Your documents never leave your Microsoft 365 tenant
DC Workflow does not store your document contents. When integrated with Microsoft SharePoint and OneDrive, your files remain entirely within your organisation's Microsoft 365 environment. DC Workflow only processes workflow metadata — review assignments, status, and audit trails — not the documents themselves. This policy applies to that metadata and to how we operate the DC Workflow service.
1 Who We Are
DC Workflow is a controlled document review and transmittal management service operated by Piksort Pty Ltd ("DC Workflow", "we", "us", "our"). DC Workflow is available as a Microsoft Teams application and as a standalone web application at dcworkflow.com.
This Privacy Policy describes how we collect, use, store, and protect personal data in connection with the DC Workflow service. It applies to all users of DC Workflow, including administrators, reviewers, document owners, and any other individuals who access the service on behalf of their organisation ("Customer").
Where DC Workflow processes personal data on behalf of a Customer organisation, we act as a data processor. The Customer organisation is the data controller and is responsible for the lawful basis under which personal data is processed. We will always act on documented instructions from the data controller.
2 Data We Collect
DC Workflow collects the minimum personal data required to provide the service. The following table describes each category.
Category
Description
Source
Identity & account data
Display name, work email address, user principal name (UPN), Azure Active Directory object ID, and tenant ID. Collected when you sign in with your Microsoft work or school account.
Review workflow metadata
Document names, review type (IFI/IFA/IFC), reviewer assignments, final approver designations, review status, transmittal reference numbers, review duration settings, and submission timestamps.
Audit and activity data
Records of actions taken within the service — who submitted a review, who approved or rejected, timestamps of status changes. This data supports auditability requirements.
Service usage data
Aggregated, non-identifying usage metrics such as feature adoption and session counts used to improve the service. No individual activity profiles are built for marketing purposes.
Technical data
Browser type, operating system, IP address (truncated), and Teams client version, collected automatically to maintain service security and performance.
We do not collect or store the contents of your documents. File content remains within your organisation's Microsoft 365 SharePoint or OneDrive environment and is never transmitted to or stored on DC Workflow infrastructure.
3 How We Use Your Data
We use collected data solely for the following purposes:
- Providing the service. Authenticating users, managing review workflows, routing notifications to assigned reviewers, and generating transmittal records.
- Service communications. Sending review assignment notifications, approval requests, and auto-close alerts to reviewers via email or Microsoft Teams notifications.
- Security and fraud prevention. Detecting and investigating suspicious activity, enforcing acceptable use, and maintaining service integrity.
- Service improvement. Analysing aggregated, anonymised usage patterns to improve features and user experience. Individual users are never profiled for commercial purposes.
- Legal and compliance obligations. Retaining records as required by applicable law or as directed by the data controller (your organisation).
- Audit support. Providing audit trail data to authorised administrators within your organisation upon request.
We do not use your data to train machine learning models, sell data to third parties, deliver advertising, or build individual user profiles for any purpose beyond service delivery.
4 Microsoft Identity Platform & Graph API
DC Workflow uses Microsoft Azure Active Directory (Azure AD) for authentication and Microsoft Graph API for integration with your organisation's Microsoft 365 environment. The following permissions are requested and used:
Permission scope and purpose
openid
profile
email
Standard OpenID Connect scopes used to authenticate your identity and retrieve your display name and email address to personalise your experience and identify review participants.
User.Read
Reads your basic profile from Azure AD (name, email, job title). Used to populate reviewer assignments and audit records.
Files.ReadWrite
Sites.ReadWrite.All
Reads and writes file metadata within your organisation's SharePoint document libraries. Used to link documents to review workflows and update review status metadata on files. File content is never read by DC Workflow.
Mail.Send
Sends review notifications and approval requests on behalf of the submitting user. Used only when email notification is triggered by a review action.
All API calls are made using tokens scoped to your organisation's Azure AD tenant. DC Workflow does not store OAuth tokens beyond the active session. Token refresh and revocation follow Microsoft's standard OAuth 2.0 flows. Your organisation's Conditional Access policies, MFA requirements, and Azure AD security controls apply to all DC Workflow sessions.
Access can be revoked at any time by your Azure AD administrator via the Enterprise Applications panel in the Azure Portal, or by revoking the DC Workflow consent grant.
5 Data Storage & Security
Workflow metadata (review records, audit trails, transmittal data) is stored on infrastructure hosted exclusively on Microsoft Azure. We do not use infrastructure outside of Microsoft's cloud platform for production workloads.
Security controls
Encryption in transit
All data transmitted between your browser, Teams client, and DC Workflow servers uses TLS 1.2 or higher. Connections over unencrypted HTTP are rejected.
Encryption at rest
All stored data is encrypted at rest using AES-256 via Microsoft Azure managed encryption, consistent with Microsoft's platform security standards.
Access controls
Access to production data is restricted to authorised DC Workflow personnel on a need-to-know basis. Multi-factor authentication is enforced for all internal administrative access.
Tenant isolation
Each Customer organisation's data is logically isolated. No data from one tenant is accessible to users or administrators of another tenant.
