Privacy Policy

Effective Date: September 3, 2026

Publisher: Realizer Services Inc. | Contact: privacy@realizer.io

1. Introduction

This Privacy Policy describes how Realizer Services Inc. ("Realizer", "we", "us", "our") collects, uses, stores, and protects information in connection with AccessPoint, our access-to-information and privacy management solution for Microsoft 365 and Azure ("the App").

AccessPoint is designed with a data sovereignty model: customer data is stored and processed entirely within the customer's own Microsoft Azure subscription and Microsoft 365 tenant. Realizer does not host, store, or have standing access to customer data.

This policy covers three contexts:

2. Data Controller and Data Processor Roles

3. Information Collected via the Website

3.1 Information You Provide

We collect information that you voluntarily provide, including:

3.2 Automatically Collected Information

When you visit our website we use Google Analytics 4 to understand which pages are read and how visitors arrive. It records the pages you view and how long you stay, the site or search engine that referred you, your browser and device type, and an approximate location derived from your IP address; Google Analytics 4 does not log or store IP addresses. We have turned off Google signals and every advertising feature, so nothing is used for advertising and no profile is built across other websites. Visitors in the European Economic Area, the United Kingdom and Switzerland are asked before analytics cookies are set; elsewhere two first-party cookies (_ga and _ga_ followed by our property identifier) distinguish returning visitors. You can opt out on any device by opening any page of this site with ?ga=off added to the address, for example realizer.io/?ga=off, and ?ga=on turns it back on. The site sets no other tracking cookies.

4. Data Processed by the App (Customer Environment)

All of the following data is stored and processed exclusively within the customer's own Azure subscription and Microsoft 365 tenant. Realizer does not have access to this data.

4.1 User Identity Data

4.2 Case Data

4.3 Documents and Recordings

Email conversion. When an email file is converted for preview, the customer's API fetches remote images the message references (at most 25 images of up to 4 MB each, over an SSRF-hardened client with an 8-second timeout) so the rendered PDF matches what the recipient saw, then renders the page offline so that nothing — including tracking pixels — contacts the network during rendering. The image hosts named in the email therefore see a request from the customer's App Service at conversion time; no other party sees the message. Attachments are extracted into child documents by default (tenant toggle Features:ExtractEmailAttachments).

4.4 Configuration Data

4.5 Records Captured from Microsoft 365

The Documents workspace lets a signed-in user add records from their own Microsoft 365 content. Every capture is initiated by the user, gated by the tenant toggle Features:M365CaptureEnabled (with separate toggles for the request and assignment workspaces), and stored as an ordinary document in the customer's Blob Storage. Which identity performs the read matters for privacy, so each source is listed with its token:

SourceWhat is capturedToken usedNotes
Outlook email ("My Email", shared/intake mailboxes)Selected messages, downloaded as .eml filesThe user's delegated token (Mail.Read, Mail.Read.Shared)Exchange mailbox permissions still apply — a user sees only mailboxes they already hold access to
Outlook calendarA date window of the user's own (or a shared) calendar, rendered as one day-grouped schedule recordThe user's delegated token (Calendars.Read, Calendars.Read.Shared)Items whose sensitivity is Private, Personal, or Confidential are excluded by default (opt-in). Attendees and location are included by default; descriptions and meeting join links are off by default. The record carries a banner noting the exclusion and that attendee names are third-party personal information subject to review
Teams chats and channel messagesThe user's own chat and channel conversations, rendered as transcriptsThe user's delegated token (Chat.Read, ChannelMessage.Read.All, Team.ReadBasic.All, Channel.ReadBasic.All)Only conversations the user is a member of
OneNotePages from the user's notebooksThe user's delegated token (Notes.Read, Notes.Read.All)
SharePoint lists and filesLists rendered as records; files copied from sites and OneDriveThe user's delegated token (Sites.Read.All, Files.Read.All)SharePoint permissions still apply
Teams meeting recordings and transcriptsRecordings of meetings the user organized, with the Teams-generated transcriptThe user's delegated token (OnlineMeetingRecording.Read.All, OnlineMeetingTranscript.Read.All, OnlineMeetings.Read)Graph lists recordings for the organizer only. The MP4 is downloaded through the user's browser into the upload queue and uploaded to the customer's API; the Teams WebVTT transcript is imported with it and is treated as authoritative — the recording is never re-transcribed. Nothing transits the publisher
Microsoft 365 Copilot interaction historyThe user's own Copilot conversations, grouped by session, rendered as transcriptsThe API's application permission (AiEnterpriseInteraction.Read.All) — there is no delegated permission for this dataRetrieval is performed server-side by the customer's API and is always scoped to the signed-in user's own Entra object ID, never tenant-wide. Requires the user to hold a Microsoft 365 Copilot licence. The permission is granted by default at setup with an opt-out

Captured records are converted to PDF in the customer's App Service, stamped with their source (for example "Email Export", "Calendar Export", "Teams Meeting Recording", "Copilot Export"), and are indistinguishable from manual uploads thereafter.

