Privacy Policy
OfficeSyncPro connects your Outlook mailbox and calendar to the projects your team runs, which means we handle data belonging to you and to the people you work with. This policy sets out exactly what we collect, why, who else sees it, how long we keep it and what you can ask us to do about it.
Effective 18 August 2026 · Last updated 18 August 2026
1.Who we are and what this covers
Office Sync (“we”, “us”), of [REGISTERED ADDRESS], operates OfficeSyncPro — the website at officesyncpro.com and the application at app.officesyncpro.com (together, the “Service”). This policy explains how we handle personal data in both.
We act in two different roles, and the difference matters:
- As a controller, for the data we decide the purposes of: your account and profile, billing records, support conversations, and technical logs.
- As a processor, for the content your team puts into a workspace — projects, tasks, comments, files, and anything reached through your Outlook connection. Your organisation decides what goes in and why; we process it on their instructions, under our Terms of Service and any data processing agreement we have signed with them.
If your workspace belongs to your employer and you want something changed or deleted, they are the right first stop — but write to us anyway at pm_atlas@quantumsoftwareinc.onmicrosoft.com and we will help route it.
2.Information we collect
Account and profile information
You sign in with a Microsoft work or school account. Microsoft Entra ID returns your Microsoft user identifier, work email address, display name and profile photo, and we store those to create and identify your account. We never see, receive or store your Microsoft password.
Workspace content
Whatever your team creates in the product: workspaces, projects, tasks and their statuses, comments, notes, timelines, teams and team membership, labels, chat messages, uploaded files, guest invitations and notification preferences.
Microsoft 365 data
Only if you connect Outlook, and only what that connection needs. This is the part people most want specifics on, so it has a section of its own — see “Your Microsoft 365 data” below.
Billing information
Your plan, billing cycle, subscription status, renewal dates, invoice history and the customer and subscription identifiers our payment processor assigns you. Card numbers never reach our servers. Payment details are entered on Stripe’s own hosted checkout and held by Stripe.
Technical and usage data
IP address, browser type and version, request timestamps, the pages and API endpoints requested, and error diagnostics. Separately, each workspace keeps an audit log of security-relevant actions — who invited whom, who changed a role, who removed a project — so an administrator can answer “what happened here?”.
Communications
Emails you send us, and the messages we send you about your account, billing, invitations and notifications you have asked for.
3.Your Microsoft 365 data
OfficeSyncPro asks for Microsoft permissions in two separate steps. Signing in needs almost nothing. The mailbox and calendar permissions are requested only later, on the screen where you choose to connect Outlook, and you can use the product without ever granting them.
| Permission | Asked for | What we do with it |
|---|---|---|
openid, profile, email | At sign-in | Identify you and match you to your account. |
User.Read | At sign-in | Read your basic profile — name, work email, photo. |
offline_access | At sign-in and when connecting Outlook | Keep your session and integration working without asking you to re-authenticate constantly. |
Mail.Read | When you connect Outlook | Show your inbox beside your projects and let you link a conversation to a project or task. |
Mail.ReadWrite | When you connect Outlook | Apply the categories, flags and folder moves you make from inside OfficeSyncPro. |
Mail.Send | When you connect Outlook | Send replies you compose in OfficeSyncPro, from your own mailbox, when you press send. |
Calendars.Read | When you connect Outlook | Show your meetings alongside project timelines and tasks. |
Calendars.ReadWrite | When you connect Outlook | Create or update the meetings you schedule from a task or project. |
What we do not do
- We do not copy your mailbox. When you link an email to a project or task, we store the Microsoft conversation identifier and a snapshot of the subject line — enough for the link to survive and to be labelled. Message bodies, recipients and attachments are fetched from Microsoft Graph at the moment you open them and are not retained in our database.
- We do not get tenant-wide access. Permissions are delegated to you personally. OfficeSyncPro can reach exactly what your own Microsoft account can reach and nothing else — never a colleague’s mailbox unless Microsoft has already shared it with you.
- We do not sell it, advertise against it, or train models on it. Microsoft 365 data is used to operate the features you turned on, and for nothing else.
Tokens and staying in sync
The refresh token that keeps your Outlook connection alive is encrypted at rest with a dedicated key. We also register change notifications with Microsoft Graph so a linked conversation stays current; a notification tells us that something changed, which prompts us to fetch the update on your behalf.
You can end all of this at any time by disconnecting the integration in OfficeSyncPro, or by revoking access from your Microsoft account’s app permissions. We delete the stored tokens when you do.
