Legal
Published in full rather than supplied on request. It is the document that says what is read from your tenant, what is never read, who else is involved and when your data is deleted — which is worth reading before you buy, not after.
DATA PROCESSING AGREEMENT
Microsoft 365 Health Assessment (Vitals)
Version 2.0 · Effective 20 August 2026
This DPA applies to direct customer Assessments where the Client is Controller and Innova is Processor. IT-provider/sub-processor engagements require the applicable IT-provider terms.
Parties
(1) Controller: the organisation identified as the Client in the order and Terms of Supply (“Client”).
(2) Processor: Innova Technologies Group Ltd, company number 17205930, registered office 7 Stromberg Street, Anlaby, Hull, HU10 7ER, trading as Innova Group (“Innova”).
This DPA forms part of the Terms of Supply for the Assessment (together, the “Agreement”).
1. Definitions
Assessment. the Microsoft 365 Health Assessment supplied using Vitals, including Scan and Worklist.
Data Protection Legislation. the UK GDPR, Data Protection Act 2018 and other UK legislation applicable to the processing under this DPA, as amended or replaced.
Report. the assessment output produced for the Client.
Tenant. the Client’s Microsoft 365 tenant identified in the order.
UK GDPR. Regulation (EU) 2016/679 as it forms part of UK domestic law.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Sub-processor have the meanings given in the UK GDPR.
2. Roles, instructions and scope
2.1 The Client is Controller and Innova is Processor for Personal Data processed on the Client’s behalf in performing the Assessment.
2.2 The Client instructs Innova to process Personal Data to perform the Assessment, generate and make available the Report, provide related support, operate the retention/deletion controls in this DPA and comply with further documented instructions consistent with the Agreement.
2.3 The Client is responsible for the lawfulness of its instructions, its lawful basis for the processing and any transparency information it must provide to Data Subjects.
2.4 Innova may separately process business-contact, contract, billing, payment, fraud-prevention, tax and accounting information as an independent Controller where necessary for those purposes.
2.5 Innova shall inform the Client without undue delay if, in its opinion, an instruction infringes Data Protection Legislation, unless prohibited by law.
3. Innova’s Article 28 obligations
3.1 Innova shall process Personal Data only on documented instructions from the Client, including for international transfers, unless UK law requires otherwise. Where legally permitted, Innova shall inform the Client before processing required by law.
3.2 Innova shall ensure persons authorised to process Personal Data are subject to confidentiality obligations. Production administrative access is currently restricted to Innova’s Managing Director.
3.3 Innova shall implement and maintain the technical and organisational measures in Schedule 2, having regard to the risks presented by the processing.
3.4 Taking account of the nature of processing, Innova shall assist the Client, insofar as reasonably possible, with Data Subject requests under Chapter III UK GDPR. If Innova receives such a request directly concerning Client Personal Data, it shall notify the Client without undue delay and shall not respond except on the Client’s instruction or where required by law.
3.5 Taking account of the nature of processing and information available to it, Innova shall reasonably assist the Client with obligations under Articles 32–36 UK GDPR, including security, breach notification, DPIAs and prior consultation.
3.6 Innova shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data and shall provide information reasonably available to it to assist the Client with its obligations.
3.7 Innova shall make available information reasonably necessary to demonstrate compliance with Article 28 and shall allow for and contribute to reasonable audits and inspections by the Client or its mandated independent auditor.
3.8 Unless an audit follows a Personal Data Breach, regulator request or reasonable evidence of material non-compliance, the Client shall give reasonable prior notice, conduct it during normal business hours, minimise disruption and ensure its auditor is bound by confidentiality.
4. Tenant access
4.1 Access is established only after a Tenant administrator grants Microsoft Entra admin consent to the Vitals application.
4.2 The production Microsoft Graph application permissions are listed in Schedule 1. They are read-only and do not permit Innova to create, alter or delete Tenant content, settings or objects.
4.3 The Client may revoke Vitals access through Microsoft Entra. Revocation prevents further use of that authorisation.
4.4 Innova shall not use the Client’s authorisation after completion of the Assessment except on a further documented instruction.
4.5 Customer Assessments are processed solely through the production Vitals service hosted in Microsoft Azure UK West. A command-line build exists for internal development and is not used to process customer data.
5. Data minimisation and restrictions
5.1 Vitals does not open, read, copy or store the contents or bodies of documents, email messages or Teams chats as part of the Assessment. MailboxSettings.Read is used only to read mailbox settings, including forwarding and inbox-rule metadata, and not the contents or bodies of email messages.
