Last updated: 18 August 2026
Xyron Holding B.V., trading as Tenvero, registered in the Netherlands under CoC number 99553333, is the controller for the personal data described in this policy. Contact:[email protected].
Tenvero runs on your own workstations and administers your own Microsoft 365 tenant.Mailbox contents, delegation data, and directory information stay between your workstation and Microsoft. That data is not sent to us and we cannot see it. Where Tenvero does process such data, it does so on your instruction and on your infrastructure — you are the controller and we are not involved in that processing.
We also do not process or store payment card data. Checkout is handled by Stripe, our payment processor; Xyron Holding B.V. is the seller of record for your transaction. Stripe processes payments under its own privacy policy.
When you buy a licence we receive your email address, the tenant identifier the licence is bound to, and subscription status from our payment provider. We use this to issue and validate licences, to provide support, and to meet accounting obligations.
Legal basis: performance of a contract, and legal obligation for accounting records.
The Tenvero client contacts our licensing service to validate a licence. Those requests include the licence key and tenant identifier. We use them to confirm entitlement and to detect misuse.
Legal basis: performance of a contract, and legitimate interest in preventing licence abuse.
If you request a download link we record a one-way hash of your email address, a one-way hash of your IP address, and the version requested. The plaintext address is kept only long enough to deliver the email and is erased as soon as the link is used or expires; the hashes remain so we can rate-limit abuse without retaining who asked.
Legal basis: consent for the email itself, and legitimate interest in preventing abuse.
Messages you send us include your name, email address, and whatever you write. We use them to reply.
Legal basis: legitimate interest in responding to enquiries.
Our services write technical logs containing request paths, status codes, timing, and a request identifier, retained briefly for security and troubleshooting. We deliberately keep personal data out of these logs: email addresses and download tokens are never written to them.
Legal basis: legitimate interest in operating a secure service.
We use a small number of processors, each under a data processing agreement:
Where a processor is outside the EEA, transfers rely on the appropriate safeguards, ordinarily the European Commission's Standard Contractual Clauses.
This website does not set tracking or advertising cookies. Any cookie present is strictly necessary for the site to function. Checkout pages are hosted by Stripe and are subject to its own cookie practices.
Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time.
To exercise any of these, email [email protected]. We respond within one month. If you are unhappy with how we handle your request you may complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
We use encryption in transit, store secrets outside application code, hash identifiers rather than keeping them in the clear where a hash is sufficient, and keep personal data out of logs. No system is perfectly secure, but we design for the smallest useful amount of retained data.
We may update this policy. The date at the top reflects the current version, and we will give notice of material changes by email or on this page.
Xyron Holding B.V., Someren, the Netherlands. Email [email protected].