Securenix · Technix IT AB Personal data in SecurenixSecurenix produces a read-only security health scan of a Microsoft 365 tenant. This page says in plain language which personal data that involves, on what legal basis it is processed, how long it is kept and how it is erased. The field-by-field detail is in the data processing annex. Who is responsible for whatTechnix is the processor for tenant data Everything Securenix reads in a customer's Microsoft 365 tenant or on-premises environment belongs to the customer. Technix processes it on the customer's behalf, solely to produce the scan and the report, and only for as long as the customer remains in Securenix. Technix is the controller for its own staff and audit trail Securenix has no customer log-ins: everyone who signs in is Technix staff, gated by a single Entra security group. Technix is the controller for those sign-ins, for the audit log that records which technician started a scan, created a report link or deleted a customer, and for the evidence that a customer consented. Which personal data Securenix storesA scan is a snapshot of security configuration, not of content. Most of what is stored is counts and policy names. Personal data appears only where a finding would be useless without it — a technician cannot fix “an administrator without MFA” without knowing which account it is.
What Securenix never doesThe scan is deliberately narrow. These are guarantees in the code, not statements of intent.
Legal basisTwo grounds carry the processing, and for tenant data Technix acts on the customer's instruction. Article 6(1)(b) — contract The scan is performed to deliver the service the customer or prospect asked for. The customer's Global Administrator grants the access themselves and can withdraw it at any time from their own tenant. Article 6(1)(f) — legitimate interest Access control for Technix staff, the audit log of who did what, and the evidence that a customer agreed to be scanned. Traceability of who has read a customer's security posture is in both parties' interest. Article 28 — processing on instruction For tenant data Technix acts on the customer's documented instruction under a data processing agreement; this page and the annex are its description of the processing. How long data is keptScans and findings — until the customer is deleted Each scan is a complete snapshot and is never rewritten; a new scan is a new run, so the history shows how the posture developed. There is no automatic expiry: the sanctioned way to remove scan data is to delete the customer, which erases every run, finding and piece of evidence. Shared report links — 14 days by default, 90 at most An expiry is mandatory and enforced on the server, and a link can be revoked immediately. Only the hash of the token is stored, and each view increments a counter and a timestamp — nothing else. Audit log — kept Audit rows survive the deletion they record, which is the point of them. They name the acting technician and the company, never the deleted customer's own personal data. Consent evidence — kept after deletion The dates and email addresses of the consent survive the deletion of the customer, so Technix can show that the scan was agreed to. The name, IP address and browser recorded when the terms were accepted are erased with the customer. Application logs — 90 days Operational logs in Azure Monitor are kept for 90 days in production. They carry no secrets and no tokens; the token in a report URL is redacted before the request is logged. Data subject rightsRequests about tenant or on-premises data are answered by the customer as controller; Technix assists as processor and acts on the customer's instruction. Write to the address below and we will handle it together with the customer. Access Everything Securenix holds about a customer is visible in the app and can be exported per scan. We can produce the same extract on request. Erasure Deleting a customer in Securenix is a hard delete of the whole aggregate: consent records, scans, findings, evidence, report links, on-premises audits and upload tokens. A single audit row remains, without personal data, together with the consent evidence: its dates and the email addresses of the invitation and the terms acceptance. Rectification A finding records what the tenant looked like at one point in time and is not edited. Correct the configuration and run a new scan; the new run is the current picture. Withdrawing access The customer removes Securenix in their own tenant under Enterprise applications and Securenix loses access at once — no further scan can read anything. Removing what was already collected is the erasure above. Where the data isSecurenix runs in Microsoft Azure in Sweden. The database uses Entra-only authentication with no SQL log-ins, secrets live in Key Vault and are reached with a managed identity, and all traffic is HTTPS. Securenix itself transfers no data outside the EU/EEA. Hosting swedencentral Sub-processor Microsoft Azure. No other sub-processor. ContactQuestions about privacy in Securenix, or a request from a data subject, go to Technix at the address below. The annex lists every source, permission and field. Last updated 2026-09-10. |