5.2 Vitals does not collect passwords, authentication secrets or MFA secrets.
5.3 The raw Microsoft Graph assessment snapshot is processed transiently in memory and is not persisted to disk or database.
5.4 Innova shall not use Client Personal Data to train, fine-tune or evaluate a machine-learning model.
5.5 Innova shall not process Client Personal Data for an unrelated purpose or disclose it except as permitted by the Agreement, on documented instruction, or as required by law.
6. Sub-processors
6.1 The Client gives general written authorisation for Innova to use the Sub-processors listed in Schedule 3 for the stated purposes.
6.2 Innova shall impose on each Sub-processor that processes Client Personal Data written data-protection obligations providing an equivalent level of protection to the obligations applicable under Article 28 UK GDPR.
6.3 Innova remains responsible for its Sub-processors’ performance to the extent required by Data Protection Legislation.
6.4 Innova shall give reasonable advance notice of an intended addition or replacement of a Sub-processor processing Client Personal Data. The Client may object on reasonable data-protection grounds. The parties shall work in good faith to resolve the objection; if they cannot, either may terminate the affected service before the change takes effect.
6.5 Microsoft’s operation of the Client’s own Microsoft 365 environment is not an appointment by Innova. Microsoft Azure is separately an Innova Sub-processor where it hosts Vitals and stores the Report.
7. Recommendation service and transfers
7.1 Before assessment information is submitted to the third-party recommendation service, Vitals applies an automated minimisation/anonymisation step. The payload is limited to overall score and band, domain-category scores, and finding category, severity, title, detail and affected-item count; the examples field is emptied before transmission.
7.2 The payload excludes Client/Tenant name, Tenant domain, company name, user names, UPNs, email addresses, file/folder names or paths, sharing URLs, Report URLs and other direct identifiers. Innova shall maintain controls intended to prevent fields capable of containing Client or Data Subject identifiers from being included.
7.3 On the basis of the processing described in 7.1–7.2, Innova does not appoint the recommendation provider to process Personal Data on the Client’s behalf. If that factual position changes, Innova shall treat it as a material processing change and meet applicable Article 28 and Chapter V requirements before transmitting Personal Data.
7.4 Where a Sub-processor processes Client Personal Data outside the UK, Innova shall ensure a lawful Chapter V mechanism applies, including adequacy regulations or appropriate safeguards. The current Resend DPA provides for ex-UK transfers using the UK SCCs (EU SCCs as amended by the UK Addendum).
8. Reports, release, retention and deletion
8.1 The raw Graph snapshot is not persisted. The rendered Report and limited assessment results described in Schedule 1 may be stored in the production database.
8.2 Scan removes identifying item examples before rendering. Worklist intentionally retains specific remediation evidence which may include file/folder paths, sharing links and account identifiers.
8.3 Scan Reports are made available through a token-protected report URL sent to the purchasing/delivery email address. The token expires no later than 30 days after delivery.
8.4 Worklist Reports are generated but are not delivered by email on completion. Innova shall withhold the Worklist until the scheduled review has taken place and an authorised Innova administrator expressly releases it to the authorised recipient. Before authorised release, the Worklist shall be inaccessible through its report-access token even where that token is known or possessed. The Worklist retention period begins only when authorised release occurs.
8.5 Report-access tokens are cryptographically random, expire no later than 30 days after delivery (Scan) or authorised release (Worklist), and are invalidated on earlier deletion. Invalid, expired, already-used and otherwise unauthorised requests do not disclose whether a Report exists.
8.6 No later than 30 days after delivery/release, an automated retention process removes persisted Report HTML and assessment-related buyer/recipient name and email, approver email, agreement signatory information and associated approval/signature IP address, and invalidates the report-access token. The process runs at least every six hours and records when removal completed.
8.7 On written request, Innova shall perform the same personal-data removal early and in any event within five working days, unless UK law requires retention.
8.8 After that removal, Innova may retain scores, domain-category scores, finding categories/severities/titles and aggregate counts only to the extent they are not Personal Data, for repeat-assessment comparison, benchmarking or service improvement.
8.9 Commercial, payment, contract, tax and accounting records retained by Innova in its separate capacity as Controller are outside clauses 8.6–8.7 and are retained only as necessary for those purposes.
8.10 At the end of the processing services, and subject to 8.9, Innova shall at the Client’s choice delete or return Client Personal Data and delete copies unless UK law requires storage. Where the normal deletion cycle will complete deletion sooner, it may be used.
