Presify Privacy Policy
Effective Date: June 27, 2026
This Privacy Policy explains how Presify, LLC, a Florida limited liability company ("Presify," "we," "us," or "our"), collects, uses, and protects information in connection with the Presify service available at presify.io (the "Service").
This Privacy Policy applies to two categories of individuals:
- Customer Personnel. Authorized Users of the Service (typically IT administrators) who sign in, configure the Service, and view reports.
- Monitored Users. Individuals within Customer's Microsoft 365 tenant whose presence data is collected by the Service on behalf of Customer.
Customer is the data controller for both categories of data. Presify processes data on Customer's instructions as described in the Data Processing Agreement available at https://presify.io/legal/dpa.
1. Information We Collect
1.1 Information from Customer Personnel
When an Authorized User signs up for or uses the Service, we collect:
- Account information: name, work email address, Microsoft user principal name (UPN), and the Microsoft tenant identifier of the organization.
- Authentication information: access tokens issued by Microsoft when the Authorized User signs in via Microsoft Entra ID (the delegated User.Read permission). These tokens are used solely to verify identity during the sign-in flow and are not retained beyond the session.
- Application usage information: features used, dashboards viewed, reports generated, and similar metadata necessary to operate and improve the Service.
- Support communications: messages submitted through our website contact forms or the in-application support form, retained for response and quality purposes.
- Billing information: processed and stored by Stripe; Presify receives a customer identifier and subscription metadata but does not store payment card numbers.
- Marketing attribution: if applicable, the UTM parameters present on the signup URL.
1.2 Information about Monitored Users
When Customer activates monitoring, the Service collects from the Microsoft Graph API on Customer's behalf:
- Identification information: Microsoft user identifier (immutable), user principal name (UPN), display name, and the organizational tenant identifier.
- Directory context: organizational department, when set in the directory, used for team-based grouping; and work location (country and, where present, state or province), used solely to enforce the regional exclusion described in Section 6.4 and to surface US state notice reminders.
- Presence events: changes in Microsoft Teams presence status (e.g., Available, Busy, Away, In a Meeting, Offline) with associated timestamps. Presence events are aggregated into daily summaries for reporting.
- Anomaly findings: automated detections derived from presence events (e.g., unbroken Available stretches, idle suppression patterns).
- Schedule context: each Monitored User's time zone and working hours, read from their Outlook mailbox settings (MailboxSettings.Read), used to render timelines and business hours in the user's own local time.
The Service presents historical analysis; it is not a real-time presence dashboard.
During a free trial, the Service collects presence data for the account owner's own Microsoft user only; no other user can be monitored until the account upgrades to a paid plan.
The Service does not access or collect:
- Email content
- Chat or message content
- File or document content
- Calendar event content
- Call recordings or transcripts
- Any other Microsoft 365 data outside of presence status, basic user directory fields, and mailbox time-zone and working-hours settings necessary to operate the Service
1.3 Information collected automatically
When users access the Service, we collect:
- Log data: IP address, browser type, operating system, referrer URL, and timestamps.
- Cookies and similar technologies: strictly necessary cookies for authentication and session management, plus non-essential cookies set only if you allow them: Google Analytics (analytics) and Google Ads (advertising) on our public website, and a first-party signup-attribution cookie (see Section 11). These are off until you consent and are never used inside the signed-in product.
1.4 Information from contact and data-request forms
When anyone submits one of our website contact forms or the data and privacy request form, we collect the name, email address, and the contents of the message provided, and we use it only to respond to and act on the request. These submissions are stored as a record of the request (so a request is never lost if email delivery fails) separately from the presence data the Service processes on a Customer's behalf, and are retained for a limited period. We ask that you not include sensitive identifiers (such as government ID numbers) in these forms.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service for Customer
- Authenticate Authorized Users and enforce access controls
- Collect, store, and display presence data and reports to Customer
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations and respond to lawful requests
- Communicate with Authorized Users about the Service, including service notices, billing notices, and updates
- Improve the Service through analytics on aggregated usage patterns
- Provide customer support
We do not use Monitored User data for any purpose other than providing the Service to the Customer on whose behalf it was collected. We do not sell it; we do not use it to train any machine learning or artificial-intelligence model; and we do not use it to benchmark, build, or improve features across customers. Any analytics we use to operate and improve the Service are limited to de-identified, aggregated service telemetry (for example, overall request volumes and error rates) that cannot reasonably be used to identify any Customer, Authorized User, or Monitored User.
