Privacy Policy
Last updated: June 14, 2026
This Privacy Policy explains what Octopane (“we”, “us”) collects, why, and how we handle it. Octopane is a console for managed service providers and IT teams to administer Microsoft 365 / Entra ID across their client tenants.
1. Who is responsible
Octopane is operated by Techmood. For the directory data we sync on your behalf, you (the subscribing organization) are the data controller and Octopane acts as your processor. See our Data Processing Agreement. For your own account data, we are the controller.
2. What we collect
Account & billing
- Identity and authentication data, handled by our auth provider Clerk (name, email, MFA).
- Organization name and team membership.
- Billing details processed by Stripe (we never see full card numbers).
Synced Microsoft 365 directory metadata
When a client tenant grants consent, we read directory metadata through the Microsoft Graph API on an app-only basis: user profiles, license assignments, MFA registration state and methods, Conditional Access policy summaries, sign-in / last-activity signals, and Secure Score history.
What we never access: passwords or credentials (authentication stays with Microsoft), and the content of mailboxes, files, chats or calendars.
3. How we use it
- To provide the service: dashboards, license cost analysis, MFA and security posture, bulk actions.
- To secure and operate the platform (audit logging, abuse prevention, support).
- To bill subscriptions and communicate service notices.
We do not sell personal data and we do not use client tenant data for advertising.
4. Sub-processors
- Amazon Web Services, hosting and database (EU, eu-west-1).
- Clerk, authentication and organization management.
- Stripe, payment processing.
- Microsoft, the Graph APIs we read on your authorization.
5. Where data is stored
Application data is hosted in AWS Europe (Ireland). Some sub-processors (e.g. Clerk, Stripe) may process limited data in other regions under appropriate safeguards such as Standard Contractual Clauses.
6. Retention
Synced tenant data persists while a tenant is connected; disconnecting a tenant removes its synced data. Account data is kept for the life of your subscription and deleted (or anonymized) within 90 days of account closure, except where law requires longer retention.
7. Security
Encryption in transit and at rest, enforced MFA for technician accounts, short-lived app-only Graph tokens scoped to the permissions your clients consented to, and an audit trail for every write action.
8. Your rights
Subject to applicable law (including the GDPR), you may request access, correction, deletion, export, or restriction of personal data. Data-subject requests relating to client tenants are handled through the controlling organization.
9. Contact
Questions or requests: support@octopane.io.