Data Processing Agreement
Processor commitments for personal data submitted through the portal.
Billed via Microsoft Marketplace
Last updated: 2026-05-10
This Data Processing Agreement (DPA) supplements the order or service agreement between you (the customer / data controller) and Modern Support Consult (the data processor). It applies to personal data submitted through the customer portal.
Quick links
1. Roles and scope
The customer is the controller of any personal data it submits or instructs us to process. Modern Support Consult acts as processor and processes such personal data only on documented instructions from the customer, including with regard to transfers to a third country.
Where the subscription is purchased through the Microsoft Commercial Marketplace, Microsoft acts independently as the merchant of recordfor the transaction (billing, taxes, invoicing, refunds) under its own terms with the customer. Microsoft is not a subprocessor of MSC/LuiT for that transactional data.
2. Categories of data and data subjects
- Identification and contact data of the customer's administrators using the portal (name, work email, sign-in claims).
- Organisational metadata: tenant ID, tenant domain, role claims.
- Scenario inputs and notes provided by the customer.
- Operational metadata: request identifiers, timestamps, status, audit trail entries.
Customer evidence files are not stored in the portal backend; uploads go directly from the browser to the customer-managed destination chosen by the customer.
3. Purpose and duration
Personal data is processed solely to operate the portal, run the requested assessments, generate the resulting artifacts, and meet legal obligations. Processing continues for the duration of the engagement and the documented retention windows below.
4. Security measures
- Encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256, platform-managed keys).
- Microsoft Entra ID OAuth 2.0 / OpenID Connect with delegated permissions only.
- Least-privilege role-based access; production secrets stored in Azure Key Vault.
- Centralised logging, tamper-evident audit trail, alerting on suspicious activity.
- Secure SDLC: code review, dependency and secret scanning, annual third-party penetration testing.
5. Subprocessors
We engage the subprocessors listed on the subprocessors page. We will give the customer prior notice of any intended additions or replacements and provide the opportunity to object on reasonable grounds.
6. International transfers
Primary processing takes place in the European Union (Azure West Europe, Netherlands). No transfer to third countries is required to operate the portal in this lane; Marketplace billing is handled independently by Microsoft under its own terms.
7. Data subject rights
We assist the customer in responding to requests from data subjects exercising their rights under applicable law. See the data subject request page for the operational process.
8. Personal data breach notification
We will notify the customer without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting customer personal data, and provide the information reasonably required to enable the customer to meet its own notification obligations.
9. Retention and deletion
- Request metadata: 365 days.
- Audit trail: 730 days.
- Generated output files created for the customer request: up to 365 days.
- Requests for earlier removal or account-level data deletion review are handled through the written support process referenced by the engagement.
These retention windows apply to run metadata, audit records, and generated output files. They do not mean the portal application backend stores uploaded evidence files when evidence uploads are directed to the customer's designated workspace.
10. Audits
On reasonable request and subject to confidentiality, we make available the information necessary to demonstrate compliance with this DPA, including third-party assessment reports where available.
11. Contact
Use the support contact referenced by your engagement to request the signed counterpart of this DPA or to raise any data protection question.