Privacy Policy
This Privacy Policy describes how TurboClientSystems, Inc. ("TurboClientSystems," "we," "us," or "our") handles information in connection with RunDEETS (the "Service"). The short version: your organization’s compliance data lives in your organization’s own Microsoft 365 tenant, we hold no copy of it, and the small amount of personal information we do handle is what it takes to sign you in and deliver the application to your browser.Effective August 21, 2026.
These terms are in force and govern your use of RunDEETS today. They were drafted in-house against how the software actually works rather than copied from a template, and they have not yet been reviewed by outside counsel — we will revise them before RunDEETS is generally available, and we would rather say so plainly than let you assume a review happened that has not. Nothing on this page is legal advice to you, and nothing on it overrides a separate signed agreement between your organization and TurboClientSystems, Inc.
1. Scope, and Our Role in Your Data
This Policy covers the RunDEETS web application and its public pages. It does not cover Microsoft 365, SharePoint, Microsoft Entra ID, or any other service your organization uses, each of which is governed by your organization’s own agreements with its provider. Our role differs depending on which information is at issue, and the distinction matters for your rights. For the compliance data, evidence, submissions, comments, role assignments, and audit records your organization creates through the Service, your organization is the controller and decides what is collected, who may see it, and how long it is kept; we are not a processor of that data in the usual sense, because it never reaches us — it moves directly between your browser and your own Microsoft 365 tenant. For the limited information involved in signing you in and serving you the application, we act as controller. Requests about the first category should go to your organization’s administrator; requests about the second can come to us.
2. Information We Collect
When you sign in, your browser receives account and profile information from your organization’s identity provider (Microsoft Entra ID) — your name, email address, user ID, tenant/organization identifier, and, where you have one set, your profile photo. That information is used in your browser and, where you record something, written into your own tenant; it is not transmitted to us. The compliance data, configuration, evidence files, generated documents, exam submissions and their answers, comments and @mentions, role assignments, and append-only audit entries you or your colleagues create are stored in your organization’s SharePoint site, each attributed to the identity of the person who created it. The Service does not use analytics, product-usage tracking, session recording, advertising, or third-party error reporting, and it makes no network requests to any host other than Microsoft’s sign-in and Graph endpoints, your organization’s SharePoint domain, and its own origin — an enforced browser policy, described in Section 10, blocks anything else. What we do necessarily have is ordinary web-server information: our hosting provider records standard request logs when your browser loads the application, including IP address, timestamp, requested URL, and user-agent string. We use those logs only to deliver, secure, and troubleshoot the site.
3. Directory Information About Other People
Some features read limited information about other people in your organization. When you open the people picker to assign a governance role or @mention a colleague, the Service searches your organization’s directory and displays matching names, email addresses, and profile photos. This happens in your browser, using your own delegated permission, against your own tenant; the results are not sent to us. If you then save an assignment, mention, or access grant, the names and email addresses of the people involved are written into your organization’s own SharePoint lists as part of that record, where they are retained under your organization’s control. Your organization is responsible for whatever notice or consent its own employees are owed for that.
4. How We Use Information, and Our Legal Bases
Information handled through the Service is used to authenticate you and enforce access controls; to display and organize your organization’s compliance data and attribute records to the person who created them; to keep your preferences and session working across page loads; to communicate with you about the Service; and to deliver, secure, and troubleshoot the application itself. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it to develop or train models. Where the UK or EU General Data Protection Regulation applies, our legal bases for the limited processing we perform as controller are the performance of a contract with you (delivering the application and signing you in) and our legitimate interests in operating and securing the Service, balanced against your rights. Where processing is based on consent — the optional browser storage described in the next section — you may withdraw it at any time without affecting processing already carried out.
5. Cookies and Browser Storage
The Service stores a small amount of information in your browser’s own storage (localStorage and sessionStorage). It falls into two groups, and we want to be exact about which is which, because the difference is your choice. Strictly necessary items are written without asking, because the Service does not work without them: your Microsoft sign-in session and token cache, which by default live in session storage and are gone when you close the tab unless you choose otherwise; your accessibility settings (high-contrast mode and text size), which are treated as necessary so that someone who needs them is never made to re-enable them; and the record of your cookie choice itself. Optional items are written only after you agree in the cookie preferences dialog, and are read back only while that agreement stands: your light/dark theme, interface density, sidebar layout, and a cached copy of your tenant’s branding and SharePoint hostname kept so pages load faster. You can review or change these choices at any time through the "Cookie settings" link in the footer, and you can remove everything by clearing your browser’s site data. The Service uses no advertising cookies, no cross-site tracking, and no analytics cookies; it sets no first-party or third-party tracking cookie; and its fonts are served from our own origin rather than from a font provider.
6. Microsoft Graph Permissions We Request
The Service asks for a deliberately small set of delegated Microsoft Graph permissions, always under your own signed-in identity and never as a service account. Signing in requests only the ability to read your basic profile and to access the one SharePoint site your organization has explicitly granted — a scope that resolves to the intersection of "this application was granted this specific site" and "you already have access to it," so it cannot reach any other site in your tenant. Two further permissions are requested separately, only at the moment a feature needs them: reading your organization’s branding, to prefill your logo in settings, and reading basic profile information for other people, to power the role-assignment people picker. Each permission, and the reasoning for choosing the narrower option over the broader one, is listed individually on our public Permissions page. Setting up the Service initially requires an administrator to grant broader, admin-consented permissions and run provisioning steps under their own credentials; as described in the Terms, that elevated access is temporary, stays in the administrator’s browser, and is never transmitted to or retained by us.
