1. Scope and current product status
This notice covers the public SecuraVouch website, support and commercial enquiries, approved controlled evaluations, and any future SecuraVouch service made available under an applicable agreement. SecuraVouch is a controlled pre-release and is not yet generally available through Microsoft Marketplace. Production customer data is not authorized for a reference deployment unless a customer agreement, data-processing terms, retention schedule and approved deployment are in place.
2. Controller and processor roles
securagen.ai P.C. is controller for this website, direct enquiries and its own service administration and security records. For customer content processed in a contracted deployment, the customer ordinarily determines the purposes and essential means of processing and securagen.ai ordinarily acts as processor, subject to the signed agreement and data-processing addendum. A trial-specific notice will identify any different allocation.
3. Categories and sources of data
Depending on the surface used, the following categories may be processed:
- Website and security data: IP address, request time, URL, user-agent, response and security-event data generated by the hosting and network layer.
- Contact data: name, business contact details, organization, message and correspondence supplied directly by you or your organization.
- Account and identity data: Microsoft Entra tenant and object identifiers, display name, assigned role and authentication context supplied by Microsoft services under the customer's configuration.
- Microsoft Teams context: meeting, organizer, session and participant references required for an approved assurance workflow.
- Protected-action and evidence data: request details, configured policy, authorized-principal decisions, state transitions, time-bounded permits and signed evidence.
- Marketplace and licensing data: subscription, plan, purchaser and entitlement information supplied by Microsoft if a Marketplace offer becomes available.
- Support and audit data: diagnostic details, timestamps, resource and actor identifiers, support correspondence and security records.
Data is obtained from you, your organization and its administrators, configured Microsoft services, and automatically from the systems used to deliver and secure the relevant service. Required fields are identified by the applicable workflow or agreement; without them the requested function may not be available.
4. Purposes and legal bases
- Provide requested information, trials, support and contracted services: performance of a contract or steps requested before entering one.
- Authenticate principals, evaluate configured policy, generate evidence, secure services and prevent abuse: contract performance and legitimate interests in providing a secure and accountable B2B service.
- Administer subscriptions, billing and business records: contract performance and compliance with legal obligations.
- Establish, exercise or defend legal claims and investigate incidents: legitimate interests and legal obligations.
- Use consent only where it is specifically requested; consent can be withdrawn without affecting earlier lawful processing.
Where a customer is controller, the customer is responsible for identifying its lawful basis, providing required notices and configuring authority and retention rules lawfully.
5. Website cookies and analytics
The SecuraVouch website code does not set cookies and contains no external JavaScript, advertising trackers, behavioural advertising or third-party analytics. Microsoft Azure may process network and security metadata to deliver and protect the site. If optional analytics or non-essential cookies are introduced, this notice and any required consent mechanism will be updated before activation.
6. Authentication tokens and secrets
Authentication tokens may be processed transiently to authenticate and authorize requests. They are not customer-profile data. SecuraVouch is designed to avoid persisting raw bearer tokens and to keep them out of normal application logs. Users must not send passwords, tokens, private keys or client secrets through email support.
7. Recipients and service providers
Data may be disclosed to authorized securagen.ai personnel, the customer organization controlling a deployment, professional advisers, competent authorities where legally required, and contracted providers needed to host, secure and support the service. Microsoft services may include Azure, Microsoft Entra, Microsoft Teams, Microsoft Graph and Microsoft Marketplace. A deployment-specific subprocessor list and contractual terms will be made available before production customer data is admitted.
8. International transfers and Data Act transparency
Microsoft Azure provides the public website and may use globally operated infrastructure. Where personal data is transferred outside the EEA, the applicable agreement must provide a lawful transfer mechanism, such as an adequacy decision or approved contractual safeguards. SecuraVouch is not currently offered as a generally available operational data-processing service. Before such availability, the service-specific infrastructure jurisdiction and measures concerning conflicting international governmental access to non-personal data will be published and kept current.
9. Retention and deletion
Public-site network and security data is retained only for the period made available by the hosting provider or needed to investigate an event. Enquiry and support records are retained while the request is active and afterwards only as needed for follow-up, security, contractual, accounting or legal obligations. Controlled-trial and contracted-service retention must be set in the trial notice, customer agreement or retention schedule before data is admitted. Short-lived authorization artifacts expire under configured policy; expiry does not itself delete signed evidence or audit records.
10. Security
Safeguards are selected for the applicable deployment and may include tenant-scoped access control, protected external references, cryptographic integrity checks, short-lived signed permits, secret-management controls, restricted logging and tested failure handling. No website can guarantee absolute security. Report suspected vulnerabilities through Support without including live secrets.
11. Policy evaluation and human responsibility
SecuraVouch applies deterministic customer-configured authorization rules; it is not designed for advertising profiles, biometric identification or autonomous legal decisions about individuals. Organizational administrators define roles and policies, authorized principals make the relevant decisions, and the customer remains responsible for human review, authority assignments, connector operation and the lawfulness of the protected action.
12. Your privacy rights
Subject to applicable law and the relevant controller relationship, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. EEA residents may complain to their local supervisory authority or the Hellenic Data Protection Authority. Where a customer controls the data, requests may be referred to that customer.
Residents of U.S. states with applicable privacy rights may request access to or confirmation of data, correction, deletion or portability, and may appeal a refusal where local law provides that right. SecuraVouch does not sell personal data, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not discriminate for exercising an applicable privacy right.
13. Children and business use
SecuraVouch is a business service and is not directed to children. Do not submit personal data of anyone under 18 through a pre-release evaluation. A customer must assess and document any exceptional regulated use before it is enabled.
14. Contact and changes
Submit privacy requests to info@securagen.ai or write to securagen.ai P.C., 44 Kifisias Ave., Bldg. C, 15125 Marousi, Greece. We may verify identity and authority before acting on a request. Material changes will be dated and published at this URL.