Privacy notice

Website Privacy Notice.

The published privacy notice, presented in a clearer reading layout.

1. Data Controller

Henkei Corporation (Private) Limited ("we", "us", "our") is the data controller for personal data processed at mcps.work. That covers three things: the public website and its published resources, the M365 Graph MCP connector, and the student subdomain service. Where a section below applies to only one of them, it says so.

๐Ÿ”’
Data Protection Officer For all data-related enquiries: info@henkeicorp.com

2. Personal Data We Process

M365 Graph MCP is a pass-through connector. We do not store your Microsoft 365 data on our infrastructure. The following data is processed transiently to fulfil your requests:

Microsoft 365 Data (on-Behalf-of-User)

  • Email messages, subject, sender, recipients, body, read/written on your behalf when you explicitly instruct the AI assistant.
  • Calendar events, title, start/end time, attendee list.
  • Contacts, display name, email addresses, phone numbers.
  • Mailbox settings, timezone, auto-reply configuration.

Authentication Data (in Memory Only)

  • OAuth 2.0 access tokens (validity: up to 1 hour), held in process memory only.
  • OAuth 2.0 refresh tokens (validity: up to 7 days), held in process memory only; deleted on logout or token revocation.
  • Microsoft Entra ID user identifier (sub claim), used for session isolation.

Website Enquiries (Sent by Email)

  • Name, email address, organisation, enquiry topic and the message you write, submitted through the consultation, training or support forms. These are emailed to us and are not written to a database.

Student Subdomain Service (Stored)

  • Email address, used to send a one-time sign-in code and the annual renewal reminder.
  • The subdomain label you claim and its DNS configuration.
  • Session tokens and sign-in codes, held as keyed hashes rather than in the clear.
  • This is the one part of the service that keeps a durable record. It is held in Azure Table Storage in our own region, and it is separate from any M365 data.
โœ“ No M365 data stored โœ“ No advertising โœ“ No profiling

3. Purpose & Legal Basis

๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka PDPA (No. 9 of 2022)
  • Consent (s. 5 with Schedule I(a)), you authenticate via Microsoft OAuth and explicitly authorise each action.
  • Contractual necessity (s. 5 with Schedule I(b)), processing is required to deliver the service you requested.
  • Legitimate interest (s. 5 with Schedule I(f)), server-side logging for security and troubleshooting.
๐Ÿ‡ช๐Ÿ‡บ EU GDPR (Regulation 2016/679)
  • Consent (Article 6(1)(a)), OAuth authorisation.
  • Contractual necessity (Article 6(1)(b)), service delivery.
  • Legitimate interest (Article 6(1)(f)), security logging, fraud prevention.

4. Sub-Processors & Third Parties

We rely on the following sub-processors to deliver this service:

  • Microsoft Corporation, Microsoft Graph API (data source), Microsoft Entra ID (authentication), Azure Container Apps (hosting). Microsoft's privacy policy applies to data held in your Microsoft 365 tenant.
  • Anthropic, PBC, Claude AI models process your natural-language instructions and the M365 data you share with them. Anthropic's enterprise data handling commitments apply.
  • Google LLC, Google Analytics (GA4) collects anonymised page-view statistics (pages visited, approximate location, device type). No M365 data or personal email/calendar content is sent to Google.
No data sales We do not sell, rent, or share your personal data with any other third parties.

5. International Data Transfers

Requests are forwarded to Microsoft Graph API servers. Microsoft maintains data residency commitments for EU/EEA customers under the EU Data Boundary programme.

When you use Claude AI features, your data is processed by Anthropic's infrastructure. For EU/EEA users this constitutes a transfer to the United States under Standard Contractual Clauses (SCCs).

Google Analytics data is processed by Google LLC in the United States under SCCs. Analytics data is anonymised and does not include M365 content.

For Sri Lankan users, cross-border transfers comply with section 26 of the PDPA.

