Legal

Privacy Policy

What data Consuy handles, why, where it lives, and what you can ask us to do with it.

Effective 11 August 2026

Who we are and what this covers

Consuy, Inc. ("Consuy", "we", "us") provides an AI service management platform. This policy applies to all of our services, applications and platforms — the Consuy platform and its modules, our self-service portal and assistant, our integrations with systems such as Microsoft Entra ID and Microsoft Teams, and the consuy.com website. It explains what personal data we handle, why, and what rights people have over it.

We handle personal data in two distinct roles, and the difference matters. When an organisation uses Consuy to support its own people, that organisation is the controller and we are its processor: we act on their instructions and their own privacy notice governs how their people’s data is used. When we run our website, market our product, and administer accounts, we are the controller.

What we process

CategoryWhat it includes and where it comes from
Directory dataName, work email address, job title, department, office location and reporting line. Provided by the customer, or read from their Microsoft Entra ID directory if they connect it. The connection is read-only: Consuy never writes to, changes or deletes anything in a customer’s directory.
Service desk contentTickets, requests, comments, attachments, approvals and their history — whatever people submit while using the service. This can contain personal data, and occasionally sensitive detail, because people describe their problems in their own words.
Knowledge contentArticles and documents a customer publishes into their knowledge base, including any personal data those documents happen to contain.
ConversationsMessages exchanged with the Consuy assistant, in the portal or in Microsoft Teams, and the answers it returns.
Account and usage dataSign-in events, actions taken in the product, audit records, and technical logs such as IP address, browser and timestamps. Used to operate, secure and support the service.
Website dataPages visited and information submitted through forms on consuy.com.

We do not sell personal data, and we do not use customer content to train foundation models.

How our AI features use data

Consuy uses large language models to answer questions, summarise, classify and draft. When someone asks the assistant a question, the question and the relevant retrieved content from that customer’s own tickets and knowledge base are sent to the model to generate an answer.

  • Models are hosted within our Microsoft Azure environment. Prompts and content are not sent to a public consumer AI service.
  • Customer content is not used to train or fine-tune foundation models.
  • Retrieval is scoped to the asking organisation, and to what that individual is permitted to see. The assistant does not read across customers.
  • AI output can be wrong. It is a suggestion, not a decision, and important actions remain subject to the permissions and approvals a customer configures.

Why we process it

  • To provide the service a customer has asked for, under our contract with them.
  • To keep the service secure, detect abuse, and investigate incidents.
  • To support customers and respond to their requests.
  • To meet legal obligations.
  • Where we rely on legitimate interests, such as product improvement and website analytics, we balance those against the rights of the people concerned.

Who else is involved

We use a small number of sub-processors to run the service. They act on our instructions, under contract, and only for the purposes below.

Sub-processorPurpose
Microsoft AzureCloud hosting, databases, file storage and platform security
Azure OpenAI ServiceLarge language model processing for the AI features described above
Azure Communication ServicesSending notification and service email
Microsoft Graph and Bot FrameworkOnly where a customer connects Microsoft Entra ID or Microsoft Teams, to read directory data and exchange chat messages

We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever party to a merger or acquisition, personal data may transfer as part of that transaction, and this policy would continue to apply until updated.

Where data is stored

Customer data is stored in Microsoft Azure. Each customer’s service desk data is held in its own database, separate from other customers, rather than pooled into shared tables.

Our production environment is hosted in Canada. Where personal data is transferred out of its country of origin, we rely on appropriate safeguards, including the European Commission’s standard contractual clauses where they apply. Customers with specific data residency obligations should raise them before onboarding, as region is decided at that point.

How long we keep it

While an organisation is a customer, we retain their content for as long as they keep it in the product. Deactivating a person does not delete their history: their tickets, comments and approvals remain, because service records must stay auditable. Customers can delete content themselves.

After a customer’s contract ends, we delete or return their data in line with that contract. Backups and audit logs are kept for a limited period and then expire on their own schedule.

How we protect it

  • Encryption in transit and at rest.
  • Per-customer database isolation, so one organisation’s data is not co-mingled with another’s.
  • Role-based access control, with permissions enforced on the server rather than in the browser.
  • Secrets held in a managed key vault, not in code or configuration files.
  • Single sign-on and multi-factor authentication supported through SAML and Microsoft Entra ID.
  • Audit logging of security-relevant actions.

No system is perfectly secure. If a breach affects personal data, we will notify affected customers without undue delay and support their own notification obligations.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive a portable copy, and to withdraw consent where we rely on it. You also have the right to complain to your data protection authority.

If your employer uses Consuy, please contact them first: they control that data, and we will support them in responding. For data we control, contact us using the details below and we will respond within the period the law allows.

Children's data

Consuy is a workplace product sold to organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

Changes to this policy

We will update this page when our practices change and revise the effective date above. Where a change materially affects how we handle personal data, we will tell customers directly rather than relying on this page alone.

Contact us

Questions about this policy, or requests about your personal data, can be sent to privacy@consuy.com.