Privacy Policy
Last updated: 19 June 2026
Summary. Olyteck builds EU-hosted AI and cybersecurity for Microsoft 365. We collect the minimum personal data needed to run your account, bill you and operate each product, and we follow a strict data-minimisation rule — "counts findings, never files." Your data stays in the EU, is isolated from every other customer at the database level, and is never used to train our own models. What each product processes and stores (and what it never stores) is detailed in that product's DPA Schedule.
Contents
- 1. Who we are
- 2. Data we collect
- 3. Data minimisation
- 4. AI & training
- 5. How we use your data
- 6. Legal basis
- 7. Sub-processors
- 8. Payments
- 9. Storage & retention
- 10. Sharing
- 11. International transfers
- 12. Your rights
- 13. Automated processing
- 14. Security
- 15. Cookies & analytics
- 16. Marketing email
- 17. California residents (CCPA/CPRA)
- 18. Minors
- 19. Changes
- 20. Contact
1. Who we are
The Olyteck products are operated by Olyteck from France under SIRET 993 174 499 00018. For the purposes of the EU GDPR:
- Olyteck is the data controller for personal data we collect to operate your account (e.g. the admin email used to sign in, billing details).
- For the data each product derives from your Microsoft 365 or your uploaded content, we act as a data processor on behalf of your organisation (which remains the controller). Our processor obligations are in the Data Processing Agreement and its per-product Schedule.
Privacy contact: [email protected].
Data Protection Officer. As a small operator, Olyteck is not required to appoint a DPO under GDPR Art. 37 and has not appointed one; all enquiries are handled by the privacy contact above. We will update this section if an appointment becomes required.
2. Data we collect
Admin / account data
Received from Microsoft Entra ID when an admin signs in:
- Email address and display name
- Opaque user and tenant identifiers (the "oid" and "tid" claims)
- Workspace role
- Timestamps: account creation, last login, session activity
Product-derived data
The categories of data each product processes about your Microsoft 365 or your content differ by product and are listed in its DPA Schedule — for example, configuration/permission metadata (Cyber), uploaded documents and answer history (Ask), or mail signals, scores and verdicts (Guard).
Usage data
- IP address and user-agent of console requests (for abuse detection)
- Audit entries for privileged and state-changing actions
Billing data
- Stripe customer identifier, subscription status, plan code, invoice metadata
- We never store full card numbers or CVC — card data is entered into Stripe's hosted Checkout and stays at Stripe
3. Data minimisation — "counts findings, never files"
Across products we store the minimum needed to deliver the service: derived signals, scores, findings, verdicts, answers and metadata rather than your raw files, message bodies or document contents wherever the product design allows. Exactly what each product stores — and what it never stores — is set out in its DPA Schedule.
Tenant isolation. Every record that touches your data is bound to the tenant that owns it; every query filters on the server-side session's tenant identifier, never on a value taken from the request. Cross-tenant access attempts return a not-found response.
4. AI & training
- We never train our own models on your data. Your content, signals and outputs are not used by Olyteck as training data for a product sold to others.
- Third-party AI varies by product. Some products use third-party AI/LLM sub-processors under contractual "no training on API data" terms (e.g. Ask, Cyber); others use none (e.g. Guard). Each product's DPA Schedule states its AI stance and lists any AI sub-processors with links to their data-use terms.
5. How we use your data
- To authenticate admin sessions via Microsoft Entra ID single sign-on.
- To deliver the product's function (scanning, answering, detection, reporting) as configured.
- To bill you accurately and issue invoices through Stripe.
- To send transactional email — trial reminders, account-state changes, security alerts.
- To detect abuse and secure the platform.
- To comply with our legal and accounting obligations in France and the EU.
What we do not do: we do not sell or share your personal information for cross-context behavioural advertising; we do not use your data to train our own models; we do not store more of your content than the product needs.
6. Legal basis for processing (GDPR)
- Contract (Art. 6(1)(b)) — to deliver the Service your organisation signed up for.
- Legitimate interest (Art. 6(1)(f)) — to secure the environment, detect threats and fraud, and debug. Network and information security is a recognised legitimate interest (Recital 49).
- Legal obligation (Art. 6(1)(c)) — to retain billing records under French tax law.
- Consent (Art. 6(1)(a)) — only where relied on (e.g. non-essential analytics cookies, optional marketing email). Withdrawable at any time.
