mpower-365-logo
  • Products
    • Document Management Solutions​
      • Project Document Management System
      • Quality Document Management
      • Transmittal Management
      • Contract Management
    • Employee Experience
      • Employee Portal
  • Success Stories
  • About Us
  • Insights
    • Blogs
    • Thought Leadership
  • Contact Us
  • Products
    • Document Management Solutions​
      • Project Document Management System
      • Quality Document Management
      • Transmittal Management
      • Contract Management
    • Employee Experience
      • Employee Portal
  • Success Stories
  • About Us
  • Insights
    • Blogs
    • Thought Leadership
  • Contact Us

MPower365 DocumentHub — Privacy Policy

Last updated: 28-Aug-2026

This Privacy Policy applies to MPower365 DocumentHub, a document management solution delivered as a single SharePoint Framework (SPFx) web part for Microsoft 365 (SharePoint). It does not cover unrelated sections of our corporate website.

1. Scope of this policy

This Privacy Policy explains how MPower365 DocumentHub collects, uses, discloses, and protects personal information when deployed in a customer’s Microsoft 365 tenant and accessed by the tenant’s own users. DocumentHub is single-tenant and has no external stakeholder portal, no separate sign-in, and no user population outside the customer’s own Microsoft 365 directory.

2. Where DocumentHub is hosted and deployed

  • DocumentHub is installed as an SPFx solution (.sppkg) into the customer’s own SharePoint tenant and runs entirely inside the browser session of the signed-in user — there is no separate application, server, or hosting environment operated by us.
  • All document content, metadata, and lists it creates (libraries, revisions, workflows, tasks, notifications, activity logs, etc.) are stored in SharePoint lists and libraries inside the customer’s own tenant, provisioned by DocumentHub’s in-app setup wizard.
  • DocumentHub has no backend of its own. Every read and write goes through PnP JS directly against the host site, authenticated as the signed-in user’s own Microsoft 365 identity. We do not operate servers, databases, or storage that hold customer content.

3. Roles (Controller vs. Processor)

  • For all data processed within the customer’s tenant, the customer is the Data Controller; MPower365 acts as a Data Processor only to the extent our code executes client-side inside the customer’s own session — we do not separately receive, store, or have standing access to that data.
  • For the narrow licensing data described in Section 6, we act as Controller of that limited data set.

4. Personal information we process

Identity & access data — Name, email, and Microsoft Entra ID identity of the signed-in user, as read from the current SharePoint session (context.pageContext) to attribute actions (created-by/modified-by, activity logs, task assignments, notifications). We do not maintain a separate user directory.

Document and workflow data — Documents, revisions, categories, statuses, numbering, workflow stages, tasks, task comments, and the audit trail (activity_logs) generated as users work in the libraries they create.

Notifications — In-app notifications are always written to the notifications list in the customer’s own tenant. If the customer’s admin opts in to email notifications (off by default, configurations.email_notifications_enabled), a mirror of the notification is sent via delegated Microsoft Graph sendMail, as the signed-in user, to recipients within the customer’s own tenant. We do not operate a mail service; the message never leaves Microsoft 365.

Technical & usage data — None collected by us. DocumentHub has no telemetry, analytics, or error-reporting service. Any browser console errors stay on the user’s device.

Licensing data — The customer’s Microsoft Entra tenant ID is sent to the MPower365 licensing API to resolve entitlements (Section 6). No user names, emails, or document content are included in this call.

Sensitive data — DocumentHub is not designed to require processing of sensitive personal data (e.g., health, biometric). If customers upload such data into documents, they remain responsible as Controllers; we never see or process that content ourselves.

5. How and why we use personal information

  • Provide the Service — Identity read from the SharePoint session to enable document authorship, revisions, approvals, task assignment, and audit trails, all written into the customer’s own lists.
  • Notifications — In-app notifications and, if enabled by the admin, a best-effort email mirror sent via the signed-in user’s own Graph token.
  • Licensing — The tenant ID is used solely to look up and return the tenant’s entitlement status, signed by our licensing platform (Section 6).

We do not use personal information for advertising, profiling, or any purpose unrelated to operating the features described above.

