Privacy & cookies

Your data, in plain terms

This notice covers what Admin Companion collects on this marketing site, what we process in the Admin Companion service itself, why, and the choices you have. The site does little with your data, and asks before it does anything optional.

Last updated: 14 September 2026.

Cookies & analytics

We'd like to understand how the site is used so we can improve it, using Microsoft Clarity. Clarity sets cookies and records anonymized usage - which pages you visit, where you click and scroll - to produce aggregate heatmaps and session playbacks. It is an analytics tool, not advertising, and we do not sell your data.

Because these are non-essential cookies, Clarity only loads if you accept. Our legal basis is your consent, under Article 6(1)(a) of the GDPR. When you first visit, a banner offers Accept and Decline side by side, and declining takes one click. Decline (or simply ignore it) and no analytics cookies are set. Your choice is remembered in your browser.

You can change your mind at any time:

Declining clears the Clarity cookies this site set, and stops Clarity loading on future visits. Cookies that Microsoft sets on its own domains, such as c.clarity.ms and c.bing.com, are governed by Microsoft's own privacy notice and are not ours to delete. The essential cookies a site needs to function are not affected, and we don't use tracking or advertising cookies of our own.

When you contact us

Two forms on this site send us a message: the contact form, and the "email me this estimate" form on the ROI calculator. What you enter is emailed to us through Azure Communication Services so we can read and reply. That is your name, your email and anything you write, and on the calculator it also includes the figures you typed into it and the result it produced, which are sent as the body of the message. We use all of it only to answer your enquiry, and we don't add you to any marketing list without asking. Our legal basis is our legitimate interest in replying to you, and where you are asking about a subscription, taking steps at your request before entering into a contract (Article 6(1)(f) and 6(1)(b) of the GDPR).

So that neither form can be used to send us floods of mail, we also store a one-way hash of the sending IP address rather than the address itself, and use it only to count submissions against a rate limit. It is not used to identify anyone.

Data we process in the Service

Everything above is about this website. The Admin Companion product is separate. When you connect a Microsoft 365 tenant to it, the Service reads that tenant's configuration through the app-only connection you grant it: the settings, policies and role assignments the checks you run depend on, and the user, group and device records those checks look at. Some of that is personal data about your own people. For it, your organization is the controller and we act on your instructions.

From that configuration the Service produces findings and the evidence behind them, the reports you schedule or export, and an audit record of every change made through it: who did it, what changed, and when. It also holds the account details of the people you invite into your workspace. Nothing in your tenant is read or changed beyond what you have configured, approved or scheduled, and we do not sell any of it.

Audit retention is configurable, with a platform default and per-tenant and per-user overrides, enforced by a purge job. The shipped defaults are roughly seven years for tenant and platform audit logs and two years for user account activity, with a permitted range of 30 days to ten years.

If you are assessing Admin Companion as a processor and need data processing terms, a subprocessor list or a security overview, ask us at hi@admincompanion.com.

Where your data is processed

The site, the Service and their email backend run in Microsoft Azure data centers in Europe. Microsoft Clarity is operated by Microsoft as a processor, and that involves processing outside the EEA, in the United States. For those transfers Microsoft relies on the EU-US Data Privacy Framework and on the Standard Contractual Clauses in its data protection addendum. See Microsoft's own privacy documentation for how it handles the analytics data.

How long we keep it

Emails from either form are kept only as long as we need them to deal with your enquiry and any follow-up, then deleted. The hashed rate-limit record is retained until a later submission from the same address supersedes it. Clarity retains its analytics for a rolling period set by Microsoft's defaults. Retention inside the Service is covered under "Data we process in the Service" above.

Your rights

Under the GDPR you can ask us to access, correct, or delete the personal data we hold about you, ask us to restrict how we process it, ask for a copy of it in a portable form, object to processing, or withdraw a consent you've given. Where analytics are in use, the button above withdraws that consent; for anything else, email us and we'll help.

You can also complain to Datatilsynet, the Danish Data Protection Agency (datatilsynet.dk).

Where the data sits inside a Microsoft 365 tenant connected to the Service, your own organization is the controller for it, so a request about it should go to them.

Contact

Questions about this notice or your data? Email hi@admincompanion.com.

Changes

If we change what we collect or how, we'll update this page and its "last updated" date.