7. Where Your Data Lives
Your organization’s compliance data is stored entirely within your organization’s own Microsoft 365 tenant. Its physical location, encryption, residency, and regulatory treatment are inherited from your organization’s own Microsoft 365 configuration and agreements with Microsoft; they are not controlled, chosen, or warranted by us. Each deployment of the Service is configured for a single Microsoft cloud — commercial, Government Community Cloud High, or DoD — to match your environment. The application itself is served from a commercial web hosting provider, which is where the request logs described in Section 2 are generated; that provider never receives your compliance data or your Microsoft access token.
8. Service Providers and Sub-processors
We keep this list short by design, and it is complete as of the effective date of this Policy. Microsoft provides identity, Graph, and SharePoint services, under your organization’s own agreements with Microsoft rather than ours. Vercel Inc. hosts and serves the RunDEETS web application and generates the standard request logs described in Section 2. Google Fonts typefaces are used, but the font files are bundled into the application and served from our own origin at build time, so your browser makes no request to Google when you load a page. We do not use an analytics provider, an advertising network, a customer data platform, an error-monitoring service, a CRM, or an email marketing platform in connection with the Service. If that changes, we will update this section and, where consent is required, ask for it before anything is collected.
9. Data Retention and Deletion
Compliance data, configuration, evidence, documents, submissions, comments, and audit records reside in your organization’s own SharePoint site and are retained according to your organization’s own retention policies, backup settings, and administrative decisions — we neither set nor enforce a retention period for them, and we cannot delete them for you. Two points deserve emphasis. First, the audit log the Service maintains is append-only by design: entries record who performed each write, to what, and when, and are never modified or deleted by the Service, because a compliance trail that can be edited is not a compliance trail. Your organization controls that list in SharePoint and can remove it, but should weigh that against its own evidentiary needs, and should treat it as a record containing personal data when responding to a deletion request. Second, information stored in your browser is retained only on your device — necessary items until you sign out or clear site data, optional items until you withdraw consent or clear them. Hosting request logs are retained by our hosting provider for a limited period under its standard practices and are used only for delivery, security, and troubleshooting. We hold no separate database of your organization’s compliance data to retain or delete.
10. Security
The Service is built so that a security failure has as little to reach for as possible. There is no server-side database of customer data, no service account in your tenant, and no standing credential of ours anywhere — which removes an entire category of breach rather than promising to prevent it. Your Microsoft access token is held only in your own browser: in session storage by default, so that it is gone when the tab closes, and in persistent storage only if you choose to stay signed in. The application enforces a strict Content Security Policy that confines every network request the page can make — including background requests, form submissions, image loads, and frames — to Microsoft’s sign-in and Graph endpoints, your organization’s SharePoint domain, and our own origin, so that even a hostile script running on the page would have nowhere to send a token. Traffic is served over HTTPS with strict transport security, and the application sets browser hardening headers including a strict referrer policy, framing restrictions, and a permissions policy disabling device APIs the Service does not use. No system is perfectly secure, and this is pre-release software. If we become aware of a security incident affecting information we hold, we will notify affected users and, where required, regulators without undue delay; if an incident affects data in your own tenant, your Microsoft 365 environment’s own logging and notification mechanisms — not ours — are what will show it, which is another reason your administrator’s configuration matters.
11. Exam Submissions and Personnel Records
Some features record information about identifiable employees. A completed exam or assessment is saved with the submitter’s name, email address, timestamp, and answers, both as a structured record and as a generated document. Role assignments, access-grant records, and comments are likewise attributed by name and email. In many jurisdictions this is employee or personnel data with heightened handling expectations, and in some it may support decisions about an individual. All of it is created by your organization, stored in your organization’s tenant, and controlled by your organization; we neither receive it nor make any decision using it. Your organization is responsible for providing employees with any required notice, for restricting access appropriately, and for handling requests those individuals make about it.
12. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, to withdraw consent, and not to be discriminated against for exercising those rights. Because your organization’s compliance data is stored in your organization’s own Microsoft 365 tenant and is under its administrator’s control, requests about that data should go to your organization’s administrator, who is the only party able to act on them — we will assist where we reasonably can, but we cannot access, produce, correct, or delete data we do not hold. For the limited information we handle as controller, submit your request through our contact form at rundeets.com/contact and we will respond within the time applicable law requires. We do not sell personal information and do not share it for cross-context behavioral advertising, under the California Consumer Privacy Act or otherwise, and we do not use personal information for automated decision-making or profiling that produces legal or similarly significant effects. If you are in the EEA or the UK, you also have the right to lodge a complaint with your local supervisory authority.
13. International Transfers
The Service is operated from the United States, and the limited information we handle as controller — principally the hosting request logs described in Section 2 — is processed there. Where your compliance data is stored and processed is determined entirely by your own Microsoft 365 tenant’s configuration and your organization’s agreements with Microsoft, including any transfer mechanism those agreements provide. If you access the Service from outside the United States, you understand that delivering the application to you involves processing in the United States.
14. Children’s Privacy
The Service is intended for use by working professionals aged 18 or older, on behalf of their organizations, using a work or school account. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a minor has used the Service, contact us and we will address it.
15. Changes to This Policy
We may update this Policy from time to time. When we do, we will change the effective date shown at the top of this page, and for material changes we will make reasonable efforts to give additional notice through the Service. Changes apply prospectively. Continued use of the Service after a change takes effect constitutes acceptance of the revised Policy. You should review this page periodically.
16. Contact
RunDEETS is a product of TurboClientSystems, Inc., a Florida corporation. Questions about this Privacy Policy, and requests regarding your personal information, should be submitted through our contact form at rundeets.com/contact — we do not publish a support or privacy email address, and the form is our designated method for receiving privacy requests. If your question is about compliance data your organization stores through the Service, your organization’s own administrator is the right first contact, for the reasons described in Section 1.