Privacy notice.
This notice explains how TensorSoft AI UK Ltd (“Tensor AI”, “we”) collects and uses personal data. It applies to visitors to tensorsoftai.io and to customers of our Marketplace and PWA products, and is written to satisfy the UK GDPR and the Data Protection Act 2018.
1 · Who we are
TensorSoft AI UK Ltd (company no. 17344319) is a company registered in England & Wales, with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the data controller for the personal data described in this notice. Our contact for privacy matters is privacy@tensorsoftai.io.
2 · Data we collect and why
2.1 When you visit tensorsoftai.io
- Server request logs — IP address, page requested, user-agent, timestamp. Retained 30 days. Used to keep the site secure and to detect abuse.
- No analytics cookies. This site does not run Google Analytics or similar third-party tracking.
2.2 When you subscribe to a Marketplace product
We receive the following from Microsoft when your subscription is activated: your Microsoft 365 tenant ID, purchaser email, purchaser name, plan ID, and seat count. We store this to activate your subscription, provide the service, and reconcile billing.
During normal operation, TenantGuard connects to the Microsoft Graph API of the tenant you have authorised, on a read-only basis, and retrieves:
- Sign-in logs (user principal name, IP, location, risk level, status, timestamp)
- Directory audit logs (activity, actor, target, timestamp)
- Secure Score snapshots
- Risky user assessments from Microsoft Entra Identity Protection
This data is stored in our Azure UK South PostgreSQL database for the retention period below.
2.3 When you buy a PWA product
We receive your email address, name, and payment token from our payment processor. Product content (invoices, passwords, financial data) is stored locally on your device and is never transmitted to us.
2.4 When you email us
We keep the thread until it is closed and archive it for two years afterwards so we can respond to follow-up queries and comply with our record-keeping obligations.
3 · Legal basis
We rely on the following legal bases under Article 6 of the UK GDPR:
- Performance of a contract for anything we do to deliver a product you have bought or subscribed to.
- Legitimate interests for security logging, fraud prevention, and improving our services. We have assessed that our interest does not override your rights and freedoms.
- Legal obligation for retention required by UK tax, company, and accounting law.
- Consent for optional marketing emails (we do not currently send any).
4 · Retention
| Data | Retention |
|---|---|
| Website request logs | 30 days |
| TenantGuard sign-in and audit events | 90 days from receipt |
| TenantGuard Secure Score snapshots | Lifetime of the subscription |
| TenantGuard alert history (acknowledged) | 90 days after acknowledgement |
| Marketplace subscription record | Lifetime of the subscription plus 30 days |
| Financial records (invoices, receipts) | 7 years (HMRC requirement) |
| Support email threads | 2 years after closure |
5 · Where we store data
All customer-visible services run in Microsoft Azure, UK South region. Personal data does not leave the United Kingdom during normal operation. Two limited exceptions:
- Email delivery — outbound emails may transit servers operated by SendGrid (EU/US). No email content is retained on those servers longer than delivery requires.
- Microsoft services — the Microsoft Graph API and Azure Marketplace platform are operated by Microsoft under its own privacy commitments.
6 · Sharing
We do not sell personal data. We share it only with:
- Microsoft — our infrastructure host and Marketplace partner, under a data processing agreement.
- SendGrid (Twilio) — for outbound email delivery, under their data processing terms.
- UK courts and regulators — where required by law.
- A future acquirer — only if the company is sold, and only with equivalent commitments in place.
7 · Your rights
Under the UK GDPR you have the right to:
- See what we hold about you (right of access)
- Have inaccurate data corrected
- Have data deleted, subject to our legal retention obligations
- Object to processing based on legitimate interests
- Receive your data in a portable format
- Withdraw consent where processing is consent-based
- Complain to the Information Commissioner's Office (ico.org.uk)
To exercise any of these rights, email privacy@tensorsoftai.io. We aim to respond within 30 days as required by law.
8 · Cookies
tensorsoftai.io sets no third-party cookies. The TenantGuard application sets one first-party session cookie (connect.sid) that is essential for keeping you signed in. It is HttpOnly, Secure, SameSite=Lax, and expires after 8 hours of inactivity.
9 · Children
Our products are aimed at businesses. We do not knowingly collect personal data from anyone under 18. If you believe we have, please email privacy@tensorsoftai.io and we will delete it.
10 · Changes to this notice
Material changes will be announced by email to Marketplace customers 30 days before they take effect. Non-material changes may be published without notice; the version and effective date at the top of this page always reflect the current text.
11 · Contact
Privacy queries: privacy@tensorsoftai.io
General contact: hello@tensorsoftai.io
Security disclosures: security@tensorsoftai.io
Tensor AI