Privacy Policy
for the web app “TEAMSDASHBOARD.COM” · Courtesy translation · Version: August 2026
This English version of the privacy policy is provided for your convenience only and corresponds to the German version August 2026. Only the German version is legally binding: Datenschutzerklärung.
1. General information
The protection of your personal data is important to us. This privacy policy informs you about how personal data are processed in the course of using the web application “TEAMS DASHBOARD”.
Personal data are all data by which you can be personally identified.
This privacy policy applies exclusively to the service “TEAMS DASHBOARD” and not generally to a company website.
The web app is directed at business customers (B2B).
2. Controller
SSIG-IT GmbH
Zum weißen Jura 3
89143 Blaubeuren
Germany
3. Data protection officer
An external data protection officer has been appointed for SSIG-IT GmbH.
You can reach the data protection officer via:
Datenschutz & Informationssicherheit Alb e.K.
Email:
Website: https://www.di-alb.de
4. Description of the service “TEAMS DASHBOARD”
TEAMS DASHBOARD is a web-based application for evaluating, visualizing, and managing information and services related to Microsoft Teams.
The application accesses Microsoft cloud services, in particular Microsoft 365 / Microsoft Teams, to provide its functions.
It is used exclusively by employees, administrators, or other authorized users of customer companies (B2B).
In doing so, TEAMS DASHBOARD processes employee data on behalf of the respective business customer. The business customer is the controller within the meaning of Art. 4(7) GDPR. SSIG-IT GmbH acts as processor pursuant to Art. 28 GDPR on the basis of a data processing agreement.
Dual role: For the display of presence, profile, and photo data from Microsoft Graph, SSIG-IT GmbH acts as processor (Art. 28 GDPR); these data are processed exclusively transiently in the user’s browser and are not stored on servers of SSIG-IT GmbH. For its own contract performance, billing, operational security, and communication (including administrator contact details, invoicing and payment data, sales inquiries, server log files), SSIG-IT GmbH is an independent controller within the meaning of Art. 4(7) GDPR.
5. Processing of personal data
5.1 Which data are processed?
In the course of using TEAMS DASHBOARD, in particular the following data may be processed:
- User and account information (e.g., name, email address, user ID)
- Organizational data from the Microsoft Graph API (e.g., job title, department, location/office, phone numbers)
- Presence status and availability information from Microsoft Teams
- Users’ profile photos
- Technical usage data (e.g., login times, access times)
- Device and connection data (e.g., IP address, browser type, operating system)
- Log and error data to ensure technical operation
The personal data are either provided directly by the user or taken from the connected Microsoft 365 tenant of the respective customer (e.g., Entra ID / Microsoft Teams).
5.2 Purpose of the data processing
Processing takes place for the following purposes:
- Provision and operation of the TEAMS DASHBOARD web app
- Authentication and authorization of users
- Ensuring stability, security, and performance
- Error analysis and abuse prevention
- Support and administration purposes
5.3 Legal bases
Personal data are processed on the basis of:
- Art. 6(1)(b) GDPR – performance of a contract: processing is necessary for the provision and use of the service within the existing contractual relationship with the business customer
- Art. 6(1)(f) GDPR – legitimate interest: processing serves the secure, stable, and economical operation of the web app as well as error detection and abuse prevention
- Art. 28 GDPR – insofar as SSIG-IT GmbH processes personal data on behalf of the business customer, this takes place on the basis of a data processing agreement
5.4 Record of the data processing agreement (DPA)
If the person of a customer company who declares to be authorized concludes the data processing agreement (Art. 28 GDPR) electronically in the customer portal, we record this conclusion as evidence. The data processed are the object ID (oid), the name, and the email address of the accepting person, the Microsoft 365 tenant identifier, the legal name and address of the company as provided by this person, the contract version and the checksum (SHA-256) of the accepted wording, the time of acceptance, and the IP address and browser identifier (user agent) of the access.
The purpose is to evidence the data processing agreement validly concluded in text form (Art. 28(9) GDPR). The legal basis is Art. 6(1)(c) GDPR (compliance with the legal obligation under Art. 28 GDPR) in conjunction with Art. 6(1)(f) GDPR (legitimate interest in a robust, integrity-protected record of the contract). The record is stored integrity-protected and retained until the end of the sixth full calendar year after the definitive end of the contract (retention analogous to Section 257 of the German Commercial Code (HGB) / Section 147 of the German Fiscal Code (AO)); it is then automatically and technically deleted, unless a legal hold (e.g., pending litigation) prevents this.
6. Recipients of the data
Recipients of personal data are:
- Internal departments of SSIG-IT GmbH (e.g., IT operations, administration, support), insofar as this is necessary to fulfil the stated purposes
- Microsoft Corporation as processor in the course of using Microsoft Azure, Microsoft 365, and Microsoft Teams
For technical operation, payment processing, and communication we also use carefully selected service providers as processors pursuant to Art. 28 GDPR, which process personal data exclusively on our instructions:
- Vercel Inc. – hosting and delivery of the web app as well as server log files. Application compute and database: Frankfurt am Main; CDN and static delivery via the global Vercel network. Provider based in the USA (DPF/SCC).
- Supabase Inc. – database hosting (including customer, contact, and inquiry data). Server location Frankfurt am Main (region eu-central-1).
