Product Schedule — Olyteck Guard
Last updated: 19 June 2026
This Schedule sets out the product-specific particulars for Olyteck Guard and forms part of the Olyteck Data Processing Agreement. The framework (processor obligations, security measures, audit, transfers, change procedure) is in the master DPA; this page is the authoritative, version-dated list of the facts that differ between products.
1. Processing
Purpose: EU-hosted email threat analysis, warning banners and response for Microsoft 365. Guard scores inbound messages for spoofing/auth, impersonation, BEC and malicious links/QR/attachments.
Data minimisation: Counts findings, never files. Message bodies and attachments are analysed transiently and never persisted; Guard stores only signals, scores, verdicts and minimal metadata.
AI / LLM: No AI / LLM sub-processors. Verdicts are produced by an explainable, rules-and-models detection engine.
Microsoft Graph scopes:
Mail.ReadMail.ReadWriteUser.Read.AllDirectory.Read.AllOrganization.Read.All
2. Categories of personal data
- Mailbox metadata and message signals (headers, auth results, sender/domain, link/attachment indicators)
- Detection scores and verdicts
- Account, tenant and billing data
3. Retention
| Data | Retention window |
|---|---|
| Account / tenant data | While the subscription is active and Graph consent is granted, plus 30 days after deletion |
| Messages, signals and detections | Plan-based: Essentials 30 days, Business 12 months, Enterprise custom |
Billing records are kept 10 years (French accounting law); audit logs 24 months — see master DPA §7.
4. Sub-processors
Each is bound by a written contract imposing data-protection obligations equivalent to the master DPA. This list is authoritative and version-dated.
| Sub-processor | Service | Region |
|---|---|---|
| Microsoft Ireland Operations Ltd. | Identity (Entra ID) + customer mail via Microsoft Graph (admin-consented) provider DPA → |
EU (Ireland) / customer tenant region |
| Scaleway SAS | EU hosting (application, PostgreSQL, backups) | France (PAR1) |
| Stripe Payments Europe, Ltd. | Card payment processing & subscription billing (Stripe Checkout / Tax) provider DPA → |
EU / Ireland |
| Microsoft 365 (Exchange Online) | Transactional email delivery (Olyteck Mailer) | EU |
Google Safe Browsing opt-in |
URL reputation lookups (opt-in, GUARD_SAFEBROWSING_KEY) | Global |
5. Changes to this Schedule
Any addition or replacement of a sub-processor that materially handles Customer personal data is posted here at least 30 days before it takes effect, so the Customer can review and object on reasonable grounds. Customers may subscribe to e-mail notifications, or raise an objection, by emailing [email protected]. See the master DPA §6 for the full procedure, and the Trust Center for the company-wide view.