9. Anonymous information
9.1 Innova may retain and use information derived from the Assessment only where it has been rendered anonymous so that it is no longer Personal Data.
9.2 Anonymous information may be used to maintain and improve Vitals, compare repeat Assessments and produce aggregate benchmarks.
9.3 Innova shall not publish a benchmark/statistic in a form that identifies the Client without prior written consent.
10. Processing changes
10.1 Innova shall keep Schedule 1 materially accurate.
10.2 Innova shall not introduce a Microsoft Graph permission or feature that materially expands the categories of Personal Data processed without first updating its processing documentation and, where required, notifying the Client or obtaining further instruction/authorisation.
10.3 Mailbox-rule analysis is part of the standard Assessment and MailboxSettings.Read is part of the production permission set. It reads mailbox settings, including inbox-rule names, rule conditions and forwarding addresses, but does not read the contents or bodies of email messages.
11. Term and liability
11.1 This DPA applies for as long as Innova processes Client Personal Data in connection with the Assessment.
11.2 The exclusions and limitations of liability in clause 12 of the Terms of Supply apply to this DPA as if set out here. Nothing limits a liability to the extent it cannot lawfully be excluded or limited, and nothing changes responsibilities imposed directly by Data Protection Legislation.
11.3 Confidentiality, deletion, anonymous-information, liability and governing-law provisions survive to the extent necessary to give them effect.
12. General
12.1 This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, subject to mandatory rights or jurisdiction under Data Protection Legislation.
12.2 If this DPA conflicts with the Terms of Supply on a data-protection matter, this DPA prevails.
12.3 Nothing in this DPA relieves either party of responsibilities imposed directly on it by Data Protection Legislation.
Schedule 1 — Details of Processing
| Item | Description |
|---|---|
| Subject matter | Read-only assessment of the configuration, security posture and metadata of the Client’s Microsoft 365 Tenant using Vitals. |
| Duration | From grant of admin consent until completion and deletion/return under clause 8. Tenant authorisation is not used after completion without a further documented instruction. |
| Nature | Automated retrieval of specified Microsoft 365 metadata via Microsoft Graph; transient in-memory analysis; scoring; findings; Report rendering; controlled delivery/release; retention and deletion. |
| Purpose | Identify and prioritise risks concerning sharing, sensitivity labelling, content currency, duplication, findability, ownership, guests, identity/security configuration, device compliance, Microsoft 365 activity and related configuration checks. |
| Tenant | As identified in the order. |
| Authorised recipient | As identified in the order. |
| Tier | Scan or Worklist, as identified in the order. |
Categories of Data Subject
- Employees, officers, workers and contractors holding Tenant accounts.
- External guests holding accounts in, or access to, Tenant content.
- Individuals whose names/identifiers appear incidentally in file, folder, site, Team, path, sharing or account metadata.
- Users associated with managed devices or Microsoft 365 activity/security-registration records.
Types of Personal Data
- Identity/directory: display name, UPN, enabled state, user type/guest flag, account creation date and UPNs of Global Administrators.
- File/collaboration metadata: file/folder names and paths, size, last-modified date, quickXorHash, sharing scope/links, sensitivity label, site/Team/group names and owners, page titles/URLs/modified dates/draft state.
- Managed devices: device name, operating system, associated UPN, compliance state and last synchronisation.
- Microsoft 365 activity: UPN, deletion status and last-activity dates for Exchange, SharePoint, OneDrive and Teams for the relevant Microsoft reporting period. Where Microsoft report obfuscation is enabled, Vitals may receive pseudonymised identifiers instead.
- Mailbox-rule metadata: inbox-rule names, rule conditions and any forwarding address. Vitals does not read message content.
- Authentication-security registration: UPN, MFA-capable status, administrator status and registered authentication-method categories. No passwords, authentication secrets or MFA secrets.
- Application/consent metadata: service-principal/application names and OAuth permission scopes; this is generally organisational/configuration information but may contain Personal Data where an identifier relates to an individual.
- Incidental Personal Data in names/paths/URLs retrieved as metadata.
Ordinarily non-personal configuration data also processed
- Conditional Access policy names/states; authorisation-policy settings; security-defaults state.
- Secure Score/control status.
- SharePoint sharing/default-link settings.
- Sensitivity-label taxonomy.
- Public DNS records for customer domains.
