Privacy Policy
How we collect, use, and protect your data
Last updated: September 9, 2026
1. Introduction
GraphCapsule ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Microsoft 365 archiving and backup service.
2. Information We Collect
Account Information
When you register for our service, we collect:
- Name and email address
- Company name and business information
- Billing and payment information
- Microsoft 365 tenant information
Microsoft 365 Data
To provide our backup and archiving services, we process:
- Email messages and attachments from Exchange Online
- Files and documents from OneDrive and SharePoint
- Calendar items, contacts, and tasks
- Teams channel content and collaboration data
- Metadata associated with the above content
Usage Data
We automatically collect certain information about your use of our service:
- Log data (IP address, browser type, pages visited)
- Device information
- Service usage statistics
- Performance and error logs
3. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve our backup and archiving services
- Process backup jobs and restore operations
- Ensure data security and prevent unauthorized access
- Communicate with you about your account and our services
- Process payments and billing
- Comply with legal obligations and enforce our Terms of Service
- Analyze usage patterns to improve service performance
4. Data Processing and Storage
Legal Basis
We process your data as a data processor on your behalf under the General Data Protection Regulation (GDPR). You remain the data controller for all Microsoft 365 content that we backup and archive.
Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256-GCM)
- Role-based access controls
- Regular security audits and monitoring
- Secure data centers with physical security controls
- Incident response and disaster recovery procedures
Data Location
Your data is stored in secure data centers within the European Union. We do not transfer data outside the EU without appropriate safeguards in compliance with GDPR requirements.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information only in the following circumstances:
- Service Providers: With trusted third parties who assist in operating our service (e.g., hosting providers, payment processors)
- Legal Requirements: When required by law or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share information
6. Data Retention
We retain your Microsoft 365 backup data for as long as you maintain an active subscription. Upon termination of your account:
- You have 30 days to export your archived data
- After 30 days, all backup data is permanently deleted
- Account information is retained for legal and accounting purposes as required by law
7. Your Rights
Under GDPR and other data protection laws, you have the following rights:
- Access: Request access to your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request limitation of data processing
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to certain types of data processing
- Withdraw Consent: Withdraw consent for data processing at any time
To exercise these rights, please contact us at [email protected]
8. Cookies and Tracking
We use cookies and similar technologies to improve your experience, analyze usage, and provide personalized content. You can control cookie settings through your browser preferences.
Types of cookies we use:
- Essential Cookies: Required for service functionality
- Analytics Cookies: Help us understand usage patterns
- Preference Cookies: Remember your settings and preferences
9. Children's Privacy
Our service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through our service. Your continued use of the service after changes take effect constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
12. Supervisory Authority
If you have concerns about our data processing practices, you have the right to lodge a complaint with your local data protection authority. For Germany, this is the Bundesbeauftragte fur den Datenschutz und die Informationsfreiheit (BfDI).
