OT Olyteck Trust Center →
Legal home Terms of Service Privacy Policy Cookie Policy Data Processing (DPA) Security overview Legal Notice

Product Schedule — Olyteck Guard

Last updated: 19 June 2026

This Schedule sets out the product-specific particulars for Olyteck Guard and forms part of the Olyteck Data Processing Agreement. The framework (processor obligations, security measures, audit, transfers, change procedure) is in the master DPA; this page is the authoritative, version-dated list of the facts that differ between products.

1. Processing

Purpose: EU-hosted email threat analysis, warning banners and response for Microsoft 365. Guard scores inbound messages for spoofing/auth, impersonation, BEC and malicious links/QR/attachments.

Data minimisation: Counts findings, never files. Message bodies and attachments are analysed transiently and never persisted; Guard stores only signals, scores, verdicts and minimal metadata.

AI / LLM: No AI / LLM sub-processors. Verdicts are produced by an explainable, rules-and-models detection engine.

Microsoft Graph scopes:

  • Mail.Read
  • Mail.ReadWrite
  • User.Read.All
  • Directory.Read.All
  • Organization.Read.All

2. Categories of personal data

  • Mailbox metadata and message signals (headers, auth results, sender/domain, link/attachment indicators)
  • Detection scores and verdicts
  • Account, tenant and billing data

3. Retention

DataRetention window
Account / tenant dataWhile the subscription is active and Graph consent is granted, plus 30 days after deletion
Messages, signals and detectionsPlan-based: Essentials 30 days, Business 12 months, Enterprise custom

Billing records are kept 10 years (French accounting law); audit logs 24 months — see master DPA §7.

4. Sub-processors

Each is bound by a written contract imposing data-protection obligations equivalent to the master DPA. This list is authoritative and version-dated.

Sub-processorServiceRegion
Microsoft Ireland Operations Ltd. Identity (Entra ID) + customer mail via Microsoft Graph (admin-consented)
provider DPA →
EU (Ireland) / customer tenant region
Scaleway SAS EU hosting (application, PostgreSQL, backups) France (PAR1)
Stripe Payments Europe, Ltd. Card payment processing & subscription billing (Stripe Checkout / Tax)
provider DPA →
EU / Ireland
Microsoft 365 (Exchange Online) Transactional email delivery (Olyteck Mailer) EU
Google Safe Browsing
opt-in
URL reputation lookups (opt-in, GUARD_SAFEBROWSING_KEY) Global

5. Changes to this Schedule

Any addition or replacement of a sub-processor that materially handles Customer personal data is posted here at least 30 days before it takes effect, so the Customer can review and object on reasonable grounds. Customers may subscribe to e-mail notifications, or raise an objection, by emailing [email protected]. See the master DPA §6 for the full procedure, and the Trust Center for the company-wide view.