dForts dForts: Copilot Readiness Monitor

Privacy Policy

dForts Copilot Readiness Monitor · Last updated: September 2026

1. Who We Are

This Privacy Policy applies to the dForts Copilot Readiness Monitor (the “Product”), published by dForts (“we”, “us”, “our”) on Microsoft AppSource and distributed as a SharePoint Framework (SPFx) solution.

Contact: support@dforts.com

2. Scope

This policy describes how we collect, use, and protect information when your organization installs and uses the dForts Copilot Readiness Monitor. It applies to all end users within the subscribing Microsoft 365 tenant.

This Product operates primarily within your own Microsoft 365 tenant. The only outbound data transfers to dForts infrastructure are the license validation request described in Section 4 and the subscription management data described in Section 5.

3. Data Processed Within Your Tenant

The following data is accessed at runtime to perform the oversharing analysis. It is never transmitted to dForts servers and is processed exclusively within your Microsoft 365 environment:

Data typePurposeStorage
SharePoint site metadata and item IDsEnumerate sites for the tenant-wide report (Premium)In-memory only
File and folder metadataIdentify items with risky permission configurationsIn-memory only
SharePoint permission assignmentsDetect oversharing (Anonymous, Everyone, External, Unique)In-memory only
Scan results summary and logsCache results and display history to site ownersStored in hidden SharePoint lists and browser storage within your own tenant

4. Data Transmitted to dForts for License Validation

The only information sent by the Product to dForts infrastructure is your Microsoft 365 Tenant ID (GUID). It is transmitted via HTTPS to copilot-readiness.dforts.solutions when a web part loads, to verify the license status. No personal data, file contents, or SharePoint metadata are transmitted.

5. Subscription Management Data

When you purchase a subscription through the Microsoft Commercial Marketplace, Microsoft provides us with the subscription details required to fulfil the purchase: subscription ID, offer and plan, purchaser tenant ID, and the purchaser's and beneficiary's sign-in email addresses. When you sign in to this website, we read your tenant ID and sign-in email from your Microsoft Entra ID token to show the subscriptions of your tenant. This data is stored in Microsoft Azure (EU region) and used solely for license fulfilment and support.

6. Microsoft Graph Permissions

The Product requests delegated permissions (Sites.Read.All, Files.Read.All, GroupMember.Read.All). All permissions are exercised under the delegated identity of the signed-in user and no data leaves the tenant.

7. Data Retention

SharePoint hidden lists (scan cache, acknowledgements, remediation log) are retained until the site owner or administrator deletes them. The dForts license database stores the data described in Section 5 for the duration of the subscription and for up to one (1) year after the subscription terminates.

8. Legal Basis for Processing (GDPR)

Processing is based on contract performance (Article 6(1)(b) GDPR) and legitimate interests (Article 6(1)(f) GDPR) for license validation and fraud prevention.

9. Security

All communication between the Product, this website and dForts infrastructure uses HTTPS (TLS 1.2 or higher). SharePoint data never leaves your tenant.

10. Your Rights and Contact

You may request access to, correction or deletion of the subscription data we hold about your organization by writing to support@dforts.com.