Legal

Privacy policy

What Power Insights reads from your Microsoft 365 tenant, what it stores and where, who else is involved, how long it is kept, and what you can ask of us.

Last updated 16 September 2026

1.Who we are

LogiSam provides Power Insights and is the controller of the personal data described in this policy, except for the contents of your tenant's inventory, which we process on your organisation's instructions as a processor. This policy covers the public website at powerplatformiq.com and the signed-in service.

It is written under the UK GDPR and the Data Protection Act 2018. If you are outside the UK, the equivalent rights under your own law apply.

2.What we collect

Your sign-in identity. When you sign in with Microsoft we receive your name, email address, the identifiers of your account and tenant, and the tokens Microsoft issues so the service can read the tenant on your behalf. We never see your password.

Your tenant's Power Platform inventory. When you run an assessment the service reads metadata from your Microsoft 365 tenant: environments, Power Apps, Power Automate flows, connections, connectors, solutions, Dataverse tables and connection references — their names, identifiers, state, owners, sharing, triggers, connectors and definitions. Owners and people apps are shared with appear by name and email address where Microsoft returns them. The service does not read the business data inside your apps, flows or tables.

What you create in the service. Organisations and their members, collections, migration plans and notes, share links, refresh-plan findings, plan and billing status, and support and website enquiries you send us.

Technical data. Server logs (IP address, user agent, timestamps, the page requested), an audit log of administrative actions, and analytics as described under cookies.

3.Why we use it, and on what basis

  • To provide the service — signing you in, reading and storing the assessment, showing it to you and the colleagues you invite, exports and sharing. Basis: performance of our contract with you or your organisation.
  • To bill paid plans through our payment provider. Basis: contract and legal obligation.
  • To keep the service secure and working — logs, the audit trail, abuse and spam prevention on the contact form. Basis: our legitimate interest in running a secure service.
  • To understand how the website and product are used, in aggregate, through analytics. Basis: consent where the law requires it, otherwise legitimate interest.
  • To answer you when you contact us. Basis: legitimate interest, or steps taken at your request before a contract.

We do not sell personal data, and we do not use your tenant's data to train models.

4.Where it is stored

The service runs on Microsoft Azure in the UK South region. Assessments, organisations, sessions and the audit log are held in an Azure SQL database in that region, encrypted at rest and in transit. Configuration secrets are encrypted before they are stored.

Your Microsoft tokens are held only inside your server-side session, which expires after twelve hours of inactivity and is deleted when you sign out.

5.Who else is involved

We use the following providers to run the service. Each acts on our instructions under a data-processing agreement.

  • Microsoft — Azure hosting and database (UK South); Microsoft Entra ID for sign-in; the Power Platform, Power Automate, Dataverse and Microsoft Graph APIs the service reads through.
  • Stripe — payment processing for paid plans. Card details go directly to Stripe and never touch our servers.
  • Google Analytics — aggregate website and product usage analytics (see cookies).
  • Google reCAPTCHA — spam scoring on the public contact form, where enabled.
  • Our email provider — transactional email such as invitations, billing reminders and enquiry acknowledgements.

Some of these providers process data outside the UK. Where they do, transfers rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.

6.Cookies and analytics

The service sets a small number of cookies and browser-storage entries:

  • ppiq_sid — a signed session identifier, set when you sign in. Strictly necessary; expires after twelve hours of inactivity or when you sign out.
  • ppiq-theme and similar local-storage entries — remember your light or dark theme, collapsed navigation and table layout. Stored only in your browser; never sent to us.
  • Google Analytics (_ga, _ga_*) — measure visits and pages, with IP anonymisation. Used to understand which pages are read and which features are used. You can opt out with Google's browser add-on or by blocking third-party cookies; the service works without them.
  • Stripe sets its own cookies on its checkout pages when you buy a plan.

7.How long we keep it

  • Assessments — one current assessment per tenant; a refresh replaces it in place. Deleted when the organisation is deleted.
  • Organisation, members, collections and migration plans — for as long as the organisation exists.
  • Sessions — twelve hours of inactivity, or sign-out.
  • Audit log and server logs — up to twelve months, for security and support.
  • Billing records — as long as tax and accounting law requires, typically six years.
  • Enquiries — until answered and for up to two years afterwards.

Backups of the database are retained for a short period and overwritten in the ordinary course of operation; data deleted from the live service leaves backups on that cycle.

8.Your rights

You have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where consent is the basis. You can delete your organisation and its stored assessment yourself from the service's settings, and revoke the service's access to your tenant from the Microsoft Entra admin centre at any time.

To exercise any other right, contact us using the details below. We will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) or to your local supervisory authority.

If you appear in an organisation's assessment as the owner of an app or flow, that organisation is the controller of that record; direct requests about it to them, and we will help them respond.

9.Security

Access to your tenant is delegated through Microsoft Entra ID and is limited to what your own account is permitted to see. Data is encrypted in transit and at rest; administrative actions are audited; access to production systems is restricted to the people who operate the service. No system is perfectly secure, and if a breach affects your personal data we will tell you and the relevant authority as the law requires.

10.Changes to this policy

We may update this policy as the service changes. The date at the top is the current version. Material changes are announced in the service or by email to organisation owners. The terms and conditions incorporate this policy.

Questions

Write to us through the LogiSam contact page. See also our terms and conditions.