Legal
How we use personal information about visitors, buyers and business contacts — and the separate position that applies when Vitals reads a customer's Microsoft 365 tenant on their instructions, which the Data Processing Agreement governs.
Vitals Privacy Notice
Version 1.0 | Effective 15 September 2026
This notice explains how Innova Technologies Group Ltd uses personal information in connection with the Vitals website, purchasing and administration of Vitals, customer communications, and related business operations. It also explains the separate position where Innova processes Microsoft 365 tenant information on a customer's instructions.
1. Who we are
Vitals is a product of Innova Technologies Group Ltd (company number 17205930, VAT number 519893442), registered office 7 Stromberg Street, Anlaby, Hull, HU10 7ER, trading as Innova Group.
For the personal information described in this notice that we use for our own business purposes, Innova Technologies Group Ltd is the controller. You can contact us at hello@tenantvitals.com.
2. What this notice covers
This notice covers personal information relating to visitors to tenantvitals.com and app.tenantvitals.com, buyers and prospective buyers, authorised approvers and report recipients, IT providers and other business contacts.
When Vitals accesses a customer's Microsoft 365 tenant to perform an Assessment, Innova normally acts as a processor for the customer, or as a sub-processor where an IT provider purchases Vitals for its end client. That processing is governed by the applicable Vitals Data Processing Agreement or IT Provider / MSP Agreement rather than by Innova deciding to use the tenant data for its own purposes.
3. Information we collect and why
| Information | How we use it | Lawful basis | Typical source |
|---|---|---|---|
| Name, business email address, company and role | To deal with enquiries, orders, approvals, delivery, support and account administration. | Contract, steps requested before a contract, and legitimate interests in operating and supporting Vitals. | You, your employer, buyer or IT provider. |
| Order and transaction information | To take payment, issue receipts, administer refunds, maintain accounting records and deal with disputes. | Contract and legal obligations; legitimate interests in financial administration and fraud prevention. | You and our payment provider. |
| Marketing source or referral information | To understand which source led to an enquiry or order and measure the effectiveness of our own marketing. | Legitimate interests in understanding and improving how Vitals is marketed, subject to applicable PECR requirements. | The page or referral information available during your visit and, if you proceed, the order record. |
| Website and technical information | To operate, secure and understand use of the Vitals website and application, including aggregated website analytics. | Legitimate interests in security, service operation and improvement. Where PECR applies to storage or access on your device, we rely only on an applicable exception unless consent is obtained. | Your browser/device and our hosting or analytics services. |
| Communications | To respond to you and send transactional messages about consent, approvals, reports, release, reminders, refunds and service matters. | Contract, steps before contract, legal obligations and legitimate interests in administering Vitals. | You and people involved in the relevant order. |
4. Cookies, browser storage and website analytics
We do not use advertising or behavioural-tracking cookies on the Vitals marketing website.
The Vitals application uses an ASP.NET Core antiforgery cookie to protect forms against cross-site request forgery. It may also use session-only browser storage for interface state, such as preventing an introductory animation from replaying during the same browser session. These technologies are used for security or requested service functionality, not behavioural advertising.
Vitals does not store marketing attribution information in cookies, local storage or session storage. Where we record how a visitor reached Vitals, that information is held only for the current visit and may be associated with an order if the visitor proceeds to purchase.
We use Vercel Web Analytics on the marketing website to understand aggregate website use. Vercel states that Web Analytics does not use analytics cookies and stores anonymised, aggregated analytics data rather than information that identifies an individual visitor.
We keep our use of cookies and other storage/access technologies under review. If we introduce a technology that requires consent under PECR, we will obtain consent before using it.
5. Payments and service providers
We use service providers to operate Vitals. Depending on the interaction, they may receive personal information necessary to provide their service:
- Stripe — payment processing and related transaction services.
- Resend (Plus Five Five, Inc.) — transactional email delivery, including messages containing report-access links.
- Microsoft Azure — hosting, compute and storage for the Vitals application and customer Assessments.
- Vercel — hosting of the Vitals marketing website and privacy-focused Web Analytics.
We require processors acting on our behalf to handle personal information under appropriate contractual and data-protection obligations.
6. AI-generated recommendations
Vitals uses Anthropic PBC's Claude API to generate prioritised recommendation text from assessment findings. Before the request is sent, Vitals removes identifying examples and does not deliberately send tenant or company names, tenant domains, buyer names, email addresses, account identifiers, file or folder paths, sharing links or report URLs. The payload consists of scores, bands, categories, severities, generic finding text and counts.
On the current design, this payload is intended to be anonymous in Anthropic's hands and is not treated by Innova as Client Personal Data. If the design changes so that personal information would be sent to an AI provider, we will reassess the processing and update the applicable contractual and privacy information before doing so.
7. Microsoft 365 Assessment data
When a customer authorises a Vitals Assessment, the service uses read-only Microsoft Graph permissions to examine relevant Microsoft 365 configuration and metadata. This can include user and guest account identifiers, device and compliance metadata, sharing metadata, authentication-method registration information, activity-report metadata and mailbox-rule metadata such as rule names, conditions and forwarding addresses.
Vitals does not read the contents of email messages, Teams chat messages or files. The detailed categories, permissions, purposes, retention arrangements and processor obligations are set out in the applicable Vitals Data Processing Agreement or IT Provider / MSP Agreement.
8. Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide Vitals, meet legal and accounting obligations, resolve disputes and establish or defend legal claims.
Customer report-access and Assessment retention periods are governed by the applicable Vitals agreement and DPA. Certain commercial records, such as company, invoice, payment and transaction information, may be retained for longer where required for tax, accounting, fraud-prevention or legal purposes.
Vitals may retain de-identified assessment profiles containing scores, counts, licence mix and rule version for benchmarking, comparison and improvement of assessment rules. These profiles are designed without fields for tenant name, domain, file path or email address and are retained only to the extent they are not personal data.
9. International transfers
Some of our service providers are based in, or may process information from, countries outside the United Kingdom. Where personal information is transferred internationally, we use an applicable UK data-transfer mechanism or other lawful safeguard where required. Further information about relevant safeguards is available from us on request.
10. Your rights
Depending on the circumstances, UK data-protection law may give you rights to ask us for access to your personal information, to correct or erase it, to restrict or object to processing, and to receive certain information in a portable form. Where processing is based on consent, you may withdraw that consent without affecting earlier lawful processing.
Where we rely on legitimate interests, you may object to processing in appropriate circumstances. We will consider the objection against the relevant legal requirements.
To exercise a right or ask a privacy question, email hello@tenantvitals.com. We may need to verify your identity before acting on a request.
11. Complaints
Please contact us first if you have a concern about how we use personal information. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection regulator. Information about making a complaint is available at ico.org.uk.
12. Changes to this notice
We may update this notice when Vitals, our providers or applicable law changes. The current version will be published with its effective date. Material changes will be brought to the attention of affected people where required.
Contact
Innova Technologies Group Ltd
7 Stromberg Street, Anlaby, Hull, HU10 7ER
Email: hello@tenantvitals.com