๐Ÿข 1. Data Controller

Henkei Corporation (Private) Limited ("we", "us", "our") is the data controller for personal data processed through the M365 Graph MCP service at mcps.work.

๐Ÿ”’
Data Protection Officer For all data-related enquiries: info@henkeicorp.com

๐Ÿ“‹ 2. Personal Data We Process

M365 Graph MCP is a pass-through connector. We do not store your Microsoft 365 data on our infrastructure. The following data is processed transiently to fulfil your requests:

Microsoft 365 Data (on-behalf-of-user)

  • Email messages โ€” subject, sender, recipients, body โ€” read/written on your behalf when you explicitly instruct the AI assistant.
  • Calendar events โ€” title, start/end time, attendee list.
  • Contacts โ€” display name, email addresses, phone numbers.
  • Mailbox settings โ€” timezone, auto-reply configuration.

Authentication Data (in memory only)

  • OAuth 2.0 access tokens (validity: up to 1 hour) โ€” held in process memory only.
  • OAuth 2.0 refresh tokens (validity: up to 7 days) โ€” held in process memory only; deleted on logout or token revocation.
  • Microsoft Entra ID user identifier (sub claim) โ€” used for session isolation.
โœ“ No database storage โœ“ No advertising โœ“ No profiling

โš–๏ธ 3. Purpose & Legal Basis

๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka PDPA (No. 9 of 2022)
  • Consent (Section 7(a)) โ€” you authenticate via Microsoft OAuth and explicitly authorise each action.
  • Contractual necessity (Section 7(b)) โ€” processing is required to deliver the service you requested.
  • Legitimate interest (Section 7(f)) โ€” server-side logging for security and troubleshooting.
๐Ÿ‡ช๐Ÿ‡บ EU GDPR (Regulation 2016/679)
  • Consent (Article 6(1)(a)) โ€” OAuth authorisation.
  • Contractual necessity (Article 6(1)(b)) โ€” service delivery.
  • Legitimate interest (Article 6(1)(f)) โ€” security logging, fraud prevention.

๐Ÿ”— 4. Sub-processors & Third Parties

We rely on the following sub-processors to deliver this service:

  • Microsoft Corporation โ€” Microsoft Graph API (data source), Microsoft Entra ID (authentication), Azure Container Apps (hosting). Microsoft's privacy policy applies to data held in your Microsoft 365 tenant.
  • Anthropic, PBC โ€” Claude AI models process your natural-language instructions and the M365 data you share with them. Anthropic's enterprise data handling commitments apply.
  • Google LLC โ€” Google Analytics (GA4) collects anonymised page-view statistics (pages visited, approximate location, device type). No M365 data or personal email/calendar content is sent to Google.
No data sales We do not sell, rent, or share your personal data with any other third parties.

๐ŸŒ 5. International Data Transfers

Requests are forwarded to Microsoft Graph API servers. Microsoft maintains data residency commitments for EU/EEA customers under the EU Data Boundary programme.

When you use Claude AI features, your data is processed by Anthropic's infrastructure. For EU/EEA users this constitutes a transfer to the United States under Standard Contractual Clauses (SCCs).

Google Analytics data is processed by Google LLC in the United States under SCCs. Analytics data is anonymised and does not include M365 content.

For Sri Lankan users, cross-border transfers comply with Section 24 of the PDPA.

๐Ÿ•’ 6. Data Retention

  • OAuth access tokens: up to 1 hour (Microsoft-imposed TTL). Not persisted to disk.
  • OAuth refresh tokens: up to 7 days. In process memory only; deleted on restart, logout, or revocation.
  • M365 content (mail, calendar, contacts): never stored. Data is fetched on-demand, returned to the AI model, and immediately discarded.
  • Server access logs: retained for up to 30 days for security monitoring. Logs contain IP addresses, timestamps, and HTTP status codes โ€” no message content.
  • Google Analytics: anonymised usage data retained per Google's default retention policy (14 months).
Revoke access at any time Visit Microsoft My Account โ†’ Privacy โ†’ App permissions to revoke all tokens immediately.

๐Ÿ›ก๏ธ 7. Security Measures

  • All traffic encrypted with TLS 1.2+ (HTTPS enforced, HSTS with preload enabled).
  • OAuth 2.0 with PKCE; tokens never exposed in URLs or logs.
  • Rate limiting and request-ID tracing on all endpoints.
  • Container-level isolation; no persistent disk storage.
  • Azure Container Apps hardened environment.
  • Input validation and HTML-escaping on all user-supplied content.

Breach Notification

๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka PDPA
  • Notify the Data Protection Authority within 72 hours (Section 38).
  • Notify affected individuals where there is significant risk of harm.
๐Ÿ‡ช๐Ÿ‡บ EU GDPR
  • Notify the supervisory authority within 72 hours (Article 33).
  • Notify affected individuals without undue delay where high risk exists (Article 34).

โœ… 8. Your Data Subject Rights

๐Ÿ‡ฑ๐Ÿ‡ฐ Rights under Sri Lanka PDPA
  • Right of access (Section 12)
  • Right to rectification (Section 13)
  • Right to erasure (Section 14)
  • Right to object (Section 16)
  • Right not to be subject to automated decisions (Section 17)
  • Right to lodge a complaint with the Personal Data Protection Authority of Sri Lanka

Response time: 21 working days

๐Ÿ‡ช๐Ÿ‡บ Rights under EU GDPR
  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure / "right to be forgotten" (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to lodge a complaint with your national supervisory authority

Response time: 1 calendar month

To exercise any right, email info@henkeicorp.com with your request and sufficient information to verify your identity.

๐Ÿ‘ถ 9. Children's Data

M365 Graph MCP is designed for professional and organisational use. We do not knowingly collect personal data from children under 18 years of age. If you believe we have inadvertently collected such data, please contact info@henkeicorp.com immediately.

๐Ÿช 10. Cookies & Analytics

This service uses Google Analytics 4 (GA4) to collect anonymised usage statistics (pages visited, approximate country, device type). GA4 sets first-party cookies (_ga, _ga_*) to distinguish visitors. No M365 data, email content, or personally identifiable information is included in analytics events.

Beyond analytics cookies, this service does not use tracking pixels, advertising cookies, or persistent session identifiers. The OAuth state parameter is a short-lived, cryptographically random nonce used solely to prevent CSRF during the login flow โ€” it is not a tracking cookie.

You may opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

๐Ÿ“ 11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the service. The effective date is shown in the page header. Continued use of the service after a policy update constitutes your acceptance of the revised terms.

For significant changes that affect your rights we will make reasonable efforts to notify connected users.

๐Ÿ“ฌ 12. Contact Us

For questions about this Privacy Policy, to exercise your data subject rights, or to report a concern:

โœ‰๏ธ
Henkei Corporation (Private) Limited โ€” Privacy Team Email: info@henkeicorp.com Support form: mcps.work/support

Sri Lankan users may also contact the Personal Data Protection Authority of Sri Lanka. EU/EEA users may contact their national data protection supervisory authority (e.g. ICO in the UK, CNIL in France, DPC in Ireland).