3. Legal Basis for Processing
Presify processes personal information based on the following legal bases:
- Contractual necessity: processing required to provide the Service under our Terms of Service with Customer.
- Legitimate interests: processing necessary for the security, integrity, and improvement of the Service.
- Compliance with law: processing required by applicable legal obligations.
- Establishment, exercise, or defense of legal claims: retaining records of who accepted our legal terms and who attested to the data-controller and employee-monitoring-notice responsibilities described in our Terms, AUP, and DPA, together with the identity of the accepting user, to prove that the monitoring was authorized and consented to and to establish, exercise, or defend legal claims. See Section 5.5.
For Monitored User data, Customer is responsible for ensuring it has a valid legal basis to monitor each Monitored User, including providing any notices required by applicable law. Presify processes Monitored User data on Customer's behalf as described in the DPA.
4. How We Share Information
We do not sell personal information. We share information only as follows:
4.1 Sub-processors
The following sub-processors assist us in providing the Service. Each is bound by a written agreement requiring confidentiality, security, and use limited to providing services to Presify:
| Sub-processor | Purpose | Location | Data accessed |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, compute | United States | All Customer Data including presence events, reports, and account information |
| Postmark (ActiveCampaign, LLC) | Delivery of transactional and account-notification email | United States | Recipient email address, subject, and the contents of Presify notification and digest emails (never Teams message content) |
| Stripe, Inc. | Subscription billing and payment processing | United States | Account billing email, organization name, subscription tier |
| Functional Software, Inc. (Sentry) | Application error and performance monitoring | United States | Application telemetry, error reports (PII scrubbed before submission) |
| Microsoft Corporation | Authentication via Microsoft Entra ID and source of presence data via Microsoft Graph API | Customer's Microsoft tenant region | Authentication tokens, presence data accessed under Customer's tenant consent |
| Google LLC | Analytics and advertising measurement on our public marketing website, loaded only with your consent | United States | Public-website visitor analytics and advertising identifiers. No Customer Data or Monitored User presence data. |
We will provide reasonable advance notice (typically thirty days) of material changes to the sub-processor list. The current list is available at https://presify.io/legal/privacy.
4.2 Service providers
We may share information with service providers who assist with payment processing, hosting, analytics, error monitoring, customer support, and similar functions. These providers are bound by contractual confidentiality and security obligations.
4.3 Legal compliance
We may disclose information when required by law, court order, or governmental request, or when we believe in good faith that disclosure is necessary to (a) protect the rights, property, or safety of Presify, our customers, or others, (b) investigate fraud or security incidents, or (c) enforce our Terms of Service.
4.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of business assets, information may be transferred to the acquirer or successor as part of that transaction, subject to standard confidentiality protections. We will provide notice via email and a prominent notice on the Service before any transfer that would materially change this Privacy Policy.
4.5 Aggregated and anonymized data
We may share aggregated and anonymized statistics that cannot reasonably be used to identify any individual.
4.6 SMS and mobile messaging
Presify uses SMS and text messaging only for conversational, one-to-one communication between you and a member of the Presify team, for example a support or service conversation from a Presify team member's phone number. We do not use SMS for marketing, promotional, automated, or bulk messaging.
We use a mobile phone number and SMS consent information only to carry and respond to these messages, including sharing them with the messaging platform providers and carriers that deliver the messages for us. Mobile information is not shared with third parties or affiliates for marketing or promotional purposes. Text-message originator opt-in data and consent are excluded from every sharing category in this Privacy Policy; that information is not shared, sold, rented, transferred, or disclosed to any third party for any purpose. The full text-messaging terms, including how to opt out, are in our SMS Terms of Use.
5. Data Retention
5.1 Customer-controlled retention
Presence data and derived reports are retained according to Customer's subscription tier:
| Tier | Retention period |
|---|---|
| Basic | 7 days |
| Standard | 30 days |
| Pro 50 / 100 / 250 | 180 days |
| Scale | 360 days |
Data older than the retention period is automatically deleted by automated processes each night.
During a free trial, the only presence data collected is the account owner's own Microsoft Teams presence, retained on the same basis until the trial ends.
