Privacy statement

Last updated 7 September 2026

The short version for IT administrators. CloudSave360 requests delegated access to Azure Resource Manager. Delegated means it acts as the person who signed in and inherits exactly their permissions — it never holds rights of its own. If that person has Reader, CloudSave360 can only read. We store resource metadata and cost figures needed to produce recommendations. We do not read the contents of your virtual machines, databases, storage accounts or files, and we never sell data.

Who we are

CloudSave360 is operated by TPA Tech Labs. For any question about this statement, or to request deletion of your data, contact [email protected].

What we access in your cloud account

When you connect a subscription, CloudSave360 uses your delegated access to read:

What we never access: the contents of your virtual machines, the data inside your databases, the objects in your storage accounts, your source code, or any personal data your systems process. Nothing in the product reads inside a resource — only the facts Azure reports about it.

When we change anything

CloudSave360 only changes a resource when you have explicitly told it to: by creating a schedule (for example, shut this development VM down at 19:00 on weekdays) or by running one manually. It never acts on a recommendation on its own. Every attempt, successful or failed, is recorded and visible to you.

What we store about you

DataWhy
Name, email address, Microsoft/Google account identifierTo identify your account
OAuth access and refresh tokensTo read your cloud account and run schedules you created. Held encrypted at rest and never shown to anyone.
Resource inventory, cost figures, analysis resultsTo produce and re-display your recommendations
Schedules and the log of each runTo operate automation you set up, and to show you whether it worked
Sign-in events — time, IP address, browserSecurity, and to tell you when your account was last used
Invoices and payment statusBilling and statutory record-keeping

Who else sees it

We do not sell your data and we do not share it with advertisers. It is disclosed only to:

Colleagues from your organisation who sign up with the same email domain are grouped into one customer account and may see shared account data. Personal mailbox domains (gmail.com and similar) are deliberately excluded from that grouping so that strangers are never placed in the same account.

Where it lives, and for how long

Data is stored in Microsoft Azure. We keep it for as long as your account is open. When you close your account, or ask us to delete your data, we remove it within 30 days — except records we are legally required to keep, such as invoices.

Revoking access

You can disconnect a subscription at any time from Settings → Cloud Connections, and your Entra administrator can revoke the application's consent for the whole organisation at any time from the Azure portal. Either action stops all access immediately, including any schedules you created.

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Write to [email protected] and we will respond within 30 days.

Cookies

We use one essential cookie to keep you signed in. Analytics and advertising tags are loaded only if the operator has configured them, and never on the signed-in dashboard.

Changes

If this statement changes materially we will say so on this page and update the date above.

TPA Tech Labs · [email protected] · Terms · Privacy · User guide · Home