4.6 Optional Azure Services

Customers may deploy the following services within their own Azure subscription by setting a deployment parameter. Each is provisioned by the same template as the rest of AccessPoint, in the customer's resource group, and each authenticates with the App Service's managed identity only — local authentication and API keys are disabled on every account that supports it (disableLocalAuth). None of them is required; an undeployed service simply leaves its feature unavailable. Document and case content processed by them does not leave the customer's Azure environment and is never sent to Realizer.

4.6.1 Azure OpenAI (AI Assist)

4.6.2 Azure AI Search (content and semantic search)

4.6.3 Azure AI Document Intelligence (OCR)

4.6.4 Azure AI Speech (transcription of recordings)

4.6.5 Microsoft Defender for Storage (malware scanning)

4.6.6 Media processing worker (Azure Container Apps)

4.6.7 Application Insights and Log Analytics (always deployed)

4.7 Privacy by Design

AccessPoint enforces role-based data access:

5. Data Processed by Realizer (Platform Services)

Realizer's Platform services process a limited set of data to support licensing, Teams notifications, jurisdiction packs, first-time setup, Teams tab routing, and software distribution. Email notifications, the in-app notification feed, documents, case records, AI prompts, and search indexes never transit Realizer.

5.1 License Validation

When the App starts and periodically during use, the customer's API sends a request to Realizer's Platform API (api.realizer.io) to validate the customer's subscription. While a licence is invalid the API backs off (five minutes, doubling) rather than polling continuously.

Data transmitted:

The request authenticates with a Microsoft Entra token issued to the customer's App Service managed identity, which carries a License.Validate role on Realizer's application; the token's tenant claim identifies the customer. A legacy static API key remains supported as a fallback for un-migrated deployments.

Data NOT transmitted:

Purpose: To verify that the customer has an active AccessPoint subscription. The response also carries the latest published AccessPoint version number (and, optionally, a link to the update template) so the App can show administrators an "Update available" notice. Realizer's Platform determines that number by reading its own release marker (get.realizer.io/public/accesspoint/latest/version.txt); the customer's API does not contact the distribution site for this.

Data stored: one licence-token record per tenant and subscription (replaced on each validation; revoked records are retained as an audit trail), the tenant's subscription status, and the self-registered API base URL on the tenant record.

Retention: Tenant ID and license status are retained for the duration of the subscription plus 90 days after expiration for billing reconciliation. The self-registered API base URL is stored as part of the tenant's subscription record.

5.2 Teams Activity Feed Notifications

Teams activity feed notifications are optional and default to on. In the default mode, when a notification is triggered (e.g., a custodian is assigned new work), the customer's API sends a request to Realizer's Platform API, which sends the notification via Microsoft Graph on behalf of the customer's tenant. This relay exists because Graph requires that activity notifications be sent by the application that owns the Teams app manifest, and AccessPoint's Teams app is published under Realizer's multi-tenant application.

Data transmitted (default relay mode):

FieldContainsPersonal data?
tenantIdCustomer tenant GUIDNo — identifier
recipientUserIdRecipient's Entra user object IDNo — identifier
activityTypeA fixed manifest value (e.g., assignmentCreated)No
previewTextAssignment or task name and due datePotentially — free text
topicTextThe in-app notification textPotentially — free text
templateParameters.actorNameDisplay name of the staff member who triggered the notificationYes — a personal name
templateParameters.requestNumberRequest reference number (request-anchored types only)No — reference
relatedEntity, relatedRecordIdRecord type and GUID for the click-through deep linkNo — identifiers

Data NOT transmitted:

Two controls reduce or eliminate this flow:

  1. Minimise — the tenant setting Notifications:TeamsMinimalPayload (Settings → Setup → Teams Notifications → "Minimise Teams notification content") replaces previewText, topicText, and actorName with fixed placeholders ("AccessPoint Notification", "You have a new AccessPoint notification", "AccessPoint"). No free text or personal name leaves the tenant; only routing identifiers do.
  2. Direct relay — the app setting Notifications:TeamsRelayMode=Direct makes the customer's API call Graph itself with its managed identity, so nothing reaches Realizer. It requires the TeamsActivity.Send role on the customer's managed identity and a Teams manifest pointed at the customer's own application (User Guide, Step 8e).

Turning Teams notifications off in the Setup panel also eliminates the flow; email and in-app delivery of the same notifications are always in-tenant.

Purpose: To deliver Teams activity feed notifications.

