, database, backups) | France (PAR1) |
Mistral AI no training on API data |
Report text generation provider DPA → |
EU (France) |
ElevenLabs Inc. opt-in |
Text-to-speech (only when voice-over is requested) | US (SCCs) |
| Stripe Payments Europe, Ltd. | Card payment processing & billing provider DPA → |
EU / Ireland |
5. Changes to this Schedule
Any addition or replacement of a sub-processor that materially handles Customer personal data is posted here at least 30 days before it takes effect, so the Customer can review and object on reasonable grounds. Customers may subscribe to e-mail notifications, or raise an objection, by emailing [email protected]. See the master DPA §6 for the full procedure, and the Trust Center for the company-wide view.