DeliverablesHow it worksSecurityPricingLog in
Draft v1.1 · Last updated 22 June 2026

Data Processing Agreement

The agreement between SimpleEntra as processor and you as controller — under GDPR Art. 28. Status: draft. Will be reviewed by legal counsel before signature.

The document covers purpose, sub-processors, security measures, deletion and audit rights for your data in SimpleEntra. It is an integral part of the Terms of Service and must be accepted at order.

Read the document

The authoritative version is maintained in the SimpleEntra repo. Choose your preferred format:

What the agreement covers

  • Purpose and scope — read-only scan of your Microsoft 365 tenant via 11 application permissions, all read-only. No changes to your configuration.
  • 3-tier data strategy — Snapshot, Pseudonymised or Full. You choose the tier and may lower it at any time.
  • Sub-processors — Supabase (EU/Frankfurt), Vercel (Frankfurt), Resend (US, SCCs), Anthropic (US, zero retention, pseudonymised input only), Cloudflare, Microsoft Graph.
  • Security — AES-256 at rest, TLS 1.2+ in transit, TOTP MFA, Row-Level Security, audit log, HTTP security headers, SSRF blocking, rate limits.
  • Breach — notification to you within 72 hours per GDPR Art. 33.
  • Deletion — all personal data is deleted no later than 30 days after termination or upon your written request.
  • Audit — you may request a security audit with 30 days' notice.

Status and disclaimer

This is a draft. The final legal document must be reviewed by legal counsel before signature. Fields marked […] (VAT/CVR, addresses, contact persons) are completed at contract execution.

Questions about the content go to hello@simpleentra.com.

Related documents