Data stored: none. The Platform logs the tenant and recipient identifiers of each relayed notification for troubleshooting.

Retention: Notification metadata is retained in transit logs for 30 days for troubleshooting purposes, then automatically deleted.

5.3 API Address Discovery

When the SharePoint web part loads and no manual API-address override is configured in the tenant, it calls the Platform's api-discovery endpoint to look up the customer API address that the licence validation self-registered (Section 5.1).

Data transmitted: a Microsoft Entra bearer token issued to the signed-in user for Realizer's application — the same token the web part uses to call the customer's own API. The Platform reads only the token's tenant claim to select the record; it does not store the token or the user's identity.

Data returned: the customer's own API base URL.

Data stored: none beyond the tenant record already described in Section 5.1. The Platform logs the tenant ID and whether a URL was found.

5.4 Teams Personal Tab Routing and First-Time Setup

Teams tab routing. The AccessPoint Teams app's personal tab opens through a Platform address (api.realizer.io/apps/accesspoint/redirect-to-sp) that decides whether the tenant has AccessPoint installed and redirects the user's browser to their own SharePoint site (or to a welcome page when it does not). This design is required by how Teams desktop establishes single sign-on with SharePoint.

Finish Setup page. After a template deployment, an administrator may open the Platform's Finish Setup page (api.realizer.io/apps/accesspoint/setup) to grant the Microsoft Graph permissions the App's managed identity needs (Section 8.1), instead of running the deployment script.

5.5 Jurisdiction Packs

Jurisdiction packs (jurisdiction-specific templates, exemptions, holidays, notification templates, and detection rules) are downloaded from the Platform on request by an administrator. Each download and each installation report authenticates as in Section 5.1.

5.6 Software Distribution

AccessPoint's installable artifacts are published to Realizer-operated endpoints. Fetching them reveals ordinary request metadata to Realizer — the artifact and version requested, the connecting IP address, and the time — and nothing else.

5.7 Summary — What Realizer Receives, and When

FlowWhenWhat Realizer receivesContains personal data?How to eliminate
License validationStartup and periodicallyTenant ID, API version, API base URLNoNot applicable (required for licensing)
Teams activity relayEach Teams notification (default mode)Tenant and recipient GUIDs, activity type, request number, record ID; plus title, preview text, and acting user's name unless minimisedActing user's name and free text unless minimisedMinimise toggle, Direct relay mode, or disable Teams notifications
API address discoveryWeb part load (when no override and cache expired)User's bearer token (tenant claim read; not stored)Token only, transientlyConfigure the manual AccessPoint_ApiUrl storage-entity override
Teams tab routingEach time the Teams personal tab is openedSharePoint domain, tenant ID, localeNoUse AccessPoint from SharePoint rather than the Teams tab
Finish Setup pageOnce per setup or upgrade, by an administratorTenant ID, managed identity ID, administrator's delegated token (transient)Administrator identity, transientlyUse Deploy-AccessPoint.ps1 instead
Jurisdiction packsOn administrator requestTenant ID, pack code, item types, installing user IDInstalling administrator's object IDDo not import packs (universal baseline is imported automatically)
Artifact downloadsDeployment and upgradeVersion requested, IP address, timeNoNot applicable
Container image pullEach media-worker scale-up (default image)Image tag, IP address, time, pull cadenceNoMirror the image into the customer's own registry
Email notificationsNever———

6. Data We Do NOT Collect

Realizer does not collect, store, or have access to:

7. Data Storage and Security

7.1 Customer Data (App)

7.2 Platform Data (Realizer)

7.3 Website Data

8. Third-Party Data Sharing

Realizer does not sell, rent, or share customer data with third parties.

The third-party services involved in data processing are:

8.1 Microsoft Graph API

AccessPoint reads and writes Microsoft 365 data through Microsoft Graph under three sets of permissions. All Graph calls are made from the customer's tenant (by the signed-in user's browser or by the customer's API) except the Teams activity relay described in Section 5.2.

Application permissions on the customer's App Service managed identity — granted by the administrator via the Finish Setup page or Deploy-AccessPoint.ps1; used by the customer's API without a signed-in user:

