GDPR
Privacy policy
Last updated: 8 October 2026 · This English translation is provided for convenience; the French version prevails.
1. Data controller
Dimby ANDRIANAMBININTSOA, sole proprietor (EI), trading as Coraxio, 91 avenue René Panhard, 94320 Thiais, France, is the controller of the processing described below. For any question or to exercise your rights: rgpd@coraxio.com.
2. In short
- The analysis of your tenant runs in your browser. Coraxio receives neither your credentials, nor your Microsoft access token, nor your tenant's data.
- Coraxio only receives personal data if you use “Receive this report” or fill in the “Start my migration” form.
- The website uses no cookies for audience measurement or advertising, and loads no resources from third-party services other than Microsoft for sign-in and the host's cookieless audience measurement tool described in section 7.
3. Analysis of the Microsoft 365 tenant
Data read. After your consent, the tool queries Microsoft Graph read-only: number of users, guests and synchronised accounts, subscribed licences, number and size of mailboxes, OneDrive accounts, SharePoint sites, groups and Teams, channel types, number of external members, and the number of enterprise applications using single sign-on. To classify mailboxes, account addresses may be read; they stay in your browser's memory for the duration of the calculation and are neither stored nor transmitted.
Data never read. The content of emails, files, Teams conversations and calendars. Your password is entered only at Microsoft.
Where and for how long. The calculation takes place in your browser. The access token issued by Microsoft is kept in the browser's session storage and deleted when the tab is closed. No result is stored by Coraxio.
Revocation. An administrator of your organisation can revoke the permission at any time from the Microsoft Entra admin centre, under Enterprise applications, application “Coraxio”.
4. Contact requests (“Start my migration”, “Receive this report”)
| Data | For “Receive this report”: your email, your optional agreement to be contacted and the report summary. For “Start my migration”: full name, company, work email, phone (optional), desired timeline, target tenant (optional), project context, and the report summary you choose to attach (score, totals per scope, estimate). The summary contains no personal data about your users. |
|---|---|
| Purposes | Answering your request, preparing a quote, organising the consultation and following up on your project commercially. |
| Legal bases | Pre-contractual measures taken at your request (Article 6(1)(b) GDPR); Coraxio's legitimate interest in following up a business relationship with a professional (Article 6(1)(f)). |
| Retention | 3 years from the last contact if no contract is concluded; if a contract is concluded, for its duration and then according to the statutory limitation periods. |
| Recipients | Coraxio only. Requests are sent by email through the Resend email service (Resend Inc., United States), which also sends a confirmation to the address entered, and are received in a Microsoft 365 (Outlook) mailbox; Resend and Microsoft act as processors. Requests are not stored in any database of the website. If you agreed to be contacted, a single follow-up email is sent to you three business days later; simply reply “stop” to receive no further messages. To block automated submissions, the form may use the Cloudflare Turnstile anti-bot service (Cloudflare Inc.), which processes your IP address and technical browser information without advertising cookies. No data is sold or transferred. |
| Transfers outside the EU | The Microsoft 365 mailbox is covered by Microsoft's EU Data Boundary commitments. The host Vercel and the email service Resend are based in the United States: any transfers are governed by the EU–US Data Privacy Framework and standard contractual clauses. |
5. Booking an appointment
The “Book my free consultation” button opens the Calendly service (Calendly LLC, United States). The information you enter there is processed by Calendly under its own privacy policy, then passed on to Coraxio to organise the appointment. Transfers to the United States are governed by the EU–US Data Privacy Framework and standard contractual clauses.
6. Technical data
Like any website, the host records technical logs (IP address, date, requested page) for security and proper operation of the service, kept for a limited period set by Vercel, at most a few days depending on the plan.
7. Cookies and local storage
The website sets no audience measurement, advertising or social network cookies. It only uses the browser's session storage, strictly necessary for the Microsoft sign-in you request; this storage is exempt from consent and is cleared when the tab is closed. If you choose the English version, this language preference is stored in your browser's local storage, on your device only.
Audience measurement
Audience measurement relies on Vercel Web Analytics (Vercel Inc., the website host). This tool sets no cookies and stores nothing on your device: each visit is identified by an anonymous fingerprint (hash of the request) valid for 24 hours, which cannot recognise you from one day to the next or across websites. Only aggregated statistics are produced (page views, referrer, country, device type), together with anonymous usage events of the tool (analysis started, report displayed, appointment requested, PDF report downloaded, language chosen), without any data from your tenant or your email address. In line with the CNIL's guidance on exempt audience measurement tools, this measurement does not require your consent.
8. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to set instructions regarding your data after your death. Write to rgpd@coraxio.com; you will receive an answer within one month.
If you believe your rights are not respected, you may lodge a complaint with the CNIL, the French data protection authority (cnil.fr).
9. Security
The website is served exclusively over HTTPS with a restrictive content security policy. Access to the tenant relies on Microsoft authentication and read-only permissions controlled by your organisation.
10. Changes
This policy may change; the date of the last update is shown at the top of the page.