Production Microsoft Graph application permissions
- Sites.Read.All
- Files.Read.All
- Directory.Read.All
- SensitivityLabel.Read
- DeviceManagementManagedDevices.Read.All
- Policy.Read.All
- Reports.Read.All
- SecurityEvents.Read.All
- SharePointTenantSettings.Read.All
- MailboxSettings.Read
- AuditLog.Read.All
Tier differences
| Stage | Scan | Worklist |
|---|---|---|
| Tenant data accessed | Same production engine/permission set | Same production engine/permission set |
| Raw Graph snapshot | Memory only; not persisted | Memory only; not persisted |
| Identifying examples in Report | Removed before rendering | Retained where required for remediation |
| Named MFA evidence in Report | Not rendered; aggregate evidence | Not rendered; aggregate evidence |
| Report detail | Scores/findings/counts plus relevant organisational/configuration information | Includes exact remediation evidence such as paths, sharing links and account identifiers |
| Recommendation payload | Same minimised/anonymised payload under clause 7 | Same minimised/anonymised payload under clause 7 |
| Release | Automatic protected-link delivery to authorised address | Generated and withheld; inaccessible by token until scheduled review and explicit authorised release |
| Deletion | No later than 30 days after delivery | No later than 30 days after release |
Schedule 2 — Technical and Organisational Measures
1. Production hosting. Customer Assessments run solely in Microsoft Azure App Service, UK West. The production SQLite database is on App Service persistent storage. The CLI build is internal-development only and is not used for customer processing.
2. Read-only access. Only the read-only Graph application permissions in Schedule 1 are used. Vitals has no write/create/delete Tenant permission.
3. Consent/revocation. Tenant access requires Microsoft Entra administrator consent and can be revoked by the Client through Microsoft Entra.
4. Minimisation. Raw Graph data is memory-only. Scan identifying examples are removed before rendering. Named MFA evidence is rendered as aggregate counts.
5. Encryption in transit. Encrypted transport (TLS) is used for service communications.
6. Encryption at rest. Production persistent storage is protected by Azure Storage encryption at rest using Microsoft-managed encryption; the Vitals workload is configured in UK West.
7. Access control. Production administrative access is restricted to Innova’s Managing Director. Innova has no employees with production access at the effective date.
8. MFA. MFA is enabled and enforced on Innova administrative and business accounts used to administer Vitals.
9. Report access. Reports use cryptographically random tokenised URLs with a maximum 30-day lifetime measured from Scan delivery or Worklist authorised release. Tokens are invalidated on early deletion; invalid, expired and unauthorised requests do not reveal whether a Report exists.
10. Worklist release. The fulfilment process does not email or make accessible a completed Worklist. The scheduled review must take place and an authorised Innova administrator must explicitly release it. Before release, possession of the token does not provide access. The 30-day retention period starts on release.
11. Retention. An automated process runs at least every six hours and removes the persisted Report and specified assessment Personal Data no later than 30 days after delivery/release; completion is recorded; early removal is available.
12. Incident handling. Innova maintains an incident-handling process proportionate to the service, including assessment, containment, remediation and Client notification where a breach affects Client Personal Data.
13. Change control. Material processing changes are reviewed and the processing description is updated before features that materially expand Personal Data processing are enabled.
Schedule 3 — Authorised Sub-processors
| Sub-processor | Purpose | Personal Data | Location | Transfer position |
|---|---|---|---|---|
| Microsoft (Azure) | Hosting, compute and persistent storage for Vitals | Report content, assessment results and associated service data stored by Vitals | Vitals production workload configured in Azure UK West | Innova maintains applicable Microsoft data-processing terms. Any provider processing/access outside the configured region remains subject to Microsoft’s applicable contractual and transfer safeguards. |
| Plus Five Five, Inc. (Resend) | Transactional email delivery: approval/consent messages, Scan report links, Worklist release links, reminders and service notices | Recipient/buyer/approver names and email addresses, message content and URLs included in messages | United States / as set out in Resend’s current DPA and sub-processor disclosures | Resend’s current DPA provides for ex-UK transfers using the UK SCCs (EU SCCs amended by the UK Addendum). |
Recommendation provider. The recommendation provider is not listed as a Sub-processor because the production integration in clause 7 is designed to transmit only the minimised/anonymised recommendation payload and not Client Personal Data. If that factual position changes, Innova will reassess the provider before transmitting Personal Data.
Acceptance
This DPA is accepted with the Terms of Supply through the electronic acceptance recorded against the order.