Privacy Policy

Effective: February 2026

Who We Are

M365Shield ('we', 'us') operates the website m365shield.com and provides Microsoft 365 security assessment and deployment services.

What We Collect

When you fill out our risk check form, we collect:

  • Your name
  • Email address
  • Business name
  • Primary domain
  • Number of M365 users
  • Optionally, your phone number and insurance renewal date

How We Use Your Information

We use your information to:

  • Perform the requested security assessment
  • Deliver your assessment and deployment reports
  • Communicate about your service engagement
  • Improve our service

Tenant Access & Data Handling

During assessments and deployments, we access your Microsoft 365 tenant configuration settings. We operate under the following strict controls:

  • Read-only access: During assessment, we only read configuration. We never access email content, file content, or user passwords.
  • Configuration changes only: During deployment, we only modify configuration settings. We never touch email data, file data, or user credentials.
  • Full audit logging: All configuration changes are logged in your Microsoft 365 audit trail.
  • Complete reversibility: All changes are fully reversible. We provide a rollback package upon completion.
  • Access revocation: Tenant access is revoked immediately upon completion of the engagement.

Data Sharing

We do not sell, rent, or share your personal information with third parties. We may share information with:

  • Service providers who assist in our operations (under confidentiality agreements)
  • As required by law

Data Retention

We retain your assessment and deployment reports for 12 months after engagement completion. You may request deletion at any time by contacting us at [email protected].

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Withdraw consent

Contact us at [email protected] to exercise these rights.

Security

We protect your data using:

  • Encryption in transit (HTTPS)
  • Access controls (role-based permissions)
  • Audit logging (all data access is logged)

Our internal practices align with security best practices.

Changes

We may update this policy. Changes will be posted on this page with an updated effective date.

Contact

Questions about this policy? Contact us at [email protected].