5.2 Operational retention
- Account information: retained while the Customer's account is active.
- Audit logs: retained for the life of the account and for a reasonable period thereafter for security and compliance purposes.
- Operational and security logs: Service-operation records, including per-tenant Microsoft Graph API availability (uptime) records, retained for the life of the account and a reasonable period thereafter as evidence that the Service operated as described. These records contain no Monitored User presence data.
- Email delivery metadata: records of notification emails the Service sends (recipient address, subject line, template type, and delivery status, never message content), retained for one hundred eighty (180) days from the send, then automatically deleted.
- Billing records: retained as required by tax and accounting laws (typically seven years).
- Support tickets: retained for the life of the account and for a reasonable period thereafter for service-quality purposes.
- Anonymized billing audit trail after cancellation: retained as required by tax and accounting laws.
5.3 Deletion on cancellation
When a Customer cancels its subscription, Customer Data is deleted at the end of the thirty-day read-only window per the Terms of Service and the DPA. Audit logs, operational and security logs (including per-tenant Microsoft Graph API availability records, which contain no Monitored User presence data), and anonymized billing records may be retained beyond this window for the purposes described above.
5.4 Immediate deletion option
Customers may request immediate deletion of all Customer Data through the in-application "Delete all data" feature, which bypasses the read-only window.
5.5 Acceptance and attestation records
We retain records of legal-document acceptances and of the connection-time data-controller and employee-monitoring-notice attestations described in our Terms, AUP, and DPA. Each record includes the document version and the exact text accepted, the date and time, the originating IP address, and the identity of the accepting Authorized User (name and email), together with the Customer's organization name and primary domain. We retain these records, and the identity of the accepting user, after the Customer's account is terminated and after Customer Data is otherwise deleted, to establish that the monitoring was authorized and consented to and to establish, exercise, or defend legal claims. Our legal basis is our legitimate interest, and where applicable the establishment, exercise, or defense of legal claims, in keeping a reliable, tamper-evident record of these authorizations. These records contain no Monitored User presence data. They are kept for the period during which a related legal claim could be brought, plus a reasonable margin, and are protected by the same security and access controls as our audit logs.
5.6 Free trial expiry
A free trial collects only the account owner's own Microsoft Teams presence. If the trial ends without an upgrade, the workspace becomes read-only and presence collection stops; the data is retained and remains exportable during a thirty (30) day read-only grace period with a deletion countdown. If the account is not upgraded by the end of that grace period, all trial Customer Data is deleted on the same basis and to the same extent as deletion on cancellation (Section 5.3), and the owner may use the in-application delete control to purge it sooner. Acceptance, attestation, audit, and operational records are retained after deletion as described in Sections 5.2 and 5.5. Only one free trial is available per Microsoft organization in any twelve (12) month period.
6. Your Rights and Choices
6.1 Rights of Authorized Users
Authorized Users have the right to:
- Access their account information
- Correct inaccurate account information
- Request deletion of their account (by transferring or removing themselves through the in-application team management)
- Withdraw from receiving marketing communications
To exercise these rights, sign in to the Service or use our contact form.
6.2 Rights of Monitored Users
Because Customer is the data controller for Monitored User data, requests from Monitored Users to access, correct, delete, or restrict processing of their data should be directed first to Customer.
If a Monitored User contacts Presify directly with such a request, Presify will (a) acknowledge receipt and (b) notify the relevant Customer of the request and forward the request to Customer for handling, except where prohibited by law.
The Service includes per-user data deletion and per-user data export features that Customer administrators can use to comply with Monitored User requests.
6.3 California residents (CCPA / CPRA)
Presify's role. For personal information about Authorized Users that Presify collects to operate and secure the Service (such as account and sign-in information), Presify acts as a "business" under the CCPA and the rights below apply directly. For personal information about Monitored Users, Presify acts as a "service provider" that Processes the information on Customer's behalf; Customer is the "business." Monitored Users should direct CCPA requests to their employer (the Customer) in the first instance, as described in Section 6.2. If a Monitored User contacts Presify directly, Presify will forward the request to the relevant Customer and assist the Customer in responding, except where prohibited by law. Presify's service-provider commitments are set out in the Data Processing Agreement.
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have specific rights:
- Right to know: the right to know what categories of personal information have been collected, the sources of that information, the purposes for collection, and the categories of third parties with whom information is shared. This Privacy Policy provides this disclosure.
- Right to delete: the right to request deletion of personal information, subject to certain exceptions.
- Right to correct: the right to request correction of inaccurate personal information.
- Right to opt out of sale or sharing: Presify does not sell personal information for money. If you consent to advertising cookies on our public website, the Google Ads cookies we then set may constitute "sharing" of personal information for cross-context behavioral advertising under the CCPA/CPRA. You can opt out at any time, and decline by default, using the "Your Privacy Choices" control in the site footer (turn off the Advertising category), and we honor the Global Privacy Control (GPC) signal as a valid opt-out of sharing. This applies to our public website only; data processed inside the signed-in Service on a customer's behalf is never sold or shared (see the Data Processing Agreement).
- Right to limit use of sensitive personal information: Presify does not collect sensitive personal information beyond what is required for authentication and service operation.
- Right to non-discrimination: Presify will not discriminate against any California resident for exercising any of these rights.
Opt-out preference signals. Presify honors the Global Privacy Control (GPC) signal. When your browser sends a GPC signal, we treat it as a request to opt out of any non-essential cookies for that browser and do not set our first-party signup-attribution cookie. You can also manage non-essential cookies any time using the "Your privacy choices" control in the site footer.
To exercise these rights, submit a request using our data request form, or use the "Your Privacy Choices" control in the site footer to opt out of advertising cookies. Presify will verify the requester's identity before fulfilling the request. We will respond within forty-five (45) days as required by California law. Where reasonably necessary, we may extend this period by an additional forty-five (45) days and will notify you of the extension and the reason for it. You may use an authorized agent to submit a request on your behalf, subject to identity and authority verification.
6.4 European Economic Area, United Kingdom, Switzerland, and Canada
Presify is designed for organizations with employees located in the United States. The Service is operated entirely on infrastructure located in the United States.
If Customer has employees based in the European Economic Area, the United Kingdom, or Switzerland, Customer should contact us before attempting to enroll them as Monitored Users. Compliance with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection (FADP) for individuals in those regions is on our roadmap but is not currently supported in the v1 Service offering. We do not currently have Standard Contractual Clauses or other approved transfer mechanisms in place for data from those regions. Presify likewise does not support monitoring individuals located in Canada; compliance with Canadian privacy laws (PIPEDA and Quebec Law 25) is not currently offered, and Canadian users are excluded on the same basis.
The Service enforces this boundary technically: a directory user whose Microsoft 365 location is in the European Economic Area, the United Kingdom, Switzerland, or Canada cannot be enrolled as a Monitored User, and if a Monitored User's directory location later changes to one of those regions, monitoring of that user stops automatically.
7. Data Security
We take commercially reasonable measures to protect personal information, including:
- Encryption of data at rest using AES-256 within AWS storage services
- Encryption of data in transit using TLS 1.2 or higher
- Multi-factor authentication for personnel with administrative access to production systems
- Role-based access controls with least-privilege design
- Database access gated by IAM-authenticated, short-lived credentials with no stored database password, over certificate-pinned TLS, with database login activity continuously monitored
- Audit logging of administrative actions
- Vulnerability scanning and security monitoring via AWS GuardDuty, Inspector, and Security Hub
- Bounded data retention per Customer subscription tier
- Append-only audit logs with row-level security enforcement at the database layer
- Sub-processor due diligence and written data protection terms
No security measure is perfect. While we work to protect personal information, we cannot guarantee absolute security.
8. International Data Transfers
The Service is operated entirely in the United States. By using the Service, Authorized Users acknowledge that their information will be transferred to, stored in, and processed within the United States. The data protection laws of the United States may differ from those of the user's country of residence.
For Customers with employees based in the European Economic Area, the United Kingdom, or Switzerland, see Section 6.4.
9. Children's Privacy
The Service is not designed for or directed at children under thirteen (13). We do not knowingly collect personal information from children under thirteen. If you believe a child under thirteen has provided personal information to us, please contact us through our contact form and we will take appropriate action.
10. HIPAA
The Service is not designed to be used as part of a HIPAA-regulated workflow. Presify is not a HIPAA Business Associate. Customers must not use the Service to process Protected Health Information (PHI). See the Terms of Service for additional details.
11. Cookies and Tracking Technologies
The signed-in Service uses only strictly necessary, first-party cookies. Our public website additionally uses Google Analytics and Google Ads cookies, but only after you consent. We group cookies into three categories, summarized below. For the complete, current list of the specific cookies we set, with their purposes and durations, and to manage or withdraw your choices, see our Cookie Policy.
Strictly necessary cookies (always active; required for the Service to function; no consent needed):
- Authentication session cookie (
__Secure-next-auth.session-token): identifies your authenticated session (encrypted; split into numbered chunks when large) and is removed when the session expires (8 hours). - CSRF protection cookie (
__Host-next-auth.csrf-token): prevents cross-site request forgery during sign-in, the OAuth callback, and impersonation flows. Cleared at the end of the browser session. - Sign-in return cookie (
__Secure-next-auth.callback-url): remembers where to send you after sign-in. Cleared at the end of the browser session. During the Microsoft sign-in handshake we also set two short-lived cookies (a PKCE verifier and a state value) that are deleted as soon as sign-in completes. - Privacy choice cookie (
presify_consent): records your cookie preferences so we can honor them on future visits. Expires after one year.
When you proceed to payment you are redirected to Stripe's hosted checkout; Stripe sets its own cookies on its domain under its own cookie policy, and we do not set payment cookies on our site.
Analytics cookies (off until you allow the Analytics category):
- Signup attribution cookie (
presify_utm): a first-party cookie that carries UTM parameters across the sign-in redirect so we can attribute a signup to its source. Expires after 10 minutes. - Google Analytics (
_ga,_ga_*): first-party cookies set by Google Analytics 4 to measure traffic to our public website. Typically expire after up to two years. We use Google Consent Mode, so these load only after you allow the Analytics category.
Advertising cookies (off until you allow the Advertising category):
- Google Ads (
_gcl_au,_gcl_aw,_gcl_gb, and cookies set by Google on its own domains): used to measure advertising and conversions on our public website, including recognizing when a visit started from one of our ads. Allowing these may constitute "sharing" of personal information for cross-context behavioral advertising under the CCPA/CPRA; keeping the Advertising category off is your "Do Not Sell or Share" opt-out. - Microsoft Advertising (
_uetsid,_uetvid): Universal Event Tracking cookies used to measure advertising and conversions on our public website. They load only after you allow the Advertising category (we send Microsoft a denied consent signal otherwise), and the same CCPA/CPRA "Do Not Sell or Share" opt-out applies. - LinkedIn (
li_fat_id,ln_or): LinkedIn Insight Tag cookies used to measure advertising conversions and build advertising audiences for our public website. The tag loads only after you allow the Advertising category (with no allowance, nothing loads and no LinkedIn cookie is set), and the same CCPA/CPRA "Do Not Sell or Share" opt-out applies.
Your choices and opt-out preference signals. The Analytics and Advertising categories are off until you allow them. You can allow or reject each when you first visit, and change your choice any time via the "Your Privacy Choices" control in the site footer. We also honor browser opt-out preference signals: if your browser sends a Global Privacy Control (GPC) signal, or a legacy Do Not Track (DNT) signal, we record that as a rejection of both categories and do not set any non-essential cookie for that browser. We keep a short record of each consent choice (a randomly generated identifier, the choice, and the time) so we can demonstrate that consent was given; this record contains no name, email, or IP address. When you reject or withdraw your consent, we also delete the Google Analytics, Google Ads, Microsoft Advertising, and LinkedIn cookies we had set in your browser, rather than leaving them to expire on their own (the short-lived signup-attribution cookie is not deleted this way because it expires on its own within minutes).
None of these analytics or advertising cookies are ever used inside the signed-in Service; they appear only on our public marketing website.
12. Third-Party Links and Services
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage users to review the privacy policies of any third-party services they interact with.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to Authorized Users by email at least thirty (30) days before they take effect. The updated policy will be posted at https://presify.io/legal/privacy with an updated Effective Date. Continued use of the Service after the effective date constitutes acceptance.
14. Contact Us
For questions, concerns, or to exercise any rights described in this Privacy Policy:
Presify, LLC, a Florida limited liability company Privacy and CCPA requests: our data request form at https://presify.io/contact/data-request Email: legal@presify.io (legal notices) Web: https://presify.io
Last updated: June 27, 2026