Dead Simple 365 Privacy Policy
Version 0.4 (draft), 23 September 2026.
This policy explains how Dead Simple Computing Ltd, trading as Dead Simple 365, collects and uses personal data when you use deadsimple365.co.uk and buy Microsoft 365 subscriptions and related services from us. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Dead Simple Computing Ltd is the controller of the personal data described in this policy.
- Company number: 11670139, registered in England and Wales
- Registered office: Unit 6 60 Portman Road, Reading, Berkshire, United Kingdom, RG30 1EA
- Privacy contact: [email protected]
- ICO registration number: ZA929540
We sell to businesses only. The personal data we hold is mainly the business contact data of the people who act for our customers, such as directors, administrators and billing contacts.
2. The data we collect
We collect and hold the following categories of data.
Company and account data. Company name, trading name, Companies House registration number, business address, VAT number where provided, and the details of your account with us.
Contact data. Names, job titles, business email addresses and phone numbers of the people who place orders, accept agreements, administer the account or receive billing correspondence.
Billing and payment data. Invoices, payment history, subscription and seat records. The quote builder does not collect payment card details. If card payments through Stripe are offered separately, card details are entered directly into Stripe's systems. We do not store full card numbers; any card metadata returned to us is limited to details such as card brand, last four digits and expiry month.
Microsoft tenant and assessment data. We store identifiers needed to connect your Microsoft tenant, including the tenant ID and the verified account identifier. The connected free licence review reads enabled and assigned licence quantities to identify unassigned seats; these counts do not establish what you pay. It does not read user activity, invoices, email or file contents, or security settings. Uploaded licence exports are processed for the requested review. Reports record their source and coverage. Any additional assessment would require an agreed scope and the relevant permissions.
Quote imports. If you upload a Microsoft user or licence CSV, we process it temporarily to group products and quantities. User principal names are used to avoid counting the same user twice within that file. User names and email addresses are not added to the quote or its emails. The temporary file is deleted after the preview attempt; abandoned uploads are subject to temporary-file cleanup. Only the product list you choose, adjusted quantities and the type of export are included when you submit your enquiry.
Optional connected reviews. Where enabled, security and advanced licence reviews each require a separate Microsoft application consent. Security reads Microsoft Secure Score, authentication-method registration data and policy state; registration is not proof that MFA is enforced. The advanced licence review reads account identifiers, enabled status and licence assignments to calculate aggregate counts of disabled licensed accounts and selected potential overlaps. Individual account rows are processed temporarily; these reports retain aggregate findings, coverage and consent evidence, without user names, email addresses or individual account identifiers. Neither review reads mailbox or file contents or makes tenant changes. Disconnecting in our portal stops further reads through that connection; Microsoft application consent can be removed separately in Entra.
Public tools and renewal planning. The email-domain checker sends the domain you enter to Cloudflare's public DNS resolver to retrieve MX, SPF and DMARC records. Relevant results are cached for five minutes and are not saved as an enquiry. The public renewal planner uses the date and optional notes you supply to prepare a checklist and a calendar download; creating a plan does not save a quote or send an email. If you choose to submit a quote, its submitted renewal details are retained with that request. Downloaded calendar files may contain your planning notes, and your chosen calendar service will process any file you import.
Microsoft Customer Agreement acceptance records. Before ordering licences we confirm the required agreement acceptance with you and Giacom. Where acceptance is collected through our site, we record the accepting person's name and email address, date and time, IP address and agreement version. We retain the evidence needed to support the order and provide it to Microsoft or Giacom where required.
Website and technical data. IP addresses, device and browser information, and usage data collected through our site, including any cookies or similar technologies described in our cookie notice.
Correspondence. Emails, support requests and other communications with us.
Enquiries and tool activity. We save quote, audit and service requests, requested licence quantities, follow-up notes and notification status. We record sign-ins, connection attempts and assessment outcomes to operate and support the service. Enquiries may include the public landing page, referring website and campaign labels to help us understand how you found us.
3. How we use the data, and our lawful bases
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Taking orders, provisioning subscriptions, managing your account, billing and support | Performance of a contract (6(1)(b)) |
| Verifying business status via Companies House and screening payments for fraud | Legitimate interests (6(1)(f)): selling only to businesses, protecting against fraud |
| Recording Microsoft Customer Agreement acceptance and sharing it with Microsoft or Giacom on request | Legitimate interests (6(1)(f)): meeting Microsoft CSP agreement requirements and retaining evidence of authorised orders |
| Sending service emails (order confirmations, renewal reminders, payment failure notices, price change notices) | Performance of a contract (6(1)(b)) |
| Sending marketing about our services to business contacts | Legitimate interests (6(1)(f)), with the right to opt out at any time |
| Keeping accounting and tax records | Legal obligation (6(1)(c)) |
| Establishing, exercising or defending legal claims | Legitimate interests (6(1)(f)) |
We do not use personal data for automated decision making that produces legal or similarly significant effects. We do not sell personal data.