PermissionPurposeWhat is read or sent
Mail.SendSend notification emails from the configured shared mailboxNotification content, from the customer's mailbox to the recipient — never via Realizer. Can be scoped to a mailbox group with an Exchange application access policy
User.ReadBasic.AllValidate that the shared mailbox exists; resolve notification recipientsBasic profile fields (name, email) only; no mailbox contents
TeamsAppInstallation.ReadForUser.AllCheck whether the AccessPoint Teams app is installed for a recipient before sending a Teams notificationThe recipient's installed-apps list, filtered to AccessPoint
Application.Read.AllTeams setup validation — confirm Realizer's application is consented in the tenantService principal metadata; read-only
AppCatalog.Read.AllTeams setup validation — confirm the AccessPoint Teams app is in the organization's catalogCatalog metadata; read-only
AiEnterpriseInteraction.Read.All"Add from Microsoft 365 → Copilot" capture (Section 4.5)The signed-in user's own Copilot interaction history — the API always scopes the call to that user's object ID. Granted by default; opt out at setup (-DisableCopilotCapture, or the Finish Setup checkbox)
TeamsActivity.Send (optional)Only when the customer adopts the Direct relay mode (Section 5.2)Teams activity notifications sent by the customer's own identity

The managed identity also holds the non-Graph License.Validate role on Realizer's application (Section 5.1).

Delegated permissions requested by the SharePoint package — approved by a SharePoint administrator; exercised in the signed-in user's browser with the user's own identity, so the user can never read more than they already can in Microsoft 365:

PermissionPurpose
User.Read.AllPeople picker, user search and resolution
Sites.Read.AllSharePoint site browsing and Lists capture
Files.Read.AllFile browsing and capture from sites and OneDrive
Mail.ReadEmail capture and preview from the user's own mailbox
Mail.Read.SharedEmail capture from shared and intake mailboxes the user already has access to
Calendars.ReadCalendar capture (Section 4.5)
Calendars.Read.SharedCalendar capture from shared mailboxes
Chat.ReadTeams chat capture
ChannelMessage.Read.AllTeams channel message capture
Team.ReadBasic.All, Channel.ReadBasic.AllListing the user's teams and channels for capture
Notes.Read, Notes.Read.AllOneNote capture
OnlineMeetingRecording.Read.AllListing and downloading recordings of meetings the user organized (Section 4.5)
OnlineMeetingTranscript.Read.AllDownloading the Teams transcript of those meetings
OnlineMeetings.ReadReading the meeting metadata needed to list recordings
access_as_user (Realizer's application)The token audience for calls to the customer's own API and to the API address discovery endpoint (Section 5.3); not a Graph permission

Realizer's multi-tenant application — consented by the customer's administrator; operated by Realizer for the Teams relay only:

PermissionPurpose
TeamsActivity.SendSend Teams activity feed notifications on behalf of AccessPoint (Section 5.2). Cannot read Teams messages, channels, or any other tenant data
AppCatalog.Read.AllResolve the Teams app's catalog identifier so the notification carries the AccessPoint icon; read-only
User.ReadBasic sign-in scope

8.2 Realizer Platform API

Used to validate the subscription, relay Teams notifications, discover the API address, route the Teams tab, finish setup, and download jurisdiction packs — each described in Section 5 with the exact data transmitted.

8.3 Microsoft Azure (optional services)

Azure OpenAI, Azure AI Search, Azure AI Document Intelligence, Azure AI Speech, Microsoft Defender for Storage, Azure Container Apps, and Application Insights — when the customer chooses to deploy them, these are Azure resources inside the customer's own Azure subscription under the customer's agreement with Microsoft; document and case content processed by them does not leave the customer's Azure environment and is never sent to Realizer (see Section 4.6).

8.4 Other

No data is transmitted to any other third-party service. Syncfusion document conversion and PDF rendering libraries run entirely within the customer's App Service — no document content is sent externally. The Syncfusion PDF viewer loads JavaScript/CSS assets from cdn.syncfusion.com in the browser, but no document content is transmitted. The face-detection and region-tracking models used for video redaction ship inside the application and call no external service. The only other outbound connections the App makes are the email image fetches described in Section 4.3 and the artifact and image downloads described in Section 5.6.

9. Data Retention and Deletion

9.1 Customer Data

Data retention is fully controlled by the customer:

9.2 Platform Data

9.3 Website Data

Contact form submissions and demo requests are retained for the duration of the business relationship. You may request deletion at any time.

10. Data Subject Rights

10.1 For End Users of the App

Requests related to personal data processed within AccessPoint (access, correction, deletion, portability) should be directed to the customer organization that deployed AccessPoint, as they are the data controller.

10.2 For Customer Organizations

As the data controller, customers can:

10.3 For Website Visitors and Platform Data

You have the right to:

To exercise these rights, or to request access to, correction of, or deletion of the limited data Realizer processes (tenant ID, license records, pack installation records), contact privacy@realizer.io.

11. International Data Transfers

12. Children's Privacy

AccessPoint is an enterprise business application. It is not directed at children and does not knowingly collect personal data from children under the age of 16.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through:

14. Contact

For questions about this Privacy Policy or AccessPoint's data practices:

Realizer Services Inc. Email: privacy@realizer.io Website: realizer.io/privacy

15. Change History