Privacy Policy
Last updated 19 July 2026
This policy explains how Daisy Chain Consulting (Pty) Ltd (“we”, “us”), operating Workspace Audit, handles data when you use the service. It is written to align with the GDPR, the UK GDPR, South Africa's POPIA and, for education customers, FERPA.
What we access
When you connect a Google Workspace account, we use read-only OAuth 2.0 scopes to read security configuration and metadata only — see our Security page for the exact scopes. We never read the contents of emails, Drive files, calendar events or chat messages, and we can never change a setting.
What we store
- Your sign-in identity (name, email address, Workspace domain).
- Scan results: the security findings, their status and severity, and a health score over time.
- We do not store your Google password. Your Google access and refresh tokens are held in your encrypted session so we can run scans on your behalf; they are never exposed to your browser.
How we use it
To produce your security audit, show it in the dashboard and reports, and track your posture over time. We do not sell your data, and we never use it to train any AI model.
Your security findings are yours. We do not pool them, aggregate them, or use them to benchmark other customers. Any comparison we ever show you is drawn from the public domain grade described below, never from another organisation's audit.
The free public domain grade
Anyone can grade a domain's email security at /scan without signing in. That check reads public DNS records (SPF, DKIM, DMARC, MTA-STS) only — nothing private, and nothing belonging to an account.
- We keep one record per domain checked: a keyed cryptographic hash of the domain name and the resulting score, so we can report how domains compare in general (for example “better than 70% of domains we have measured”).
- We do not record who ran the check — no IP address, no browser details, no account, no identity of any kind. We cannot tell who looked up which domain, and neither can anyone who obtained the data.
- The domain name itself is not stored in readable form; the hash is keyed with a secret we hold server-side.
Retention & deletion
We retain scan data while your account is active so you can see your history. You may request deletion of your data at any time by emailing darren@dcai.co.za; we will delete it within 30 days. On account closure we delete your data within 90 days.
Sub-processors
We use a small set of infrastructure providers to run the service — see our sub-processor list.
Your rights
You may request access to, correction of, or deletion of your personal data, and may object to or restrict processing. Contact us at darren@dcai.co.za.
Contact
Daisy Chain Consulting (Pty) Ltd, South Africa — darren@dcai.co.za.
This document is provided in good faith and is subject to final legal review; contact us if you require a countersigned version for procurement.