4.How we use information
| Purpose | Lawful basis (UK/EU GDPR) |
|---|---|
| Providing and operating the Service you signed up for | Performance of a contract |
| Authenticating you and keeping accounts secure | Contract; legitimate interests |
| Billing, collecting payment and issuing invoices | Contract; legal obligation |
| Responding to support requests | Contract; legitimate interests |
| Diagnosing faults and improving the product | Legitimate interests |
| Sending service, security and billing notices | Contract; legal obligation |
| Preventing fraud and abuse, and enforcing our Terms | Legitimate interests |
| Meeting tax, accounting and other legal requirements | Legal obligation |
Marketing email, if we ever send any, is separate and opt-in, and every message carries an unsubscribe link. Service and billing notices are not marketing and cannot be unsubscribed from while your account is open.
6.International data transfers
The Service is hosted in [HOSTING REGION]. Our sub-processors may process data in other countries. Where personal data from the European Economic Area, the United Kingdom or Switzerland is transferred somewhere without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the technical measures described under “How we protect information”. Ask us at pm_atlas@quantumsoftwareinc.onmicrosoft.com if you would like a copy of the relevant safeguards.
7.How we protect information
- No password for us to lose. Authentication is delegated entirely to Microsoft, so your organisation’s own multi-factor and conditional-access rules apply, and there is no OfficeSyncPro password database to breach.
- Encryption. Traffic is protected with TLS. Microsoft refresh tokens are encrypted at rest with a dedicated key held separately from the database credentials.
- Workspace isolation. Every record carries the workspace it belongs to, and that boundary is enforced in the database itself with row-level security — not only in application code.
- Role-based access. Owner, admin, manager, member and guest roles limit what each person can see and do, and guests are scoped to the projects they were invited to.
- Audit logging. Security-relevant actions are recorded so an administrator can reconstruct what happened.
- Least privilege for staff. Access to production data is limited to the people who need it to operate or support the Service, and it is logged.
No system is perfectly secure. If you believe you have found a vulnerability, please write to pm_atlas@quantumsoftwareinc.onmicrosoft.com before disclosing it publicly, and we will work with you on a fix.
8.How long we keep information
- Workspace content is kept while the workspace is active. Deleting a project, task or file removes it from the workspace immediately; residual copies age out of encrypted backups on our normal rotation.
- Activity history follows your plan. The Free plan retains 90 days; paid plans retain longer, as stated on the plan.
- Microsoft tokens are deleted the moment you disconnect the integration or close your account.
- Account data is deleted or anonymised within 30 days of you closing your account or asking us to.
- Billing records are kept for as long as tax and accounting law requires, typically seven years, even after an account closes.
- Technical logs are kept on a short rolling window for diagnostics and security.
Cancelling a paid plan does not delete anything. The workspace moves to the Free plan’s limits and your content stays — see the Terms of Service for what happens when content exceeds those limits.
9.Your rights and choices
Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to how we use it, receive it in a portable format, withdraw a consent you gave, and complain to your data protection authority.
If you are a California resident, you may request to know, delete or correct the personal information we hold, and you may not be discriminated against for asking. We do not sell or share personal information as those terms are defined by the CCPA, and we do not use sensitive personal information to infer characteristics about you.
Controls already in the product
- Edit your profile and notification preferences in Settings.
- Disconnect Outlook at any time from the integrations screen.
- Workspace owners can remove members, guests and the workspace itself.
Making a request
Email pm_atlas@quantumsoftwareinc.onmicrosoft.com from the address on your account. We respond within 30 days. If the data sits inside a workspace controlled by your employer or client, we will forward the request to them and support them in answering it.
10.Children’s privacy
OfficeSyncPro is a workplace tool. It is not directed at children, we do not knowingly collect data from anyone under 16, and creating a workspace requires a Microsoft work or school account. If we learn that we hold data from a child, we delete it.
11.Changes to this policy
We will post any change on this page and update the date at the top. If a change materially affects how we handle your personal data, we will tell you by email or an in-app notice at least 14 days before it takes effect, so you have time to object or close your account.
12.Contact us
Questions, requests or complaints about privacy go to pm_atlas@quantumsoftwareinc.onmicrosoft.com, or by post to Office Sync, [REGISTERED ADDRESS].
Data protection officer: [DPO NAME AND CONTACT, IF APPOINTED]. Representative under Article 27 of the UK/EU GDPR: [EU/UK REPRESENTATIVE, IF APPOINTED].
This document is a good-faith description, in plain language, of how OfficeSyncPro works today. It is not legal advice. Have it reviewed by qualified counsel — and fill in every bracketed placeholder — before relying on it.
← Back to OfficeSyncPro