PPM Compass Logo
PPM Compass 360 For Microsoft 365
🛡️ In-Tenant Data Sovereignty

Privacy Policy

Effective Date: October 1, 2026 • Product: PPM Compass 360 (SPFx Solution Package: ppm-compass-360.sppkg)

đź”’ Core Architectural Privacy Guarantee

PPM Compass 360 is built as a 100% in-tenant client-side SharePoint Framework (SPFx) application. We do not host external servers, databases, or API proxies. Zero customer data, zero project records, zero financial data, and zero personal information ever leave your Microsoft 365 tenant boundary.

1. Introduction & Overview

This Privacy Policy describes how PPM Compass 360 ("the Application", "we", "us", or "our") processes data when deployed as a SharePoint Framework (SPFx) solution web part within your organization’s Microsoft 365 SharePoint Online environment.

We believe privacy is an architectural decision. By engineering PPM Compass 360 entirely on client-side SPFx technology using standard SharePoint REST APIs, we ensure that your organization retains absolute data ownership, residency, and privacy control at all times.

2. Data We Do NOT Collect (Zero Egress Statement)

Unlike traditional SaaS or multi-tenant cloud PPM products, we do NOT collect, transmit, store, or process any of the following on external infrastructure:

  • No Project Content: Project names, descriptions, charters, status summaries, milestone dates, financials, change requests, risks, or issue registers remain strictly inside your SharePoint lists.
  • No User Identification (PII): We do not collect user email addresses, Microsoft Entra ID (Azure AD) tokens, phone numbers, or employee directory profiles.
  • No Telemetry or Usage Tracking: The Application contains no third-party analytics SDKs (e.g., Google Analytics, Mixpanel, Segment), no tracking beacons, and no heartbeat pings.
  • No External Alerting Infrastructure: The Application does not route notification emails or alerts through external mail relays. All workflows leverage your native Microsoft 365 Power Automate licenses.

3. Data Storage & Residency

All data generated or managed by PPM Compass 360 is stored exclusively in standard, native SharePoint Online lists provisioned directly inside your own organization's SharePoint site collection (such as project registers, milestone schedules, risk logs, change records, monthly financials, and team resource allocations).

All data objects reside strictly within your tenant's chosen Microsoft 365 geographic data boundary (e.g., European Union, United States, Canada, United Kingdom, Australia) under your organization's existing Microsoft enterprise agreement, compliance center, access controls, and retention policies. No data is ever transmitted to or stored in external databases.

4. Native SharePoint Groups & Least-Privilege Security

PPM Compass 360 enforces the principle of least privilege across your SharePoint environment using native group architecture:

  • Dedicated Communication Site Architecture: New deployments are provisioned on a dedicated SharePoint Communication Site. This ensures clean isolation of standard SharePoint Owners, Members, and Visitors groups without associated Microsoft 365 Group, mailbox, or Teams sprawl.
  • Contribute Without Delete for Editors: Users assigned as Site Members (Project Leaders, sponsors, deputies, and team contributors) receive write and edit permissions on operational lists, but cannot delete records ("Contribute Without Delete").
  • Read-Only Access for Visitors: General stakeholders and readers assigned as Site Visitors have read-only access. Site Owners can configure whether Visitors have visibility into executive financial figures.
  • Exclusive Deletion Rights: Deletion rights, configuration list modifications, and administrative settings are restricted exclusively to Site Owners.
  • Item-Level Preference Isolation: Personal view preferences and user settings are protected with item-level permissions, ensuring each user can only read and write their own preferences.

5. Client-Side Browser Execution & Local Storage

When users view the PPM Compass 360 web part, JavaScript executes locally inside their authenticated browser session:

  • Session Execution: Data queries are made directly from the user's browser to your SharePoint site using the user's existing Microsoft 365 session credentials.
  • Local Preferences: The application stores non-sensitive UI preferences (such as language, selected portfolios, saved filters, column widths and zoom level) in the browser's localStorage. This data stays on the user's device.
  • Exports: Excel, PowerPoint and PDF exports are generated in the browser and saved to the user's device. They are never sent to PPM Compass; exported files are handled under your organization's own policies.
  • No Third-Party Cookies: The application does not deploy advertising, marketing, or cross-site tracking cookies.

