Privacy Policy
Last updated: 8 July 2026 · ICO Registration: ZC173030
1. Data controller
The data controller is Stephen Bennett (sole trader), operating AZClarity at support@azclarity.com. ICO Registration: ZC173030.
2. What data we collect
Account data: Your email address, display name, and company name (from your Microsoft identity when you sign in). We use this to identify your account and send service emails.
Azure subscription data: Resource types, counts, regions, and SKU metadata from your Azure subscription. We do not collect resource names, tags, or configuration values beyond what is necessary to identify service types.
Access tokens: Azure OAuth access and refresh tokens, encrypted with AES-256-GCM, stored to enable scheduled scans without requiring you to re-authenticate.
MSP client-tenant data (MSP plan only): When an MSP connects a client's Azure tenant, AZClarity reads that client's Azure resource metadata (resource types, counts, regions, SKU and configuration metadata) using AZClarity's own read-only application identity, after the client has granted admin consent and assigned the Reader role. We never read customer content or data held inside those resources — only configuration and inventory metadata needed for the assessment. For this data the MSP is the data controller and AZClarity acts as a data processor on the MSP's instructions; the MSP is responsible for having a lawful basis and appropriate agreement with their client.
Usage data: Scan timestamps, AI call counts, and session activity. Used to enforce rate limits and detect abuse.
Payment data: Billing is handled by Stripe. We store only your Stripe customer ID — no card details are held by AZClarity.
3. Legal basis (UK GDPR)
- Contract performance — processing necessary to deliver the service you subscribed to
- Legitimate interests — security monitoring, abuse prevention, service improvement
- Legal obligation — where required by law
4. How we use your data
- To authenticate you and manage your subscription
- To scan your Azure subscription and generate coverage reports
- To generate AI observations using Anthropic Claude (infrastructure metadata only — no personal data sent)
- To send service emails (scan complete, payment, account notifications)
- To detect and prevent fraud and abuse
5. AI and third-party processing
We use Anthropic's Claude API to generate AI observations. Before sending data to Anthropic, we:
- Strip all personal data (email addresses, names, tokens)
- Sanitise resource names to prevent prompt injection
- Send only aggregate infrastructure metadata (service types, counts, regions)
Anthropic processes this data under their own privacy policy. No data from one customer is used to generate results for another.
We also use: Stripe (payment processing), Brevo (transactional email), Cloudflare (infrastructure, CDN, D1 database). Each operates under their own privacy policy and GDPR compliance programme.
6. Data storage and retention
All data is stored in Cloudflare D1 (Western Europe region — Amsterdam). Azure tokens are encrypted at rest using AES-256-GCM with per-token key derivation.
Retention periods:
- Account data — retained while your account is active, deleted within 30 days of account closure
- Scan results — retained for 12 months, then deleted
- AI usage logs — metadata only (no prompt content), 90 days
- Audit logs — 12 months
- Payment records — 7 years (legal obligation)
7. Your rights (UK GDPR)
You have the right to: access your personal data, correct inaccurate data, request deletion, restrict processing, data portability, and object to processing. To exercise any right, email support@azclarity.com. We will respond within 30 days.
You also have the right to lodge a complaint with the ICO at ico.org.uk.
8. Cookies
AZClarity uses a single session cookie to maintain your login state. We do not use tracking cookies, advertising cookies, or third-party analytics. No cookie consent banner is required as we use only strictly necessary cookies.
9. Security
See our Security page for full details of our technical and organisational security measures.
10. Changes to this policy
We will notify you by email before making material changes to this policy. The date at the top of this page shows when it was last updated.
Contact
Data protection enquiries: support@azclarity.com