Privacy

What we collect, and why

Short, because there is not much of it. This covers the website; the second half covers what the product reads once a tenant is connected.

Who is responsible

SeQontrol is operated by JeffOps, Hermesburg 29, 3437 HG Nieuwegein, The Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 99353946. For anything on this page, including a request to see or delete what we hold, write to jeff@jeffops.com and a person will answer.

Where this policy says "we", it means that entity and nobody else. No data described here is sold, brokered, or handed to an advertising network.

This website

The site is static. It sets no cookies, runs no advertising or profiling scripts, and makes no third-party requests — no fonts, no CDN, no embedded video. Nothing about you is collected by visiting it.

If you send the contact form, we receive what you typed: your name, email address, and whatever else you chose to add. We use it to reply to you and to keep track of the conversation. We do not sell it, share it for marketing, or add you to a list you did not ask for.

What the product reads

Once you connect a Microsoft 365 tenant, SeQontrol reads configuration and metadata through app-only Microsoft Graph permissions in order to produce findings. Concretely, that means things like sharing links, permission assignments, group memberships, application consents, Conditional Access policies and DNS records.

It is metadata about access, not the contents of your files. SeQontrol records that a document is shared with an external address; it does not read the document.

Scanning is read-only. Anything that writes back to your tenant — revoking a permission, publishing a DNS record, restoring an approved configuration — requires a separate, explicit consent that is distinct from the read grant, and can be withdrawn without losing the findings and evidence you already hold.

Where it is kept

Everything SeQontrol stores about your tenant — findings, evidence, scan history and the audit trail — lives in Microsoft Azure, West Europe region, which is in the Netherlands. Same jurisdiction as the company that operates it. It is not replicated to a region outside the EU.

Two things that follow, and are worth being explicit about. Microsoft is therefore a processor for the hosting itself. And the data in your own Microsoft 365 tenant never moves — SeQontrol reads it where it already is; what lives in West Europe is the findings and evidence produced from that reading, not a copy of your estate.

How long it is kept

Findings and evidence are retained for the period your licence sets, because the value of compliance evidence is that it covers a period. The audit trail is hash-chained and append-only by design: entries are not edited or deleted, which is the property that makes it worth having.

Contact-form correspondence is kept for as long as the conversation is useful, and deleted on request.

Your rights

You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, or object to it being processed. Email jeff@jeffops.com and you will get a reply from a person.

Where SeQontrol processes data from your tenant, you are the controller and we act as processor on your instructions. A data processing agreement is available on request.

Changes

If this notice changes materially, the change is visible in the site's public commit history — the whole site is a public repository, which is a stronger guarantee than a "last updated" date we control.