- Stripe Payments Europe, Ltd. (Ireland) – processing of payments in the self-service purchase (including name, email address, billing address); card data are processed exclusively by Stripe
- Resend, Inc. – sending of transactional emails (e.g., onboarding, confirmation, and reminder messages). Provider based in the USA; email delivery takes place via EU infrastructure, but account, log, and metadata may be processed in the USA. The transfer is based on the EU-US Data Privacy Framework (Art. 45 GDPR) or EU standard contractual clauses (Art. 46 GDPR).
- Cloudflare, Inc. – protection of the public forms against automated access (bot protection “Turnstile”). In the process, the requester’s IP address is transmitted to Cloudflare; the IP address is not stored in our database.
Data processing agreements pursuant to Art. 28 GDPR are in place with these service providers. Data are not passed on to other third parties unless there is a legal obligation to do so.
Insofar as individual service providers transfer personal data to third countries (in particular the USA), this takes place on the basis of an adequacy decision (EU-US Data Privacy Framework, Art. 45 GDPR) or appropriate safeguards pursuant to Art. 46 GDPR, in particular EU standard contractual clauses.
7. Use of Microsoft cloud services
TEAMS DASHBOARD uses cloud services of Microsoft Corporation, in particular:
- Microsoft 365
- Microsoft Teams
- Microsoft Azure
Personal data are processed on Microsoft servers in the process.
Microsoft processes data exclusively on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Microsoft Corporation is certified under the EU-US Data Privacy Framework (DPF). Personal data are transferred to the USA on the basis of the European Commission’s adequacy decision pursuant to Art. 45 GDPR.
Insofar as individual processing operations are not covered by the Data Privacy Framework, Microsoft additionally relies on appropriate safeguards pursuant to Art. 46 GDPR, in particular EU standard contractual clauses.
8. Server log files
When operating the web app, information is automatically recorded in server log files:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
Storage takes place for security and stability reasons and is based on Art. 6(1)(f) GDPR.
Retention period: according to the periods of our hosting provider, but no longer than six weeks.
9. Cookies, local storage, and web analytics
9.1 Technically necessary storage
For the operation of the web app, exclusively technically necessary storage mechanisms (e.g., session information, consent status) are used that are required for the secure operation of the application. These do not require consent (Section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG).
In addition, the application uses technically necessary local caching in the browser (IndexedDB) to cache profile photos and user data. These data are stored exclusively locally in the user’s browser, serve to improve loading times, and are automatically refreshed at the end of the session or upon re-login. These cached data are not transmitted to third parties.
9.2 Web analytics and reach measurement (only with consent)
On our public marketing and information pages we use the following services – exclusively after your active consent via the cookie notice. As long as you neither consent nor decline, these services are not loaded. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
- Umami (self-hosted on a server of SSIG-IT GmbH in the EU) – data-minimizing, aggregated reach measurement without cross-site profiling. No transfer to third parties and no third-country transfer takes place.
- HubSpot (HubSpot, Inc.) – marketing and contact management for analyzing website usage and handling inquiries. Provider based in the USA; the transfer is based on the EU-US Data Privacy Framework (Art. 45 GDPR) or EU standard contractual clauses (Art. 46 GDPR).
- Microsoft Clarity (Microsoft Corporation) – analysis of page usage (including click and scroll behavior) to improve the website. Provider based in the USA; the transfer is based on the EU-US Data Privacy Framework (Art. 45 GDPR) or EU standard contractual clauses (Art. 46 GDPR).
You can withdraw your consent at any time with effect for the future: via the link “Privacy settings” in the footer you reopen the selection and choose “Decline”. The withdrawal removes the loaded analytics scripts, stops further calls (as far as possible via the withdrawal interfaces of HubSpot and Microsoft Clarity), and deletes the accessible cookies of these services; for the complete removal of scripts already running in memory, reload the page afterwards. The lawfulness of the processing carried out until withdrawal remains unaffected.
10. SSL/TLS encryption
TEAMS DASHBOARD is used exclusively via an SSL or TLS encrypted connection.
This protects transmitted data against access by third parties.
11. Contact
If you contact us by email or telephone, your details are processed for the purpose of handling your inquiry.
Processing is based on Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR.
The data are deleted as soon as the purpose no longer applies and no statutory retention obligations exist.
12. Retention period
Personal data are generally stored only as long as necessary for the respective processing purposes.
User accounts and associated data are deleted or anonymized as soon as use of the service ends, a user account is deactivated, or the purpose of processing no longer applies, unless statutory retention obligations prevent this.
Specific, automatically enforced deletion periods apply to individual data sets: inquiries via the contact form are deleted or anonymized after 180 days at the latest, email logs after 90 days, payment processing event data after 90 days, and the internal administration log after two years. The record of the conclusion of the data processing agreement (section 5.4) is retained until the end of the sixth full calendar year after the definitive end of the contract and is then automatically and technically deleted, unless a legal hold prevents this. The technical and organizational measures implemented are described in our TOM (Art. 32 GDPR).
13. Your rights as a data subject
You have the right at any time to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
14. Withdrawal of consent
Consent given can be withdrawn informally by email at any time.
The lawfulness of the processing carried out until withdrawal remains unaffected.
15. Right to lodge a complaint
You have the right to lodge a complaint about the processing of your personal data with the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg).