Legal

Privacy Policy.

What personal data NetworkDown collects, why we collect it, who we share it with and how long we keep it, including the identity information Microsoft passes to us when you sign in.

Last updated

6 August 2026

This document is a plain-English template. It has not been checked by a solicitor, and it should be reviewed by a qualified legal professional before it is relied upon.

1. About this policy

This privacy policy explains how NetworkDown collects, uses, shares and protects personal data when you visit networkdown.co.uk, sign in to a NetworkDown application, or get in touch with us.

NetworkDown is a business based in the United Kingdom and is the data controller for the personal data described here. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you sign in with a work or school account, your employer or organisation remains the controller of that Microsoft account itself. We are the controller only for the data we hold about you inside our own services.

2. Identity data we receive when you sign in

Several NetworkDown applications use Microsoft Entra ID for sign-in. Rather than asking you to create a new password with us, we ask Microsoft to authenticate you. The first time you sign in, Microsoft shows you a consent screen listing the information that will be shared with us.

We never see, receive or store your Microsoft password, and we cannot access anything in your Microsoft account beyond what you or your organisation have consented to.

The identity data Microsoft passes to us is:

  • your name, as it appears on your Microsoft account, so we can address you correctly in the application;
  • your email address or user principal name, which we use to identify you, to match you to an existing invitation or record, and to contact you about the service;
  • your Microsoft object ID, a unique identifier for your account that we store as the permanent key for your user record so that your access still works if your name or email address changes;
  • your Microsoft tenant ID, which tells us which organisation or directory your account belongs to, so we can apply the right permissions and keep one customer's data separate from another's; and
  • any application roles or group memberships your organisation chooses to release to us, where these determine what you are allowed to see and do.

3. Sign-in and audit logging

We keep an audit log of authentication and security events. Every sign-in to a NetworkDown application is logged, whether it succeeds or fails.

Each audit entry records the account involved, the date and time, the outcome (for example a successful sign-in, a failed sign-in, or a sign-out), the IP address the request came from, and basic browser or device information. We also log significant actions taken inside the application, such as administrative or permission changes.

We keep these logs so that we can protect accounts against unauthorised access, detect and investigate security incidents, resolve disputes about who did what, and meet our own security and accountability obligations. We do not use audit logs to monitor individual productivity.

4. Other data we collect

  • Contact and enquiry data: the name, email address and message content you provide when you email us, use a form on this site, or ask to be notified about a launch.
  • Marketing preferences: the topics you have asked to hear about, and whether you have unsubscribed.
  • Technical data: server logs generated automatically when you visit the site, including IP address, the pages requested, timestamps, referrer and browser user agent.
  • Anti-spam data: information processed by Cloudflare Turnstile when you submit a form, which helps us tell real people apart from automated bots.
  • Service data: any content or configuration you or your organisation enter into a NetworkDown application while using it.

5. Our lawful basis for using your data

Under the UK GDPR we must have a lawful basis for each use of personal data. We rely on the following:

  • Performance of a contract: to create and maintain your account, authenticate you, and provide the applications and services that you or your organisation have asked us to provide.
  • Legitimate interests: to keep our services secure and available, to log and investigate sign-ins and security events, to prevent fraud and abuse, to respond to enquiries, and to run and improve our business. We have considered your interests and rights and consider that this processing does not override them.
  • Consent: to send you launch updates and other marketing emails. You can withdraw your consent at any time, and doing so does not affect processing carried out before you withdrew it.
  • Legal obligation: where we are required to retain or disclose information in order to comply with the law.

6. How we use your data

We use the data described above for the following purposes:

  • To authenticate you and decide what you are permitted to access.
  • To create, maintain and support your user record and your organisation's account.
  • To display your name and email address inside the application, so colleagues can see who took an action.
  • To detect, investigate and respond to security incidents and suspected misuse.
  • To respond to your enquiries and provide customer support.
  • To send you the launch updates you asked for, and nothing else without your consent.
  • To maintain, troubleshoot and improve the reliability and performance of our services.
  • To comply with our legal and regulatory obligations.

We do not use your identity data for advertising, we do not sell personal data, and we do not carry out automated decision-making that produces legal or similarly significant effects.

7. Who we share your data with

We do not sell personal data and we do not share it for advertising. We share it with a small number of providers who process it on our behalf, under contract and only on our instructions:

  • Microsoft, as our identity provider. Microsoft authenticates you, issues the sign-in tokens we rely on, and tells us the identity data listed above. Microsoft processes your data under its own privacy statement and, if you use a work or school account, under your organisation's agreement with Microsoft.
  • Our hosting, database and content delivery providers, who run the infrastructure our sites and applications depend on.
  • Cloudflare, which provides bot protection on our forms.
  • Our professional advisers, and regulators, law enforcement or other authorities where the law requires it.

8. International transfers

We prefer to keep personal data in the UK or the European Economic Area. Some of our providers, including Microsoft, operate globally and may process data outside the UK.

Where that happens, we rely on a safeguard permitted by the UK GDPR, such as UK adequacy regulations or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, so that your data continues to receive an equivalent level of protection.

9. How long we keep your data

We keep personal data only for as long as we need it. In practice that means:

  • Account and identity data (name, email address, Microsoft object ID and tenant ID): for as long as your account is active, and for up to 12 months after it is closed or your access is removed.
  • Sign-in and audit logs: normally 12 months, unless a longer period is needed to investigate an incident or to meet a legal obligation.
  • Enquiry and support correspondence: up to 24 months after our last exchange with you.
  • Marketing sign-ups: until you unsubscribe, after which we keep a minimal suppression record so that we do not contact you again by mistake.
  • Server logs: normally no more than 90 days.

10. How we protect your data

We take appropriate technical and organisational measures to protect personal data, including:

  • Sign-in is delegated to Microsoft Entra ID, so we never handle your password. Multi-factor authentication and conditional access are controlled by you or your organisation in Microsoft.
  • All traffic to our sites and applications is encrypted in transit using HTTPS, with HTTP Strict Transport Security enabled.
  • Data is encrypted at rest by our infrastructure providers.
  • Access to production systems and data is limited to the people who need it, uses least-privilege credentials, and is itself logged.
  • Our sites send strict security headers, including a content security policy, and our applications validate the sign-in tokens they receive from Microsoft.

No system can be guaranteed to be completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours and tell you where we are required to do so.

11. Cookies

This website uses strictly necessary cookies only. We do not use advertising, analytics, profiling or tracking cookies, so there is no cookie banner and nothing for you to opt in or out of.

When you sign in to a NetworkDown application, strictly necessary cookies are used to keep you signed in for the duration of your session and to protect the sign-in process against cross-site request forgery. These cookies are essential: sign-in cannot work without them, and they cannot be switched off.

Cloudflare Turnstile may set a strictly necessary cookie when you submit a form on this site, purely to tell real visitors apart from automated bots.

12. Your rights

Under the UK GDPR you have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate personal data corrected;
  • ask us to erase your personal data where there is no good reason for us to keep it;
  • ask us to restrict how we use your personal data while a concern is resolved;
  • receive certain data in a portable, machine-readable format, or have it sent to another controller;
  • object to processing we carry out on the basis of legitimate interests;
  • withdraw your consent to marketing at any time, using the unsubscribe link in any email or the unsubscribe page on this site; and
  • complain to a supervisory authority.

13. Making a request or a complaint

To exercise any of the rights above, email [email protected]. We will respond within one month, and we may ask you to confirm your identity first. Exercising your rights is free of charge in almost all cases.

If you sign in with a work or school account, requests about the Microsoft account itself should go to your employer or organisation, because they control it. Requests about the data we hold inside our own services should come to us.

If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner's Office at ico.org.uk, or by telephone on 0303 123 1113. We would appreciate the chance to put things right first.

14. Children

Our services are aimed at businesses and are not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Changes to this policy

We may update this privacy policy from time to time, for example if we change how our services work or add a new provider. The “last updated” date at the top of this page shows when it was last changed.

Where a change materially affects how we use your personal data, we will give you reasonable notice on this page or by email.

16. How to contact us

For any question about this policy, or to make a data protection request, email us and we will come back to you. We are based in the United Kingdom.

[email protected]