Privacy
Privacy policy
DataVault365 handles personal data with care. This policy explains in plain language which data we process through this website and when delivering our backup service, for what purpose, on which legal basis and for how long.
Last updated: 5 September 2026
1. Controller
Who is responsible for your data?
DataVault365 is a service of Altena Software Development & IT Management, referred to below as “we”. We are the controller for the data of visitors to this website and of our customers and business contacts. For the content of the backups we create on behalf of customers, we act as processor. You can read more about that in section 4.
- Trade name
- DataVault365
- Company
- Altena Software Development & IT Management
- Chamber of Commerce
- 98829106 (Netherlands)
- VAT number
- NL005358968B89
- info@datavault365.com
- Website
- https://datavault365.com
2. Visiting the website
What happens when you visit this website?
Server logs
On every visit our web server records technical data: your IP address, date and time, the page requested, the browser type and the referring page. We use this data solely to keep the website secure and working and to detect faults and abuse. The legal basis is our legitimate interest in a secure website. Logs are rotated daily and deleted automatically after 30 days at the latest.
No analytics, no trackers
This website uses no analytics cookies, no advertising cookies and no third-party tracking pixels. We do not build a profile of you and do not share your visit data with advertising networks. Fonts, scripts and images are served from our own server; no files are loaded from Google or other third parties.
Cookies
We only set functional cookies. No consent is required for these.
- pll_language remembers your language choice (Dutch or English). Retention: 1 year.
- altena_contact_recall is only set when the contact form reports an input error, so that the text you entered is preserved. Retention: 10 minutes.
- WordPress cookies (wordpress_*, wp-settings-*) are only set for administrators who log in to manage the website. Visitors do not receive these cookies.
You can delete or block cookies at any time in your browser settings.
Customer portal
The “Customer login” button links to the customer portal at app.datavault365.com. Account data is only processed once you log in there (see section 3). Visiting this website does not set any cookies from the portal.
3. Contact and customers
Data of contacts and customers
If you contact us
If you email us, call us or use the contact form on this website, we process your name, email address, where provided your organisation, telephone number and number of Microsoft 365 users, and the content of your message. We use this data to answer your question and, if you wish, to prepare a proposal. The legal basis is our legitimate interest in answering your question, or taking steps prior to entering into a contract.
For the contact form we also record your IP address, browser type and the time of submission, solely to prevent abuse and spam. Messages from the form are delivered to us by email and kept temporarily in the secured administration area of this website, where we delete them automatically after 12 months. For a quotation we keep the data for no longer than 12 months after the last contact, unless you become a customer.
If you are a customer
To deliver DataVault365 we process:
- Contact details of your organisation and its contact persons: name, role, business email address and telephone number.
- Contract, invoicing and payment data.
- Customer portal account data: name, email address, role and login activity. You sign in with your Microsoft account, with multi-factor authentication through Microsoft.
- Data needed for support, such as your questions and the management and restore actions carried out.
We use this data to perform the contract, to invoice, to provide support and to secure the service. The legal basis is the performance of the contract and, for our financial records, our statutory retention obligation. We keep customer data for the duration of the contract and up to 2 years afterwards. Financial records are kept for 7 years under Dutch tax law.
We do not send newsletters or marketing emails without your additional consent.
4. Backup data
The backups of your Microsoft 365 environment
As a customer you give DataVault365 access to your Microsoft 365 environment through Microsoft’s official interfaces, with the permissions you grant yourself. With that access we create backups of Exchange Online, OneDrive, SharePoint and Power Automate. Those backups contain personal data of your employees and contacts, such as email, files, sites and automations.
For this data you are the controller and we are the processor. This means:
- We process the backup data solely on your instructions and in accordance with the data processing agreement.
- We do not look into the content of your backups, do not use them for our own purposes and do not share them with third parties.
- Backup data is stored on servers in Germany and is encrypted both in transit and at rest. You manage the key yourself in your own Microsoft Azure environment; without that key the data cannot be decrypted.
- Access is limited to authorised staff, only for management and support, and is logged.
- You set the retention period within your plan, up to a maximum of seven years. When the service ends, backups are deleted in accordance with the data processing agreement.
Are you an employee or contact of a customer and do you have questions about your data in a backup? Please contact the organisation that has the backup made. We help our customers handle such requests.
The full terms are set out in the data processing agreement of DataVault365.
5. Third parties
Who do we share data with?
- Hosting. This website, the customer portal and the backup storage run on servers of Strato AG in Germany. Strato acts as sub-processor under a data processing agreement.
- Microsoft. Microsoft is the provider of your Microsoft 365 environment and therefore the source of the backups. The connection runs through Microsoft’s official interfaces, with the consent you grant as a customer.
- Public authorities. Only where the law requires us to.
We do not sell data and do not share it for third-party marketing purposes. We do not transfer backup data or data from this website to countries outside the European Economic Area.
6. Security
How do we protect your data?
- All connections to this website and the customer portal are encrypted (HTTPS).
- Backup data is transferred encrypted, stored encrypted with a customer-specific key, in separate blocks rather than a single file, and kept separate from your primary Microsoft 365 environment.
- Access to systems and data is limited to authorised roles. Administrators sign in with their Microsoft account with multi-factor authentication; management and restore actions are logged.
- Systems are kept up to date with security updates.
7. Your rights
What are your rights?
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and the right to object. Where you have given consent, you can withdraw it at any time.
Send your request to info@datavault365.com. We respond as soon as possible and within one month at the latest. To prevent misuse we may ask you to verify your identity.
If we cannot resolve the matter together, you have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the supervisory authority in your own country.
8. Changes
Changes to this policy
We may update this privacy policy, for example when we add features or when legislation changes. The current version is always available on this page; the date at the top shows the latest change. We inform our customers of significant changes.
Other documents
Questions about privacy? Email info@datavault365.com.
