Purpose of this page
Enterprise endpoint and Microsoft cloud work can involve access to customer systems and personal data. This page describes the general data-processing and security approach M365 Factory intends to use. Customer-specific obligations are confirmed in the applicable contract or Data Processing Agreement (DPA).
Controller and processor roles
For website enquiries and M365 Factory's own business administration, M365 Factory generally determines why and how the information is used. During customer projects, M365 Factory may instead act as a processor or service provider when handling data strictly on a customer's instructions. The actual role is determined by the activity, not only by the contract title.
Data Processing Agreement
Where required by applicable privacy law or customer policy, a DPA can be agreed before processing customer personal data. A DPA may cover processing instructions, confidentiality, security, approved subprocessors, support for data-subject rights, incident cooperation, deletion/return of data, audits, and international-transfer provisions.
International transfers
For customers whose laws regulate cross-border transfers, the required transfer mechanism will be identified during contracting. This may include recognised contractual safeguards such as applicable standard contractual clauses, transfer addenda, or another legally permitted mechanism.
Security approach
- least-privilege access appropriate to the agreed task;
- customer-approved remote access and administrative methods;
- separation of customer credentials from public website communications;
- use of encrypted transport where supported and appropriate;
- documented changes and handover for in-scope work;
- reasonable access control and credential hygiene;
- avoidance of unnecessary copies of customer personal data;
- prompt escalation of material security issues identified during an engagement.
Credentials and privileged information
Do not send passwords, private keys, recovery codes, API secrets, or privileged credentials through the public contact form. Secure access arrangements should be agreed separately once an engagement is authorised.
Subprocessors and platforms
The exact subprocessors used for customer work depend on the engagement. Website hosting and business communications currently involve GoDaddy and Microsoft 365. Customer projects may also involve platforms selected and controlled by the customer. Where required, subprocessors relevant to a DPA will be identified contractually.
Retention and deletion
Customer data should be retained only for the agreed purpose and period. Project-specific deletion, return, evidence-retention, or archival requirements should be specified in the contract or DPA. Business records that must be retained for legal, tax, security, or dispute reasons may be retained separately where permitted.
Incident cooperation
If M365 Factory becomes aware of a material security incident involving customer data under an active engagement, notification and cooperation will follow the applicable contract, DPA, customer incident process, and mandatory legal requirements.
Requesting a DPA or security information
Customers can request a DPA, security questionnaire response, or project-specific data-handling discussion by emailing hello@m365factory.com.