6. Artificial Intelligence & Microsoft Copilot

PPM Compass 360 does not send data to public AI models or external LLM endpoints.

If your Project Leaders choose to export project snapshots as Excel (.xlsx) files to analyze them with Microsoft 365 Copilot, ChatGPT Enterprise, or custom Copilot Studio agents, those interactions are governed exclusively by your organization's commercial agreement with Microsoft or your designated AI provider. Production SharePoint data remains protected and untouched by AI write operations.

7. GDPR & Data Protection

Under the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), UK GDPR, and comparable international data privacy frameworks:

  • Customer as Data Controller: Your organization acts as the sole and exclusive Data Controller for all personal data, employee assignments, and project records managed within your SharePoint environment.
  • No Processing of Customer Data by Licensor: PPM Compass 360 runs client-side in the user's browser against native SharePoint Online REST APIs. Licensor does not receive, host, access or transmit Customer Data stored in SharePoint. Whether your organization needs a Data Processing Agreement is for you to assess; we will support that review on request.
  • Zero Sub-processors for Customer Data: Licensor engages zero third-party sub-processors or cloud relays to handle your project records or team allocations.
  • Data Subject Rights & Sovereignty: Because all records reside in standard SharePoint Online lists within your specified geographic tenant boundary, your Microsoft 365 administrators retain full and immediate capability to execute data subject access requests (DSARs), rectifications, exports, or erasures using native Microsoft 365 compliance tools.

8. Data Retention & Deletion

Because we host no external database, we retain none of your operational data. If your organization removes the PPM Compass 360 web part from a page or uninstalls the ppm-compass-360.sppkg solution from the SharePoint App Catalog, your project data remains safely in your SharePoint lists under your control until your administrators choose to delete the site or lists.

9. Marketing Website Inquiries & License Key Generation

If you contact us via email, submit an inquiry for a commercial quote, or request a license key through our website, we collect only the contact details you voluntarily provide (name, business email, organization name) solely to respond to your inquiry and deliver your signed cryptographic license key. We never sell, rent, or trade your contact information.

9b. This Website: Analytics, Cookies & Service Providers

This section covers ppmcompass.com only. The PPM Compass 360 app contains no analytics or tracking (see sections 2 and 5).

  • Microsoft Clarity (analytics): If you click Accept in the cookie banner, we use Microsoft Clarity to see how visitors use our pages (clicks, scrolling, session replays, device and browser type). Clarity sets cookies and processes this data on Microsoft's servers under Microsoft's privacy statement. If you click Reject, Clarity is not loaded. You can change your choice at any time with Cookie settings in the footer.
  • Contact and trial forms: Form submissions (name, business email, organization, message) are delivered to us through Web3Forms and, on one form, Formspree. These services pass the message on to our mailbox.
  • Page styling and fonts: Styles and fonts are served from this website. No third-party font or style service is used.
  • Browser storage: We store your cookie choice in your browser's local storage so that we do not ask again.

10. Commercial Orders, Payment Processing & Merchant of Record

When purchasing commercial licenses, site subscriptions, or consulting services, transactions and invoicing may be fulfilled directly by MonVogo Ventures Inc. or through an authorized Merchant of Record (MoR) platform (such as Paddle.com or Stripe):

  • Merchant of Record Role: Where an MoR is utilized, the MoR acts as the merchant of record for payment card processing, checkout handling, currency conversion, and global sales tax/VAT remittance.
  • PCI-DSS Level 1 Compliance: Payment card details, billing addresses, and tax identifiers (VAT/GST numbers) are processed directly by the certified PCI-DSS Level 1 compliant Merchant of Record under their independent privacy policy and security standards.
  • Zero Card Data Stored: PPM Compass 360 and MonVogo Ventures Inc. never receive, store, or process complete credit card numbers or sensitive banking credentials.

11. Contact Information & Corporate Identity

For any privacy questions, security reviews, or compliance verifications regarding PPM Compass 360, please contact our corporate desk:

MonVogo Ventures Inc. (Operating as PPM Compass 360)

Ottawa, ON, Canada

Corporate Jurisdiction: Ontario, Canada

Email: contact@ppmcompass.com

Support Desk: support/index.html