Privacy Notice
Your trust is the product. This notice explains what data Copilot Insights processes, why, and the choices you have — starting with the most important point: we never read your Copilot prompts, chats or files.
Last updated: 19 September 2026
Template notice. This document is a starting template tailored to how Copilot Insights works. Placeholders in [square brackets] must be completed, and the final text should be reviewed by a qualified legal professional before you rely on it.
1. Who we are
Copilot Insights is operated by [LogiSam legal entity name] (“we”, “us”, “our”), registered in [jurisdiction] at [registered address]. For privacy questions, contact [privacy@yourdomain] or logisam.com/contact-us.
2. The most important point
Copilot Insights reads activity metadata and inventory only. We never access or store the content of Copilot prompts, chat messages, emails or documents. The connection to your Microsoft 365 tenant is read-only — we cannot change anything in your tenant.
3. Controller and processor roles
For the account data of the people who sign in to Copilot Insights, we act as a data controller. For the tenant metadata we process from your Microsoft 365 environment on your instruction, you are the controller and we act as your data processor. Where you self-host Copilot Insights in your own Azure subscription, that data stays entirely within your tenant and you are the controller and processor.
4. What data we process
a. Account data (controller)
- name, work email and sign-in identifier of users who create an account;
- authentication metadata and audit events (sign-in times, actions taken in the app);
- support communications you send us.
b. Microsoft 365 tenant metadata (processor)
- licence assignment and usage signals (purchased vs assigned vs active seats, activity dates, usage by app);
- user-level directory attributes needed for the report (display name, user principal name, licence status) — which can be anonymised;
- an inventory of Copilot Studio / Power Platform agents (name, owner, status, publication state, connected data indicators).
We do not process prompt content, chat content, email or file content.
c. Billing data
Payments are handled by Stripe. We receive billing status and limited details (plan, last four digits, billing contact); we do not store full card numbers.
d. Technical data
Standard server logs and security telemetry (e.g. IP address, request metadata) used to operate and secure the Service.
5. How we use data
- to provide the Service — run scans and produce your ROI and governance reports;
- to authenticate users and secure the Service;
- to process payments and manage subscriptions;
- to provide support and respond to you;
- to improve reliability and performance;
- to meet legal and regulatory obligations.
We do not sell personal data, and we do not use your tenant metadata to train AI models.
6. Legal bases (UK/EU GDPR)
- Contract — to deliver the Service you signed up for;
- Legitimate interests — to secure, operate and improve the Service;
- Legal obligation — for tax, accounting and compliance;
- Consent — where required (e.g. certain communications), which you can withdraw at any time.
For tenant metadata we process as your processor, the lawful basis is established by you as controller; we process it only on your documented instructions.
7. Sub-processors & sharing
We share data only with providers that help us run the Service:
- Microsoft Azure — hosting and database (region: [e.g. UK South]);
- Microsoft Graph — the read-only source of your tenant metadata;
- Stripe — payment processing;
- [email/SMTP provider] — transactional and digest emails.
We do not sell or rent personal data to third parties.
8. International transfers
Where data is transferred outside your region, we rely on appropriate safeguards (such as Standard Contractual Clauses / UK IDTA). If you self-host, you control the region entirely.
9. Data retention
We keep account data for as long as your account is active and as needed for legal purposes. Scan/tenant metadata is retained to show trends over time and is deleted or anonymised when you delete your organisation or close your account. Disconnecting revokes our access to your tenant immediately.
10. Security
We apply appropriate technical and organisational measures, including encryption in transit, least-privilege read-only access to Microsoft Graph, encrypted storage of secrets, and access controls. No system is perfectly secure, but read-only, metadata-only design keeps the impact of any incident low by construction.
11. Anonymisation
User names in reports can be anonymised so that analysis and sharing do not expose individual identities, while still surfacing the licence and adoption insights you need.
12. Your rights
Subject to applicable law, you have rights to access, correct, delete, restrict or object to processing, and to data portability. To exercise them, contact [privacy@yourdomain]. You also have the right to complain to your data protection authority (in the UK, the ICO). Where we act as processor for your tenant data, please direct data-subject requests to your own organisation as controller; we will assist you.
13. Cookies
We use only the cookies necessary to sign you in and keep the Service secure, plus privacy-respecting analytics. We do not use advertising cookies.
14. Children
The Service is for business use and is not directed at children under 16.
15. Changes to this notice
We may update this notice from time to time; we will change the “last updated” date above and, for material changes, take reasonable steps to notify you.
16. Contact
Questions or requests? Contact [privacy@yourdomain] or logisam.com/contact-us.
