Legal
Privacy Policy
Last updated 17 June 2026
This policy explains how KAIRAVO processes personal data and customer tenant data. KAIRAVO is built evidence-first: it reads Microsoft Intune data through Microsoft Graph with read-only access and never writes to your tenant.
1Who we are
KAIRAVO provides evidence-backed findings for Microsoft Intune environments, built for managed service providers (MSPs) and internal IT teams. In this policy, “KAIRAVO”, “we”, “us”, and “our” refer to UgurLabs UG (haftungsbeschränkt), the entity responsible for the service available at www.kairavo.com.
For data we process about your own account and use of the service, we act as a controller. For Microsoft 365 and Intune tenant data we access on your behalf to generate findings, we act as a processor on your instructions, governed by a Data Processing Agreement (DPA).
2Scope
This policy covers the KAIRAVO website, the dashboard, and the read-only connectors used to assess a customer tenant. It does not cover Microsoft services, third-party tenants, or external sites that KAIRAVO may link to, each of which is governed by its own privacy terms.
3Data we process
We process the following categories of data:
- Account and identity data. When you sign in through Microsoft Entra ID, we receive basic profile information such as your name, email address, and tenant identifier to create your session.
- Tenant assessment data. Through read-only Microsoft Graph access we read configuration and inventory data, including device inventory and state, detected application metadata, policy and configuration settings, assignments, filters, and compliance status. This data is used to produce findings and their supporting evidence.
- Findings and evidence. The recommendations, snapshots, baselines, and evidence trails KAIRAVO generates from your tenant data.
- Technical and usage data. Logs, IP address, browser type, and interaction events used to operate, secure, and improve the service.
KAIRAVO requests the minimum Microsoft Graph scopes needed for an assessment and does not request write scopes.
4How we use data and legal bases
We process data to:
- provide the assessment, generate findings, and present supporting evidence;
- authenticate users and secure access to the dashboard;
- operate, maintain, troubleshoot, and improve the service; and
- meet legal, accounting, and security obligations.
Where the GDPR applies, we rely on the following legal bases: performance of a contract (providing the service you or your organisation requested), legitimate interests (securing and improving the service, in a way that does not override your rights), and legal obligation where applicable. For tenant assessment data we process on a customer’s instruction, the customer is the controller and is responsible for the legal basis for that processing.
5Read-only access and least privilege
The KAIRAVO assessment is read-only. It does not modify, delete, or create configuration in your Microsoft tenant. Access follows the principle of least privilege: only the scopes required to read the data behind a finding are requested, and consent can be revoked at any time from your Microsoft Entra admin centre.
6Automated explanations and AI
Findings are produced from rules and source data first. Plain language explanations are optional and never invent facts the evidence does not support. Customers can choose between:
- Deterministic mode, which uses no generative AI; or
- EU-hosted AI, which routes approved prompts through an Azure OpenAI deployment in a European region.
We do not use customer tenant data to train foundation models, and we configure AI processing to avoid provider-side retention of prompts and outputs where the provider supports it.
7Sharing and subprocessors
We do not sell personal data. We share data only with service providers that help us operate KAIRAVO, under contracts that require appropriate safeguards. Core subprocessors include:
- Microsoft — identity (Microsoft Entra ID) and the Microsoft Graph APIs used to read tenant data.
- Azure OpenAI (EU region) — only when EU-hosted AI explanations are enabled.
- Hosting and infrastructure providers — used to run the application and store data.
A current list of subprocessors, including provider, region, purpose, and retention, is available on request at privacy@kairavo.com.
8International transfers
Where data is transferred outside the European Economic Area, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Customers requiring EU data residency can use the deterministic mode or the EU-hosted AI option so that assessment processing stays within a European region.
9Data retention
We keep personal data only as long as needed for the purposes above. Tenant assessment data and findings are retained for the duration of the engagement and deleted within 30 days of its end or on verified request, unless a longer period is required by law. Account and limited security logs may be retained for a longer, defined period for audit and security purposes.
10Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, least-privilege scopes, server-owned sessions, and logging. Authentication uses an HttpOnly session managed on the server; the session cookie cannot be read by client-side scripts.
11Your rights
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, and the right to data portability. Where processing relies on consent, you may withdraw it at any time. To exercise these rights, contact privacy@kairavo.com. If the data concerns a customer tenant for which we act as processor, we will direct the request to the relevant controller.
If you are in the EEA or UK and believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority (To be confirmed (lead EU supervisory authority pending)).
13Children
KAIRAVO is a business tool that is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children.
14Changes to this policy
We may update this policy as the service evolves. We will revise the “last updated” date above and, for material changes, provide a more prominent notice. Continued use of KAIRAVO after an update means you accept the revised policy.
15Contact and company details
Questions about this policy or our data practices can be sent to privacy@kairavo.com.
- Entity: UgurLabs UG (haftungsbeschränkt)
- Address: To be confirmed (registered business address pending)
- Privacy contact: privacy@kairavo.com