Privacy Policy of AZExecute

Please read this privacy policy carefully.
1. Information Collection

The service processes names, work email addresses, tenant/user identifiers, roles and user-linked activity obtained through Microsoft sign-in, authorised integrations and customer input. Customer-provided scripts, configuration and outputs may also contain personal data. Your organisation determines the lawful basis for processing on its behalf; Dyntora follows its instructions under the DPA. For Dyntora's own business-contact, support and service-security administration, the basis is our legitimate interest in operating a secure business service; contract necessity applies where the individual is the contracting party, and statutory accounting processing is based on legal obligations. Optional consent-based purposes require separate consent. Minimal identity and tenant/session information is processed at sign-in before agreement acceptance so that the correct organisation and administrator can be identified.

2. Use of Information

Customer Data is processed to deliver, secure, maintain and support the agreed service and follow the organisation's documented instructions under the DPA. We do not sell it, use it for advertising, train general-purpose AI models on it or reuse it for unrelated product development. Dyntora separately uses necessary business-contact and billing information to administer its own customer relationship and accounting obligations.

3. Data Sharing

We do not sell personal information. We use Microsoft Azure for the infrastructure supporting AZExecute and Stripe for payments. We do not engage other providers for these services. Microsoft processes hosted Customer Data under the applicable data processing terms. Stripe processes payment and billing information; depending on the activity, it acts as a processor or an independent controller, including for its own fraud-prevention and legal-compliance purposes. These providers may use their own affiliates and subprocessors under their applicable terms. Processing of Customer Data on behalf of your organisation is governed by the applicable data processing agreement.

4. Data Security

We implement security measures like encryption and access control to protect against unauthorized access or breaches. Despite our efforts, please be aware that no internet transmission is completely secure.

5. User Rights

Subject to the applicable conditions, individuals may request access, rectification, erasure, restriction or portability and may object to processing. Where processing relies on consent, consent may be withdrawn without affecting earlier lawful processing. You may complain to Datatilsynet (datatilsynet.dk) or another competent supervisory authority. We may need to verify your identity proportionately before acting on a request.

6. International Transfers

AZExecute hosting and backups use Microsoft Azure in Denmark and Sweden, both within the European Economic Area (EEA). These hosting locations do not describe every location involved in provider support or payment processing. Stripe payment processing is separate from AZExecute hosting. Any transfer of personal data outside the EEA requires an applicable legal transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, and additional safeguards where required. The applicable data processing agreement describes the arrangements for Customer Data processed on your organisation’s behalf.

7. Changes to Privacy Policy

We publish updates to this notice on this page and communicate material changes through in-app notices or direct communication as appropriate. Contractual changes requiring acceptance follow the versioned organisation-agreement process; continued use is not a substitute for that acceptance.

8. Contact Information

Dyntora ApS, CVR 46375599, VAT DK46375599, Nørregårdsvej 232, 2610 Rødovre, Denmark. For privacy enquiries contact info@azexecute.com. For information processed on your organisation's behalf, contact your organisation first; we assist it under the DPA. Our Security and Data Protection guide explains how to report a security concern.

9. Cookie Policy

Our service uses cookies exclusively to facilitate the login process and ensure a secure user authentication experience. We do not use cookies for analytics, tracking, or any advertising purposes. Contract acceptance is not cookie or marketing consent. These cookies support the authentication functionality you request.

Data Retention Policy

Our retention policy requires routine user-linked operational and security logs to be deleted or anonymised when no longer needed and no later than six months after recording. Evidence required for a documented incident, rights request or legal obligation is isolated, restricted to that purpose and reviewed for deletion when no longer necessary. Tenant deletion disables tenant access immediately and schedules permanent cleanup after the recovery period shown in the application (normally seven days). Permanent cleanup runs in the background; disabling access is not the same as immediate physical deletion. Contact us if you need assistance with an erasure instruction or confirmation of completed cleanup. Residual backup copies are deleted no later than 90 calendar days after active-data deletion and may be deleted sooner. During this period, backup copies remain protected and are not used for ordinary service operations. Backup recovery uses a full restore, not selective editing of records inside a backup. A full restore does not revoke a valid deletion instruction: affected restored data must remain outside ordinary use until that instruction can be respected. Recovery may require additional checks; no automatic selective deletion from backups is promised. Any retention required by applicable law is limited to the data and period required by that law. Processing of personal data on behalf of a customer, including agreed return and deletion procedures, is governed by the applicable data processing agreement.

© 2026 - Dyntora ApS

2.0.1.315