Privacy Policy
dForts Copilot Readiness Monitor · Last updated: September 2026
1. Who We Are
This Privacy Policy applies to the dForts Copilot Readiness Monitor (the “Product”), published by dForts (“we”, “us”, “our”) on Microsoft AppSource and distributed as a SharePoint Framework (SPFx) solution.
Contact: support@dforts.com
2. Scope
This policy describes how we collect, use, and protect information when your organization installs and uses the dForts Copilot Readiness Monitor. It applies to all end users within the subscribing Microsoft 365 tenant.
This Product operates primarily within your own Microsoft 365 tenant. The only outbound data transfers to dForts infrastructure are the license validation request described in Section 4 and the subscription management data described in Section 5.
3. Data Processed Within Your Tenant
The following data is accessed at runtime to perform the oversharing analysis. It is never transmitted to dForts servers and is processed exclusively within your Microsoft 365 environment:
| Data type | Purpose | Storage |
|---|---|---|
| SharePoint site metadata and item IDs | Enumerate sites for the tenant-wide report (Premium) | In-memory only |
| File and folder metadata | Identify items with risky permission configurations | In-memory only |
| SharePoint permission assignments | Detect oversharing (Anonymous, Everyone, External, Unique) | In-memory only |
| Scan results summary and logs | Cache results and display history to site owners | Stored in hidden SharePoint lists and browser storage within your own tenant |
4. Data Transmitted to dForts for License Validation
The only information sent by the Product to dForts infrastructure is your Microsoft 365 Tenant ID (GUID). It is transmitted via HTTPS to copilot-readiness.dforts.solutions when a web part loads, to verify the license status. No personal data, file contents, or SharePoint metadata are transmitted.
5. Subscription Management Data
When you purchase a subscription through the Microsoft Commercial Marketplace, Microsoft provides us with the subscription details required to fulfil the purchase: subscription ID, offer and plan, purchaser tenant ID, and the purchaser's and beneficiary's sign-in email addresses. When you sign in to this website, we read your tenant ID and sign-in email from your Microsoft Entra ID token to show the subscriptions of your tenant. This data is stored in Microsoft Azure (EU region) and used solely for license fulfilment and support.
6. Microsoft Graph Permissions
The Product requests delegated permissions (Sites.Read.All, Files.Read.All, GroupMember.Read.All). All permissions are exercised under the delegated identity of the signed-in user and no data leaves the tenant.
7. Data Retention
SharePoint hidden lists (scan cache, acknowledgements, remediation log) are retained until the site owner or administrator deletes them. The dForts license database stores the data described in Section 5 for the duration of the subscription and for up to one (1) year after the subscription terminates.
8. Legal Basis for Processing (GDPR)
Processing is based on contract performance (Article 6(1)(b) GDPR) and legitimate interests (Article 6(1)(f) GDPR) for license validation and fraud prevention.
9. Security
All communication between the Product, this website and dForts infrastructure uses HTTPS (TLS 1.2 or higher). SharePoint data never leaves your tenant.
10. Your Rights and Contact
You may request access to, correction or deletion of the subscription data we hold about your organization by writing to support@dforts.com.