M365Factory
Home Services Migration About How We Work Contact
Discuss Your Project
Legal & privacy

Data Processing & Security

General privacy, processor, DPA, international-transfer, and security principles for customer engagements.

Last updated: 4 September 2026 Contact: hello@m365factory.com
Legal & privacy Business & Legal Information Privacy Policy Website & B2B Terms Cookie Notice Data Processing & Security Contact

Purpose of this page

Enterprise endpoint and Microsoft cloud work can involve access to customer systems and personal data. This page describes the general data-processing and security approach M365 Factory intends to use. Customer-specific obligations are confirmed in the applicable contract or Data Processing Agreement (DPA).

Controller and processor roles

For website enquiries and M365 Factory's own business administration, M365 Factory generally determines why and how the information is used. During customer projects, M365 Factory may instead act as a processor or service provider when handling data strictly on a customer's instructions. The actual role is determined by the activity, not only by the contract title.

Data Processing Agreement

Where required by applicable privacy law or customer policy, a DPA can be agreed before processing customer personal data. A DPA may cover processing instructions, confidentiality, security, approved subprocessors, support for data-subject rights, incident cooperation, deletion/return of data, audits, and international-transfer provisions.

International transfers

For customers whose laws regulate cross-border transfers, the required transfer mechanism will be identified during contracting. This may include recognised contractual safeguards such as applicable standard contractual clauses, transfer addenda, or another legally permitted mechanism.

Security approach

  • least-privilege access appropriate to the agreed task;
  • customer-approved remote access and administrative methods;
  • separation of customer credentials from public website communications;
  • use of encrypted transport where supported and appropriate;
  • documented changes and handover for in-scope work;
  • reasonable access control and credential hygiene;
  • avoidance of unnecessary copies of customer personal data;
  • prompt escalation of material security issues identified during an engagement.

Credentials and privileged information

Do not send passwords, private keys, recovery codes, API secrets, or privileged credentials through the public contact form. Secure access arrangements should be agreed separately once an engagement is authorised.

Subprocessors and platforms

The exact subprocessors used for customer work depend on the engagement. Website hosting and business communications currently involve GoDaddy and Microsoft 365. Customer projects may also involve platforms selected and controlled by the customer. Where required, subprocessors relevant to a DPA will be identified contractually.

Retention and deletion

Customer data should be retained only for the agreed purpose and period. Project-specific deletion, return, evidence-retention, or archival requirements should be specified in the contract or DPA. Business records that must be retained for legal, tax, security, or dispute reasons may be retained separately where permitted.

Incident cooperation

If M365 Factory becomes aware of a material security incident involving customer data under an active engagement, notification and cooperation will follow the applicable contract, DPA, customer incident process, and mandatory legal requirements.

Requesting a DPA or security information

Customers can request a DPA, security questionnaire response, or project-specific data-handling discussion by emailing hello@m365factory.com.

M365Factory

Independent IT services for endpoint management, migration, application packaging, automation, and Microsoft cloud environments.

Legal Information Privacy Terms Cookies Data Processing

Navigation

Home Services Migration About How We Work Contact

Get in touch

✉ hello@m365factory.com

Worldwide remote services

© 2026 M365 Factory. All rights reserved.
M365 Factory is an independent service provider and is not affiliated with or endorsed by Microsoft Corporation. Product names and trademarks belong to their respective owners.