Data Processing Agreement (DPA)

Last updated: 22-07-2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use, or other written or electronic agreement, between SharePoint Designs ("Data Processor") and You ("Data Controller") for the purchase of services from SharePoint Designs, including products distributed via Microsoft AppSource.

SharePoint Designs understands the importance of protecting the privacy and security of your personal data. This DPA establishes the terms and conditions under which SharePoint Designs processes your data, in compliance with prevailing international data protection laws, including the GDPR and UK GDPR.

1. Definitions

"Data Controller" means the natural or legal person who determines the purposes and means of the processing of Personal Data.

"Data Processor" means SharePoint Designs, which processes Personal Data on behalf of the Controller.

"Data Protection Officer (DPO)" is the designated representative responsible for overseeing data protection strategy and implementation, and serving as the primary point of contact for privacy inquiries.

2. Data Processing Details

SharePoint Designs processes Personal Data strictly to the extent necessary to provide the Services specifically, business email address, full name, and Microsoft 365 / Azure Active Directory tenant identifier, collected solely for license validation, activation, seat allocation, and subscription administration in connection with our Microsoft AppSource products. We do not process any other Content, files, or data you or your users create, upload, or manage within our products. For full details, see our Privacy Policy.

3. Data Subject Rights

SharePoint Designs shall, to the extent legally permitted, promptly notify the Data Controller if it receives a request from a Data Subject to exercise their rights (including access, rectification, restriction of processing, erasure, portability, objection, or withdrawal of consent).

To better understand these rights, please refer to our Privacy Policy.

4. Authorized Sub-Processors

To provide our Services, SharePoint Designs engages the following third-party entity ("Sub-processor") to process Personal Data. We impose data protection terms on this Sub-processor that are no less protective than those contained in this DPA:

  • Sub-Processor Name: Microsoft Corporation (Microsoft Azure)
  • Location / Hosting: Central US (primary) / Central India (geo-replica)
  • Purpose of Processing: Hosting and storage of license management data (Azure SQL Database, Azure Functions, Microsoft Entra ID for authentication)

5. Security Measures (Technical and Organizational)

To protect Personal Data against unauthorized access, loss, or destruction, SharePoint Designs maintains a security posture including:

  • Encryption: Data is encrypted at rest and in transit (TLS) within the Azure environment.
  • Access Control: Role-Based Access Control (RBAC), Privileged Access Management (PAM), and multi-factor authentication (MFA) via Microsoft Entra ID, applied on a least-privilege basis.
  • Standards Alignment: Information security practices aligned with ISO/IEC 27001 and SOC 2 control frameworks.
  • Data Breach Notification: We commit to notifying the Data Controller without undue delay upon becoming aware of a Personal Data Breach affecting Customer's Personal Data.

6. Standard Contractual Clauses (SCCs)

Due to our use of a Sub-processor in the United States, with data hosted outside the EEA/UK, SharePoint Designs engages in cross-border data transfers. For Users operating within the European Union (EU), EEA, or United Kingdom, the EU Standard Contractual Clauses (SCCs), and where applicable the UK International Data Transfer Addendum, are hereby incorporated by reference into this DPA, ensuring these transfers remain legally compliant.

7. Data Deletion and Return

Within thirty (30) days of the end of the Agreement or cessation of the Processor's Services, whichever occurs earlier, SharePoint Designs will, at the Controller's choice, return or securely delete all Personal Data, unless applicable law requires continued retention.

8. Audit Rights

SharePoint Designs grants the Data Controller the right to audit our compliance. Upon reasonable written request (at least fifteen (15) days' notice), we will provide information reasonably necessary to demonstrate compliance with this DPA and applicable data protection law.

9. Data Protection Officer (DPO) Contact

SharePoint Designs has appointed a Data Protection Officer to oversee our compliance with global data protection protocols and to serve as your primary point of contact for privacy inquiries.

DPO Name: Venkatesh Maran

Email Address: privacy@sharepointdesigns.com