6. Data locations, transfers, and residency

  • Document and workflow data: Stored and processed entirely in Microsoft-managed data centers per the customer’s own Microsoft 365 configuration (including Multi-Geo/EU Data Boundary where applicable). We have no independent copy and no independent location for this data.
  • Licensing data: The tenant ID is sent to our licensing API (license-validation/entitlements) and the signed entitlement response is cached, signed, inside the customer’s own configurations list. We disclose the hosting region of the licensing API to customers on request; where a cross-border transfer occurs, we apply appropriate safeguards (e.g., SCCs) as required by GDPR.
  • Email notifications: Sent via me/sendMail as the signed-in user — a Microsoft 365 service call under that user’s own token, not a service we operate.

7. Data retention

  • Document/workflow/notification data: Retention is entirely controlled by the customer via SharePoint retention labels, Records Management, or Microsoft Purview policies. We do not override, access, or independently retain this data.
  • Licensing data: The cached, signed entitlement token is retained in the customer’s own tenant until superseded by a fresh entitlement check or removed by the customer. Our licensing platform retains only the tenant ID and issued entitlements for as long as needed to serve the licence, per our internal retention schedule.

8. Security

DocumentHub runs entirely under the signed-in user’s own SharePoint permissions — there is no elevated or app-only identity, and no action can bypass the permissions that user already holds (C3). Platform security and compliance controls rely on the customer’s own Microsoft 365 services (SharePoint, Entra ID); customers can additionally enforce Conditional Access, MFA, and DLP/Purview policies. The licensing entitlement response is ECDSA-signed and verified against a public key in the product bundle before being trusted, so a tampered cache entry fails closed rather than granting access.

9. Sub-processors and integrations

  • Microsoft 365 services (SharePoint, Entra ID, Microsoft Graph) are the foundational platform and act as sub-processor/infrastructure provider for all tenant data.
  • MPower365 licensing API processes the tenant ID only, as described in Section 6.
  • No other third party, sub-processor, analytics vendor, or external portal is involved. DocumentHub has no Teams bot, no add-in, and no server-side backend of ours (C1, C6).

10. Cookies and similar technologies

DocumentHub is a web part rendered inside SharePoint pages; it does not set its own cookies or tracking technologies. Any session storage used is the host SharePoint page’s own authentication session. We do not use cookies for behavioral advertising or analytics.

11. Your privacy rights

  • GDPR (EEA/UK): Right to access, rectify, erase, restrict, object, and data portability; right to withdraw consent; right to lodge a complaint with a supervisory authority. Requests should be sent to the customer (Controller); we support the customer in fulfilling requests as their Processor, since we hold no independent copy of their data.
  • California (CCPA/CPRA): Rights to know, access, correct, delete, opt-out of sale/share, limit use of sensitive personal information, and non-discrimination. Customers provide the method for their own users to submit requests; we assist as Processor where applicable.

12. Children’s privacy

DocumentHub is a business-to-business solution not intended for children. We do not knowingly collect personal information from children under the age specified by local law.

13. Data Processing Addendum (DPA)

For enterprise customers, a DPA governing Processor obligations, sub-processors, international transfers, and security measures is available on request and forms part of the service agreement.

14. Incident response and breach notification

We maintain procedures to detect, investigate, and remediate security incidents affecting the licensing platform. Because document and workflow data lives entirely in the customer’s own tenant, incidents affecting that data are managed by the customer’s own Microsoft 365 security tooling; where an incident on our side (e.g., the licensing API) affects a customer, we promptly notify the customer and cooperate to meet legal notification obligations.

15. Changes to this policy

We may update this policy to reflect product changes or legal requirements. The “Last updated” date will change, and material updates will be communicated to customers by email.

16. How to contact us

Privacy & DPA / support requests: support@mpower365.com

Project Documentation. Unified in Microsoft 365.

Products

  • Project Document Management System
  • Quality Document Management System
  • Transmittal Management System
  • Contract Management System
  • Employee Portal

Company

  • About Us
  • Contact Us

Resources

  • Case Studies
  • Privacy Policy

Business Enquiries

enquiries@mpower-365.com
APAC: +91 80753 82394, +91 95396 21416
EMEA: +971 5068 22303
NA: +1 562 359 4113
MPower365

Copyright © MPower365. All rights reserved.

Linkedin IconFacebook IconInstagram Icon