Data Processing Agreement
Last updated: June 14, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Controller”) and Techmood, operator of Octopane (“Processor”), and applies where we process personal data on your behalf under the GDPR and equivalent laws.
1. Roles & scope
You are the Controller of the Microsoft 365 directory data we sync; Octopane is the Processor, acting on your documented instructions (the use of the service being such an instruction).
2. Subject matter & nature
- Subject matter: provision of the Octopane multi-tenant M365 management console.
- Categories of data: directory metadata, user profiles, license assignments, MFA registration state, Conditional Access summaries, sign-in/activity signals, Secure Score. No passwords; no mailbox, file, chat or calendar content.
- Data subjects: users of the client tenants you connect.
- Duration: for as long as a tenant is connected and your subscription is active.
3. Processor obligations
- Process personal data only on your instructions and for the service.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Section 5).
- Assist you, taking into account the nature of processing, with data-subject requests and security obligations.
- Delete or return personal data on termination, per the Privacy Policy.
4. Sub-processors
You authorize the following sub-processors; we will give notice of changes:
- Amazon Web Services, hosting & database (EU, eu-west-1).
- Clerk, authentication.
- Stripe, billing.
- Microsoft, Graph APIs accessed on your authorization.
5. Security measures
- Encryption in transit and at rest.
- App-only, short-lived Microsoft Graph tokens scoped to consented permissions; no stored tenant credentials.
- Enforced MFA for technician accounts and role-based access.
- Audit logging of administrative write actions.
6. International transfers
Primary processing occurs in the EU. Where a sub-processor processes data outside the EEA, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information reasonably available to help you meet your obligations.
8. Audits
On reasonable request and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA.