Privacy Policy

Last updated: 8 July 2026 · ICO Registration: ZC173030

Summary: We collect only what we need to operate the service. We store your Azure scan data in the EU. We do not sell your data. We use Anthropic's API to generate AI observations — only your infrastructure metadata is sent, never personal data.

1. Data controller

The data controller is Stephen Bennett (sole trader), operating AZClarity at support@azclarity.com. ICO Registration: ZC173030.

2. What data we collect

Account data: Your email address, display name, and company name (from your Microsoft identity when you sign in). We use this to identify your account and send service emails.

Azure subscription data: Resource types, counts, regions, and SKU metadata from your Azure subscription. We do not collect resource names, tags, or configuration values beyond what is necessary to identify service types.

Access tokens: Azure OAuth access and refresh tokens, encrypted with AES-256-GCM, stored to enable scheduled scans without requiring you to re-authenticate.

MSP client-tenant data (MSP plan only): When an MSP connects a client's Azure tenant, AZClarity reads that client's Azure resource metadata (resource types, counts, regions, SKU and configuration metadata) using AZClarity's own read-only application identity, after the client has granted admin consent and assigned the Reader role. We never read customer content or data held inside those resources — only configuration and inventory metadata needed for the assessment. For this data the MSP is the data controller and AZClarity acts as a data processor on the MSP's instructions; the MSP is responsible for having a lawful basis and appropriate agreement with their client.

Usage data: Scan timestamps, AI call counts, and session activity. Used to enforce rate limits and detect abuse.

Payment data: Billing is handled by Stripe. We store only your Stripe customer ID — no card details are held by AZClarity.

3. Legal basis (UK GDPR)

4. How we use your data

5. AI and third-party processing

We use Anthropic's Claude API to generate AI observations. Before sending data to Anthropic, we:

Anthropic processes this data under their own privacy policy. No data from one customer is used to generate results for another.

We also use: Stripe (payment processing), Brevo (transactional email), Cloudflare (infrastructure, CDN, D1 database). Each operates under their own privacy policy and GDPR compliance programme.

6. Data storage and retention

All data is stored in Cloudflare D1 (Western Europe region — Amsterdam). Azure tokens are encrypted at rest using AES-256-GCM with per-token key derivation.

Retention periods:

7. Your rights (UK GDPR)

You have the right to: access your personal data, correct inaccurate data, request deletion, restrict processing, data portability, and object to processing. To exercise any right, email support@azclarity.com. We will respond within 30 days.

You also have the right to lodge a complaint with the ICO at ico.org.uk.

8. Cookies

AZClarity uses a single session cookie to maintain your login state. We do not use tracking cookies, advertising cookies, or third-party analytics. No cookie consent banner is required as we use only strictly necessary cookies.

9. Security

See our Security page for full details of our technical and organisational security measures.

10. Changes to this policy

We will notify you by email before making material changes to this policy. The date at the top of this page shows when it was last updated.

Contact

Data protection enquiries: support@azclarity.com