7. Sub-processors
Each product uses a short list of vendors as data sub-processors under written processing agreements. The authoritative, version-dated list per product is in its DPA Schedule; the Trust Center shows the company-wide view. Common to all products: Scaleway (EU hosting), Microsoft (identity, and where connected, Graph), and Stripe (billing). Whether a product uses third-party AI sub-processors is stated in its Schedule.
8. Payments
Paid subscriptions are processed by Stripe Payments Europe, Ltd. (Ireland). We receive a transaction reference, amount, currency, subscription state and the last four digits of the card. Full card data is entered directly into Stripe's hosted Checkout and never touches our servers. Stripe's privacy policy applies to that portion of the flow.
9. Storage & retention
Application data is hosted in France (Paris, PAR1) (EU-27). Product-specific retention windows are in each product's DPA Schedule. Windows common across products:
- Account data — while your tenant is active, plus 30 days after deletion.
- Audit logs — 24 months.
- Billing records — 10 years (required by French accounting law).
11. International transfers
Applications, databases and workers run in France (Paris, PAR1) (EU-27). Current sub-processors process through their EU entities, so processing stays within the EEA. If a future sub-processor processes data outside the EEA, transfers will rely on the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) and, where available, the EU-US Data Privacy Framework, and the product Schedule will be updated.
12. Your rights
If you are in the EU, the UK, or otherwise subject to GDPR, you have the right to access, correct, delete, export, restrict or object to processing of your personal data, and to withdraw consent where processing is based on it. You may also lodge a complaint with the French data-protection authority (CNIL) at cnil.fr.
To exercise any right, email [email protected] from the address associated with your account. We respond within 30 days. Where a product processes data on behalf of your employer, individual requests are usually routed through your organisation (the controller); we assist your administrator in responding.
13. Automated processing
Some products automatically score or classify items (e.g. Guard scores messages) and can, where an admin has enabled it, apply reversible actions. These are security decision-support outputs about items, not automated decisions producing legal effects on individual data subjects within the meaning of GDPR Art. 22. We do not profile or score individual employees. Output quality varies; the Terms of Service set out the customer's responsibility to review outputs before acting on them.
14. Security
The full technical and organisational measures are in the Security overview and DPA §5. Key points: encrypted transport (TLS 1.2+), encrypted storage, Microsoft Entra SSO with PKCE, strict per-tenant isolation, least-privilege staff access and audit logging.
No online service can promise absolute security. If you suspect a breach affecting your data, email [email protected] immediately. We acknowledge within one business day and, where a breach is confirmed, notify affected administrators within 72 hours of awareness as required by GDPR Art. 33.
16. Marketing email
The emails we send today are transactional: trial reminders, account
confirmation, plan-state changes, security notifications, sent on the basis of contract
performance (Art. 6(1)(b)). If we introduce an optional newsletter, enrolment will be by an
unticked-by-default checkbox with one-click unsubscribe and a List-Unsubscribe
header (RFC 8058); we record consent and remove you immediately on withdrawal.
17. California residents (CCPA / CPRA)
If you are a California resident, the CCPA (as amended by the CPRA) gives you specific rights; this section is your "notice at collection".
- Categories collected. Identifiers (admin work email, Entra OID/TID, and any identifiers in product-derived data), professional information (role), internet/network activity (IP for abuse detection, sign-in timestamps), commercial information (subscription plan), and security signals where the product produces them.
- Sources. Your admin at sign-in; Microsoft Entra on authentication; Microsoft Graph or your uploads for the data the product processes on your behalf.
- Business purposes. Operating, securing and improving the Service; threat detection; billing; transactional email; legal compliance.
- Sale or sharing. We do not "sell" personal information and do not "share" it for cross-context behavioural advertising as defined under the CPRA.
- Sensitive personal information. These are B2B tools; we do not intentionally collect or use sensitive personal information to infer characteristics.
- Your rights. Know, delete, correct, and non-discrimination. Email [email protected]; we respond within 45 days (extendable once by 45 days with notice, as the CPRA permits).
18. Minors
The Olyteck products are B2B tools intended for authorised members of an organisation. They are not directed at children under 16. If you believe a minor has signed up, email us and we will close the account and delete the data.
19. Changes to this policy
When we make a material change we update the "Last updated" date and post an in-app notice where the change affects your rights. Continued use after the change means you accept the updated policy.
20. Contact
Questions about privacy? Email [email protected] — or general support [email protected]. Security incidents: [email protected].
Operator: Olyteck — SIRET 993 174 499 00018.