Privacy Policy

How Xertone LLC handles information when you use TeamsPIM and related services.

Draft notice: This Privacy Policy is a working draft pending review by licensed Texas counsel prior to public launch. Material terms may be revised.

1. Effective Date

This Privacy Policy is effective as of May 20, 2026. We will note the date of any future material changes in Section 12 below.

2. Data Controller

The data controller responsible for personal data processed under this Policy is:

3. What We Collect

To operate TeamsPIM and meet Microsoft AppSource Marketplace publisher requirements, we collect:

4. What We Do NOT Collect

We do not collect or store the following categories of data:

5. How We Use Data

We use the categories of data described above solely to:

We do not use customer data for advertising, sale to third parties, or training machine-learning models.

6. Cookies & Analytics

The Xertone website and Customer Admin Portal use minimal first-party cookies only, limited to what is necessary to operate the site and remember user-session state. We do not embed third-party analytics, advertising, or tracking pixels on our properties.

7. User Rights

Depending on your jurisdiction, you may have the following rights with respect to personal data we hold about you.

European Economic Area & United Kingdom (GDPR / UK GDPR Articles 15–22):

California residents (CCPA / CPRA, Cal. Civ. Code §§ 1798.100–1798.145):

To exercise any of these rights, contact us using Section 13 below. Your Microsoft Entra ID administrator separately controls access to organization-level data through Microsoft's tooling.

8. Third-Party Services

TeamsPIM depends on the following Microsoft sub-processors to deliver core functionality:

9. Data Retention

10. International Transfers

Customer data is hosted in Microsoft Azure United States regions. If you access the service from outside the United States, your data will be transferred to and processed in the United States. For European Economic Area and United Kingdom customers, cross-border transfers from Microsoft sub-processors are covered by Microsoft's Standard Contractual Clauses (SCCs) as set forth in the Microsoft Products and Services Data Protection Addendum.

11. Children's Privacy

TeamsPIM is a business-to-business SaaS service for IT and security teams. It is not directed to, and we do not knowingly collect personal information from, children under the age of 16. If we become aware that we have collected such information, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide notice through the in-app Customer Admin Portal at least thirty (30) days before the changes take effect. Continued use of the service after the effective date constitutes acceptance of the updated Policy.

13. Contact

To exercise data rights, ask questions about this Policy, or report a privacy concern, contact:

This Privacy Policy is governed by the laws of the State of Texas, United States.