Privacy Policy
This page explains how MAQ Techs AB processes personal data in connection with our website, customer dialogues, support matters, and business relationships.
1. Data controller
MAQ Techs AB is the data controller for the personal-data processing described in this policy when we determine the purposes and means of the processing.
- MAQ Techs AB
- Uppsala, Sweden
- support@maqtechs.com
- +46 107 075 999
In some customer engagements we may also act as a processor on behalf of our customers. In those cases, the processing is governed by a separate data-processing agreement or the customer contract.
2. M365 Audit Tool – Data Handling
The M365 Audit Tool (maqtechs.com/en/m365-audit) is a separate tool that, after your administrator explicitly signs in and grants consent through Microsoft's own sign-in and consent screen, connects to your Microsoft 365 environment via the Microsoft Graph API to read a set of metrics and compile a report.
The tool requests the following read permissions (scopes) from Microsoft Graph:
- openid, profile, email – basic identification of the signed-in administrator.
- User.Read – basic profile information.
- Reports.Read.All – e.g. MFA registration and usage reports.
- Directory.Read.All – licence data, directory roles (e.g. Global Administrator count), and guest users.
- Policy.Read.All – Conditional Access policies.
- UserAuthenticationMethod.Read.All – authentication methods (MFA status).
- SecurityEvents.Read.All – Microsoft Secure Score.
All permissions above are read-only. The tool never makes any changes, writes, or configuration adjustments in your Microsoft 365 environment — it only reads data to generate the report.
The access token Microsoft issues at sign-in is stored only temporarily in server memory while the audit runs, and is deleted immediately afterward. We do not request persistent access (no "offline_access" scope), so every audit requires a fresh consent. The report is shown directly to the signed-in administrator. A summary of the results (the administrator's name and email, plus the metrics that were read) is also emailed to our internal team at info@maqtechs.com for follow-up. This summary is kept for up to 90 days for sales follow-up purposes, after which it is deleted. No audit data is stored in a separate database.
Only de-identified, aggregated metrics (for example the share of MFA-registered users, Secure Score, and administrator count — never names or email addresses) are sent to our AI provider, Anthropic, to generate the report's written summary and recommendations. We never sell audit data and do not share it with any third parties other than those named here.
Since audit results are not stored in a database but only in the internal email above, you can request its deletion by contacting support@maqtechs.com. We respond to such requests within 30 days.
The legal basis for this processing is the explicit consent your administrator provides via Microsoft's OAuth consent screen before the audit is run.
3. What personal data we process
The data we process depends on how you interact with us. It may include:
- Contact details such as name, email address, phone number, and company name.
- Information you provide in contact forms, quote requests, meeting bookings, or support cases.
- Communication history such as emails, meeting notes, and support dialogues.
- Customer and contract information such as role, organisation, invoicing data, and delivery information.
- Technical website-use information such as IP address, logs, and security-related information.
4. Purposes and legal basis
We process personal data only where there is a clear and lawful basis under the GDPR.
5. Where the data comes from
Most personal data is collected directly from you or the organisation you represent. In some cases, information may also come from email signatures, public company details, or existing customer relationships.
7. Transfers outside the EU/EEA
We aim to use services within the EU/EEA whenever possible. If personal data is nevertheless transferred outside the EU/EEA, we ensure that a lawful transfer mechanism is in place, such as the European Commission’s standard contractual clauses or an adequacy decision.
8. How long we keep the data
We keep personal data for as long as necessary for the purpose for which it was collected, and thereafter only as long as required by law or to handle legal claims.
- Contact enquiries are normally kept while the dialogue is active and thereafter for a reasonable follow-up period.
- Customer and contract data is kept during the contract term and thereafter as long as required under accounting and contract-law rules.
- Security and technical logs are kept only as long as needed for operations, troubleshooting, and security.
9. Your rights
Under the GDPR, you have the right to request information about how we process your personal data and, depending on the circumstances, have it corrected, erased, restricted, or transferred.
- Right of access.
- Right to rectification.
- Right to erasure.
- Right to restriction of processing.
- Right to data portability where applicable.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent where processing is based on consent.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe our processing violates applicable data-protection rules.
11. Security
We use organisational and technical security measures to protect personal data against unauthorised access, loss, alteration, or disclosure. The level of protection is adapted to the type of data involved and the risk presented by the processing.
12. Contact
If you want to exercise your rights or have questions about this policy, you are welcome to contact us.