6. Data Retention

  • OAuth access tokens: up to 1 hour (Microsoft-imposed TTL). Not persisted to disk.
  • OAuth refresh tokens: up to 7 days. In process memory only; deleted on restart, logout, or revocation.
  • M365 content (mail, calendar, contacts): never stored. Data is fetched on-demand, returned to the AI model, and immediately discarded.
  • Server access logs: retained for up to 30 days for security monitoring. Logs contain IP addresses, timestamps, and HTTP status codes, no message content.
  • Google Analytics: anonymised usage data retained per Google's default retention policy (14 months).
  • Website enquiries: retained in the receiving mailbox for as long as needed to answer you and to keep a record of the engagement.
  • Subdomain sign-in codes and sessions: short-lived. Codes expire on use or shortly after issue; sessions last 12 hours.
  • Subdomain claims: held while the claim is active, and released 30 days after a claim lapses.
Revoke access at any time Visit Microsoft My Account โ†’ Privacy โ†’ App permissions to revoke all tokens immediately.

7. Security Measures

  • All traffic encrypted with TLS 1.2+ (HTTPS enforced, HSTS with preload enabled).
  • OAuth 2.0 with PKCE; tokens never exposed in URLs or logs.
  • Rate limiting and request-ID tracing on all endpoints.
  • Container-level isolation; no persistent disk storage.
  • Azure Container Apps hardened environment.
  • Input validation and HTML-escaping on all user-supplied content.

Breach Notification

๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka PDPA
  • Notify the Authority in the form, manner and time set by rules made under the Act (s. 23).
  • Notify affected data subjects in the circumstances those rules prescribe (s. 23).
๐Ÿ‡ช๐Ÿ‡บ EU GDPR
  • Notify the supervisory authority within 72 hours (Article 33).
  • Notify affected individuals without undue delay where high risk exists (Article 34).

8. Your Data Subject Rights

๐Ÿ‡ฑ๐Ÿ‡ฐ Rights under Sri Lanka PDPA
  • Right of access (s. 13)
  • Right to withdraw consent and to object (s. 14)
  • Right to rectification or completion (s. 15)
  • Right to erasure (s. 16)
  • Right not to be subject to automated individual decision making (s. 18)
  • Right of appeal to the Authority (s. 19), and to complain to the Personal Data Protection Authority of Sri Lanka

Response time: one month, extendable by two further months with notice (s. 17)

๐Ÿ‡ช๐Ÿ‡บ Rights under EU GDPR
  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure / "right to be forgotten" (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to lodge a complaint with your national supervisory authority

Response time: 1 calendar month

To exercise any right, email info@henkeicorp.com with your request and sufficient information to verify your identity.

9. Children's Data

M365 Graph MCP is designed for professional and organisational use. We do not knowingly collect personal data from children under 18 years of age. If you believe we have inadvertently collected such data, please contact info@henkeicorp.com immediately.

10. Cookies & Analytics

Google Analytics 4 (GA4) runs on every page of this website, including the published training decks. It collects anonymised usage statistics: pages visited, approximate country, device type, and how far a reader gets through a deck. GA4 sets first-party cookies (_ga, _ga_*) to distinguish visitors. No M365 data, no email or calendar content, and no directly identifying information is included in analytics events.

Analytics runs on the website only. The MCP connector endpoints and the student subdomain service are not instrumented, so using the connector sends nothing to Google.

Beyond analytics cookies, this website does not use tracking pixels, advertising cookies, or persistent tracking identifiers. Two cookies are functional rather than analytical: the OAuth state parameter, a short-lived cryptographic nonce that prevents CSRF during the login flow, and __Host-mcps_domains, the signed-in session for the student subdomain service. Neither is used for tracking.

You may opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the service. The effective date is shown in the page header. Continued use of the service after a policy update constitutes your acceptance of the revised terms.

For significant changes that affect your rights we will make reasonable efforts to notify connected users.

12. Contact Us

For questions about this Privacy Policy, to exercise your data subject rights, or to report a concern:

โœ‰๏ธ
Henkei Corporation (Private) Limited, Privacy Team Email: info@henkeicorp.com Support form: mcps.work/support

Sri Lankan users may also contact the Personal Data Protection Authority of Sri Lanka. EU/EEA users may contact their national data protection supervisory authority (e.g. ICO in the UK, CNIL in France, DPC in Ireland).