Privacy Notice

This notice explains what personal data Ahmed Wael, sole proprietor, trading as The Global Assistant (TGAGlobal) collects when you visit www.theglobalassistant.click or use The Global Assistant, why we collect it, who we share it with and what rights you have. We collect only what the Service needs in order to work. We do not sell personal data, we do not share it for advertising, and we do not use it to train machine-learning models.

1. Two roles: controller and processor

For your account and billing data we are the data controller and this notice describes what we do with it. For the contents of automation outputs — data pulled from your Microsoft 365 tenant, which may describe your colleagues — your organisation is the controller and we act as your processor, handling it only on your instruction. If you need a data processing agreement, email us and we will provide one.

2. Data we collect

Account data. When you sign in with Microsoft we receive your name, email address, Microsoft user ID and tenant ID, and the plan and seat assigned to you. We do not receive or store your Microsoft password.

Tenant connection data. When an administrator connects a tenant we store the tenant ID, organisation name and SharePoint admin URL, and a record that consent was granted. Tenant access uses certificate-based application credentials held in our managed key vault (or, on Bring-Your-Own-App setups, held by you).

Run data. For every automation you run we store the inputs you entered, the script name, who ran it, timestamps, status and the output. Outputs come from your own Microsoft 365 tenant and may contain personal data about people in your organisation — for example names, email addresses, mailbox sizes, licence assignments or sign-in dates.

Billing data. Payments are handled by Paddle.com Market Ltd, our Merchant of Record. Paddle collects your billing name, address, country, tax identifiers and card details directly, under its own privacy notice. We never see full card numbers. We store only your Paddle customer and subscription IDs, plan, billing period, status and renewal date.

Technical data. Standard server logs — IP address, browser and device type, pages requested, timestamps and error traces — kept for security, abuse prevention and troubleshooting.

Correspondence. Emails you send to our support address and our replies.

3. Why we use it, and our legal basis

  • To provide the Service — run automations, show your history, manage tenants, seats and plan limits. Basis: performance of our contract with you.
  • To take payment and prevent fraud — process subscriptions, renewals and refunds. Basis: performance of our contract, and our legitimate interest in preventing fraudulent payments.
  • To send service messages — failed runs, security notices, billing and plan changes. Basis: performance of our contract. These are not marketing emails and cannot be turned off while your account is active.
  • To keep the Service secure and reliable — logging, rate limiting, debugging, capacity planning. Basis: our legitimate interest in a secure service.
  • To comply with law — tax and accounting records, responding to lawful requests. Basis: legal obligation.

Where we rely on legitimate interests, we have considered the impact on you and limited what we collect accordingly. You can object at any time using the contact details below.

4. Cookies

We use one first-party session cookie to keep you signed in, and local browser storage for interface preferences such as theme. That is all. We run no advertising cookies and no cross-site tracking, and we use no cookies for analytics, so no cookie consent banner is required. Paddle sets its own cookies inside the checkout window it controls; see Paddle’s privacy notice for detail.

We measure aggregate traffic to our public website pages using Umami, a privacy-focused analytics tool that sets no cookies, stores no personal data and does not track you across sites. It records anonymous page views, referrer and approximate country only.

5. Who we share data with

We use a small number of sub-processors, each bound to process data only for us:

  • Microsoft Azure — hosting, database, key management and script execution (United States).
  • Supabase — application database and authentication records.
  • Umami Software, Inc. — cookieless analytics for our public website pages; no personal data collected.
  • Paddle.com Market Ltd — Merchant of Record, payment processing, invoicing and tax (United Kingdom / European Union).
  • Microsoft Azure Communication Services — transactional email.

We do not otherwise disclose personal data, except where legally required or to protect our rights or the safety of users. If the business is sold or reorganised, data may transfer to the acquirer under the same protections, and we will tell you first.

6. International transfers

Our infrastructure is hosted in the United States and the business is operated from Egypt. Where personal data originates in the European Economic Area, the United Kingdom or Switzerland, transfers are covered by the standard contractual clauses and equivalent safeguards our providers maintain, together with encryption in transit and at rest.

7. How long we keep it

  • Account and tenant data — while your account is active, then deleted within 30 days of closure.
  • Run inputs and outputs — while your account is active so you can review past runs; deleted with the account, or earlier on request.
  • Server logs — up to 90 days.
  • Billing and tax records — retained by us and by Paddle for as long as tax and accounting law requires, typically several years, even after account closure.

Revoking our application in Microsoft Entra ID ends our access to your tenant immediately, independently of any deletion request.

8. Security

Data is encrypted in transit (TLS) and at rest. Tenant access uses certificate-based application authentication with the minimum permissions each plan requires; certificates and secrets live in a managed key vault and never in code or in source control. Production access is restricted to the operator of the Service and protected by multi-factor authentication. Automation runs are isolated per tenant and logged. If a breach affects your personal data we will notify you and any relevant supervisory authority without undue delay, and within 72 hours where required.

9. Your rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, export it in a portable format, restrict or object to its processing, and withdraw consent where processing relies on consent. California residents may request disclosure of the categories of personal information collected and may opt out of sale or sharing — we do neither.

To exercise any right, email info@theglobalassistant.click. We will verify your identity and respond within 30 days. There is no charge unless a request is manifestly excessive. We will never restrict or degrade your Service for making a request.

If you are in the EEA or UK you may also lodge a complaint with your local data-protection authority. For personal data contained in automation outputs, the organisation that ran the automation is the controller — contact them first, and we will support them in responding.

10. Children

The Service is for business use by adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it.

11. Changes and contact

We will update this notice when our practices change and revise the date above; material changes are emailed to active subscribers. Questions, requests and complaints go to Ahmed Wael, sole proprietor, trading as The Global Assistant (TGAGlobal) at info@theglobalassistant.click. See also our Terms and Conditions and Refund and Cancellation Policy.