4. Who we share data with (our processors and partners)
We share data with the following recipients, only to the extent needed for the purposes above.
- Stripe, where card payments are separately offered, processes those payments and holds your card details. Stripe also acts as an independent controller for some of its own regulatory purposes, as described in Stripe's privacy policy.
- Giacom, our Microsoft indirect provider, receives the customer, tenant and subscription details needed to place and manage your Microsoft orders, and the Microsoft Customer Agreement acceptance records where requested.
- Microsoft receives the customer and tenant details needed to provision your subscriptions, and processes your tenant data under the Microsoft Customer Agreement as your processor.
- Laravel Cloud hosts our website, application and databases.
- Cloudflare's public DNS resolver receives domain queries when you use the email-domain checker. We send the requested DNS name, not your enquiry details or Microsoft account data.
- Resend sends our service and account emails on our behalf, including enquiry acknowledgements and sign-in links.
- Google Analytics or Plausible, when configured and accepted through Cookie settings, measures visits to public website pages.
- Our professional advisers (accountants, solicitors, insurers), and authorities where disclosure is required by law.
Where these recipients act as our processors, they do so under contracts that meet the requirements of Article 28 UK GDPR.
5. International transfers
Some of our providers (including Stripe and Microsoft) may process data outside the UK, including in the United States. Where personal data leaves the UK, we rely on safeguards recognised under UK GDPR, such as UK adequacy regulations, the UK Extension to the EU US Data Privacy Framework, or the International Data Transfer Agreement and Addendum to the EU Standard Contractual Clauses, as applicable to each provider.
6. How long we keep data
- Account, subscription and MCA acceptance records: for the life of the customer relationship, then for 6 years after the relationship ends, reflecting limitation periods for contract claims and Microsoft CSP audit requirements.
- Invoices and accounting records: at least 6 years from the end of the financial year they relate to, as tax law requires.
- Correspondence and support records: up to 6 years after the relationship ends.
- Marketing contact data: until you opt out or the data is no longer current.
- Website logs and technical data: typically no more than 12 months.
After these periods, data is deleted or anonymised.
7. Security
We apply appropriate technical and organisational measures, including encryption in transit, access controls, and restriction of card data handling to Stripe's PCI DSS certified systems. No system is perfectly secure, and we will notify you and the ICO of personal data breaches where the UK GDPR requires it.
8. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure of your data in certain circumstances;
- restriction of processing in certain circumstances;
- data portability of data you provided to us under contract;
- object to processing based on legitimate interests, including the right to stop direct marketing at any time;
- withdraw consent at any time, where we rely on consent.
To exercise any right, contact [email protected]. We respond within one month, extendable by two further months for complex requests. We may need to verify your identity first. These rights belong to the individuals whose data we hold (for example, the named contacts at our customers), not to the company as such.
9. Complaints
If you are unhappy with how we handle your personal data, please contact us first at [email protected] so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
10. Changes to this policy
We may update this policy from time to time. The current version is always published on our site with its version date. Material changes will be notified to the billing contact on file.
11. Cookies and optional analytics
Essential session and security cookies support sign-in, forms and your basket. We remember your analytics choice in browser storage for up to 180 days. Optional analytics only loads after you choose Accept analytics. You can reject it or change your choice using Cookie settings. If you withdraw consent, we stop loading analytics and remove accessible Google Analytics cookies.
Optional analytics measures public pages. Our explicit page and event measurements exclude URL query strings, email addresses, form text and tenant identifiers. Analytics scripts are not loaded on account, assessment report, checkout or admin pages. Service activity stored in our own application is separate from these optional website measurements.
When you request a quote, we keep limited source details with your enquiry, such as the first public page visited, the referring website domain and campaign labels. We also offer an optional question about how you found us. We use this information to understand which pages and channels produce useful enquiries. Your answer is kept separately from automatically observed source details.
Authorised staff can review recorded service activity and outstanding requests in our admin portal. Internal daily email summaries contain aggregate activity, lead-source and delivery-status counts, without uploaded user lists or customer message contents.