Legal

Privacy Policy

Last updated

Who is responsible

SOV17 LLC, 3 Moskovyan St., Kentron, Yerevan 0001, Republic of Armenia, operates Acknowledged. Contact: [email protected].

What we store

  • Display names of channel members, as Microsoft Teams provides them.
  • Teams user IDs and Microsoft Entra object IDs, as Teams sends them to the app.
  • Announcement text (title and message) and due dates.
  • Timestamps: when an announcement was posted, acknowledged and reminded, and who has opted out of reminders.
  • Your organization's Microsoft tenant ID and plan, and usage counts per month.
  • For a paid plan: the Microsoft Entra object ID of the person who bought it, so that only they can change the plan.

What we do not collect

Acknowledged does not collect email addresses. When Teams includes a person's email address or user principal name in the member list it shares with apps, Acknowledged discards it and never stores it. Acknowledged does not use Microsoft Graph, does not ask for admin consent and does not sign anyone in.

Why we use it

To post announcements, record acknowledgements, send reminders, show the person who posted who has acknowledged, apply plan limits, and keep the service secure. Our legal basis is performing our contract with your organization and our legitimate interest in running and improving the service. We do not sell data or use it for advertising.

Who processes it for us

  • Google Cloud (Google LLC): hosting and database, in the us-central1 region (Iowa, United States).
  • Microsoft (Microsoft Teams and Azure Bot Service): delivering messages between Teams and Acknowledged.
  • Paddle.com Market Limited: payments, billing contacts, invoices and tax, as Merchant of Record for paid plans.
  • Cloudflare, Inc.: hosting this website and our DNS.
  • Fastmail Pty Ltd: our support email.

Data is processed in the United States and wherever these providers operate, under their data processing terms.

How long we keep it

  • Announcement content is deleted 90 days after its due date, or 90 days after posting if it has no due date.
  • Data from a team or private channel is deleted 30 days after Acknowledged records that the app was removed from it or from its team, or that its team was deleted. If Acknowledged finds the app there again before then, the deletion is cancelled and the remaining data is kept; this can also happen when that check is mistaken. Data already deleted is not restored, and announcement content still expires on its own schedule.
  • When we delete an organization's data, we keep a minimal record (the Microsoft tenant ID, the date and the payment subscription IDs) so that old billing events cannot restore the deleted data.
  • Monthly usage counts without personal data are kept for business records; Paddle keeps billing records as the law requires.

Your choices and rights

You can ask for access to, correction of, or deletion of data about you or your organization by emailing [email protected]. We may confirm that the request comes from your organization before acting on it. Anyone can stop reminders for an announcement from the reminder itself.

Security

Data is encrypted in transit and at rest. Only the person who posted an announcement can see who has acknowledged it. They can export that list as a CSV file through a download link that works for 15 minutes; anyone they share the link or the file with can read it. For private channels, the link also keeps working after the sender leaves the channel. It stops working once Acknowledged records that the app was removed from the channel, and in any case 15 minutes after it was issued. A link that stopped working because of a recorded removal does not work again if the app is added back; the sender can create a new link. Access to production systems is limited to the people who operate the service.

Children

Acknowledged is a workplace tool and is not directed at children.

Changes

We will post any change here with a new date.