Data Processing Agreement

Processor commitments for personal data submitted through the portal.

Billed via Microsoft Marketplace
Last updated: 2026-05-10
This Data Processing Agreement (DPA) supplements the order or service agreement between you (the customer / data controller) and Modern Support Consult (the data processor). It applies to personal data submitted through the customer portal.
Back to Legal
Quick links
FAQ
Common questions
Support
Ask Fop
Architecture
Deployment paths
RFS
Request a scenario
Security
Report concerns
Privacy
Data handling
Terms
Usage conditions
Accessibility
Feedback channel
Partners
CSP marketing
Legal
Policies & agreements
1. Roles and scope
The customer is the controller of any personal data it submits or instructs us to process. Modern Support Consult acts as processor and processes such personal data only on documented instructions from the customer, including with regard to transfers to a third country.
Where the subscription is purchased through the Microsoft Commercial Marketplace, Microsoft acts independently as the merchant of recordfor the transaction (billing, taxes, invoicing, refunds) under its own terms with the customer. Microsoft is not a subprocessor of MSC/LuiT for that transactional data.
2. Categories of data and data subjects
  • Identification and contact data of the customer's administrators using the portal (name, work email, sign-in claims).
  • Organisational metadata: tenant ID, tenant domain, role claims.
  • Scenario inputs and notes provided by the customer.
  • Operational metadata: request identifiers, timestamps, status, audit trail entries.
Customer evidence files are not stored in the portal backend; uploads go directly from the browser to the customer-managed destination chosen by the customer.
3. Purpose and duration
Personal data is processed solely to operate the portal, run the requested assessments, generate the resulting artifacts, and meet legal obligations. Processing continues for the duration of the engagement and the documented retention windows below.
4. Security measures
  • Encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256, platform-managed keys).
  • Microsoft Entra ID OAuth 2.0 / OpenID Connect with delegated permissions only.
  • Least-privilege role-based access; production secrets stored in Azure Key Vault.
  • Centralised logging, tamper-evident audit trail, alerting on suspicious activity.
  • Secure SDLC: code review, dependency and secret scanning, annual third-party penetration testing.
5. Subprocessors
We engage the subprocessors listed on the subprocessors page. We will give the customer prior notice of any intended additions or replacements and provide the opportunity to object on reasonable grounds.
6. International transfers
Primary processing takes place in the European Union (Azure West Europe, Netherlands). No transfer to third countries is required to operate the portal in this lane; Marketplace billing is handled independently by Microsoft under its own terms.
7. Data subject rights
We assist the customer in responding to requests from data subjects exercising their rights under applicable law. See the data subject request page for the operational process.
8. Personal data breach notification
We will notify the customer without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting customer personal data, and provide the information reasonably required to enable the customer to meet its own notification obligations.
9. Retention and deletion
  • Request metadata: 365 days.
  • Audit trail: 730 days.
  • Generated output files created for the customer request: up to 365 days.
  • Requests for earlier removal or account-level data deletion review are handled through the written support process referenced by the engagement.
These retention windows apply to run metadata, audit records, and generated output files. They do not mean the portal application backend stores uploaded evidence files when evidence uploads are directed to the customer's designated workspace.
10. Audits
On reasonable request and subject to confidentiality, we make available the information necessary to demonstrate compliance with this DPA, including third-party assessment reports where available.
11. Contact
Use the support contact referenced by your engagement to request the signed counterpart of this DPA or to raise any data protection question.
2026 LuiT || ₷©®•Modern Support Consult•Hosted on Microsoft Azure + GitHub Enterprise
FAQSupportArchitectureRFSSecurityPrivacyTermsAccessibilityPartnersLegalTRIX
Support details(version & routing)
APImsc-portal-api-d7g5fudfa7eufufa.westeurope-01.azurewebsites.net
Builda30883e1@20260812T141507Z
LaneMicrosoft Commercial Marketplace (ISV Success)
Billing & licensing(public summary)
This portal provides structured assessments and actionable guidance. Results depend on what is observable and what changes are implemented in your environment.
Results depend on inputs
  • Online scenarios measure available signals (for example: public DNS records) and report what is observable at the time of the run.
  • Guidance describes recommended steps; applying them may require configuration changes, permissions, vendor behavior, and timing.
  • Outcomes are influenced by multiple moving parts; we focus on measurable improvements, defensible choices, and clear evidence you can act on.
How costs are calculated (customer view)
  • Microsoft Commercial Marketplace: Microsoft is the merchant of record. Microsoft handles billing, taxes, invoicing, refunds, plan changes, and cancellation under your Microsoft Customer Agreement. Manage the subscription from Azure Portal → SaaS subscriptions.
  • Plans & metering: per-plan price and any metered dimensions are visible in the Marketplace offer at checkout. Charges appear on your Microsoft invoice.
  • Customization-supported scenarios: scope and pricing are confirmed with you (in writing) before work begins, and only change if scope assumptions materially change.
  • Taxes are calculated and collected by Microsoft. Marketplace invoices are the source of truth.
Fairness & exceptions
Reconciliation is based on the agreed deliverables and the available inputs. If customer-side deliverables (access, approvals, change windows) are delayed after being identified as blockers, we may pause measurement or re-baseline the delivery window. We prefer fast, transparent review and adjust when the facts support it.
License scope
Some scenarios and deeper artifacts are intentionally restricted in public mode. For customization-supported engagements, licensing/procurement and exact deliverables are confirmed before work begins. If you need enterprise-wide terms or invoicing, use Support.
Why Modern Support Consult
Microsoft-first, on-prem friendly
MSC is built around Microsoft infrastructure and cloud operations, with on-premises realities treated as first-class. Built by an Exchange-focused specialist (~30 years IT; ~20 years Microsoft messaging & integration).
Curated, regulated guidance
Not random tips: curated and cross-compared to reduce noise and keep actions defensible.
Benchmarking + checklist outputs
Scenarios benchmark posture and produce checklist-style remediation aligned with mainstream security/ops methods.
Quadral method (Codex / Metaflow-ready)
Evidence → traceable outcomes: signals, checks, decisions, guidance, exceptions. Designed for consistent benchmarking and audit-friendly reasoning.
Use Close to return to the portal.