Audit logging
Administrative actions and data access events within DC Workflow are logged. Logs are retained for a minimum of 12 months and are available to Customer administrators on request.
Vulnerability management
We conduct regular security reviews of our application and dependencies. Security patches are applied on a priority basis consistent with CVSS severity ratings.
6 Data Sharing & Sub-processors
We do not sell, rent, or trade personal data. We share data only in the following limited circumstances:
- Microsoft Azure. Our primary cloud infrastructure provider. Data is processed and stored within Azure data centres in accordance with Microsoft's Data Protection Addendum (DPA).
- Microsoft Graph API / Microsoft 365. Data exchanged with Microsoft's platform services as part of authentication and document library integration, subject to your organisation's Microsoft agreement.
- Legal obligations. Where required by law, court order, or regulatory authority, we may disclose data to the extent legally required. We will notify the affected Customer where permitted.
- Business transfers. In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.
We do not use third-party advertising networks, analytics brokers, or data enrichment services that would receive personal data about your users.
7 Data Retention
We retain personal data only for as long as necessary to provide the service or as required by applicable law. The following periods apply:
Retention schedule
Active account data
Retained for the duration of the active subscription. Deleted within 30 days of subscription termination or written deletion request from the Customer administrator.
Review and audit records
Retained for 7 years by default to support compliance and audit requirements. Customers may request a shorter retention period subject to their regulatory obligations.
Security and access logs
Retained for 12 months, then permanently deleted.
Aggregated usage analytics
Anonymised and retained indefinitely for service improvement purposes. No personal data is retained once anonymisation is applied.
Upon receipt of a valid deletion request from an authorised Customer administrator, we will confirm deletion within 30 days and provide written confirmation.
8 Your Rights
Depending on your jurisdiction, you or your organisation may have the following rights regarding personal data we hold. Requests should be directed to your organisation's DC Workflow administrator, who may raise them with us.
Right of access
Request a copy of personal data we hold about you and information about how it is used.
Right to rectification
Request correction of inaccurate or incomplete personal data held about you.
Right to erasure
Request deletion of your personal data where we have no lawful basis to continue processing it.
Right to restriction
Request that we limit how we process your data while a dispute or review is outstanding.
Right to portability
Receive your personal data in a structured, machine-readable format where technically feasible.
Right to object
Object to processing of your personal data where we rely on legitimate interests as a lawful basis.
DC Workflow is designed to support organisations subject to GDPR, Australian Privacy Act 1988, and other applicable data protection frameworks. Where we act as data processor, we will assist Customer data controllers in responding to data subject requests within applicable timeframes.
9 Enterprise Administrator Controls
DC Workflow is designed to meet the governance expectations of enterprise IT departments. Customer administrators have access to the following controls:
- Consent management. Administrators grant and revoke DC Workflow's access to the organisation's Azure AD tenant and Microsoft Graph at any time via the Azure Portal Enterprise Applications panel.
- User provisioning. Access to DC Workflow is gated by your organisation's Azure AD. Offboarding a user in Azure AD immediately revokes their DC Workflow access.
- Data export. Authorised administrators may request a full export of their organisation's workflow metadata and audit records at any time by contacting support.
- Deletion requests. Authorised administrators may request complete deletion of their organisation's data at any time, effective within 30 days.
- Audit log access. Administrators can request access to DC Workflow audit logs showing all administrative actions within their tenant.
- Conditional Access compatibility. DC Workflow respects Azure AD Conditional Access policies, including device compliance, MFA requirements, and IP restrictions, as configured by your organisation.
For enterprise Data Processing Agreements (DPA), custom data residency requirements, or security review documentation including questionnaire responses, contact us at privacy@dcworkflow.com.
10 Cookies & Tracking
DC Workflow uses a minimal number of cookies strictly necessary to operate the service:
- Session cookies. Used to maintain your authenticated session after signing in with Microsoft. These are session-scoped and deleted when you close your browser.
- Security cookies. Used to prevent cross-site request forgery (CSRF) attacks. These contain no personal data.
We do not use advertising cookies, cross-site tracking pixels, third-party analytics cookies, or any tracking technology that shares data with external advertising networks. The DC Workflow Teams application does not use any persistent browser storage for tracking purposes.
11 International Data Transfers
DC Workflow infrastructure is hosted on Microsoft Azure. By default, data is processed in the Australia East Azure region. Customers requiring data residency in a specific Azure region (including EU regions for GDPR compliance, or US regions for FedRAMP purposes) should contact us to discuss custom deployment options.
Where data is transferred outside of your jurisdiction, we ensure appropriate safeguards are in place, including standard contractual clauses and reliance on Microsoft's Data Protection Addendum, which covers Microsoft Azure international data transfer obligations.
12 Changes to This Policy
We may update this Privacy Policy from time to time as the service evolves or in response to regulatory changes. We will notify Customer administrators of material changes by email and by posting a notice within the DC Workflow application at least 30 days before the change takes effect.
The version number and effective date at the top of this page will be updated with each revision. Previous versions are available upon request.