Privacy Policy

Effective Date: September 6, 2026

This Privacy Policy explains how Margin for Outlook (the "Add-in," "Service," or "we"/"us"/"our") collects, uses, shares, and protects information when you use the Add-in. Margin for Outlook is an Outlook task-pane add-in that lets members of an organization add internal collaborative comments and private notes alongside their email conversations.

Margin for Outlook is operated by Younes Azamiyan (ABN 53 691 109 499), a software developer based in New South Wales, Australia. We handle the personal information described below in line with the Australian Privacy Principles, as a matter of our own practice.

Where this policy stands. The Add-in is in private beta and is operated by an individual. The descriptions of what we collect, store, and delete are accurate and current. The legal characterisations in this policy — who is controller, who is processor, which statutory regimes apply — are our own assessment and have not been reviewed by a lawyer.

Who decides what happens to your data. The Add-in runs inside your organization's Microsoft 365 tenant, and your organization decides who uses it, what is written in it, and how long that content is kept. We therefore treat your organization as the controller of the comments, notes, memberships, and preferences held in the Add-in, and ourselves as a processor acting on its instructions. That is how we operate in practice; the characterisation itself is our own assessment, not a legal opinion.

One limit we place on ourselves. Your organization can direct us to delete the private notes in its tenant, as it can any other data we hold for it. It cannot obtain their contents from us: a note is written by one person for themselves, and we do not disclose note content to anyone but its author, whatever the instruction. The only exception is where we are compelled by law or legal process. See Sections 6 and 8.

We are the controller for a narrower set of information we decide to collect for our own purposes: feedback and support requests you send us, operational and error-monitoring logs, and the list of organizations invited to the beta. Section 3a sets out our legal basis for each of these.

The practical consequence is in Section 8: for data your organization controls, requests are best directed to your organization's administrator, and we assist them.

We have designed the Add-in to access as little of your email as possible and to encrypt the content you create. This policy describes exactly what that means.


1. Introduction

We are committed to protecting your privacy. This policy applies to the Margin for Outlook add-in and its backend service. It does not apply to Microsoft Outlook, Microsoft 365, or any third-party services that you access independently of the Add-in.

By using the Add-in, you agree to the collection and use of information as described in this policy.

2. Information We Collect

We collect only the information needed to provide the Service.

2.1 Identity information (from Microsoft Entra ID)

When you sign in, we receive the following from your Microsoft 365 identity token:

2.2 Email association data (identifiers only)

To attach your comments and notes to the correct email, the Add-in reads a limited set of properties from the currently selected message via Office.js:

Important: We do not store the body of your emails, the recipients of your emails, attachments, or sender/recipient address books. We store only the conversation and item identifiers needed to link your comments and notes to a message.

2.3 Content you create

2.4 Usage and preference data

3. How We Use Your Information

Information Purpose
Entra user ID, tenant ID, display name, email Authenticate you, enforce tenant isolation, attribute comments/notes, and display authorship
Conversation ID / item ID Link your comments and notes to the correct email conversation
Comment and note content Provide the core collaboration and private-notes features
Membership data (emails, roles, hashed codes) Manage who can access shared comments in a mailbox and verify invitations
Feedback and support content Respond to your requests and improve the Service
Preference and usage data Personalize and improve the in-app experience
Operational logs Maintain security, reliability, and troubleshoot issues
Audit records Answer your organization's questions about who did what and when; investigate security incidents

We do not use your information for advertising, and we do not sell your personal data.

3a. Our legal basis for processing

Where the GDPR or an equivalent law applies, processing needs a legal basis. Which basis applies depends on whether we are acting as a processor for your organization or as a controller in our own right (see the note at the top of this policy).

Information Our role Legal basis
Comments, membership, preferences, and the identifiers that link them to a conversation Processor We process these only on your organization's documented instructions. Your organization determines its own legal basis for holding them
Private notes Processor Same basis, with one limit: we act on instructions to delete them, and never on instructions to disclose their contents to anyone but their author (Sections 1 and 6)
Feedback and support requests you send us Controller Performance of our agreement with you, and our legitimate interests in responding to you and improving the Service
Operational logs, error monitoring, and rate limiting Controller Our legitimate interests in keeping the Service secure, available, and free from abuse
Audit records (Section 2.4) Controller Our legitimate interests in keeping the Service secure and in being able to answer your organization's questions about who did what in its mailboxes
The list of organizations invited to the beta Controller Our legitimate interests in administering access to the Service

Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests, rights, and freedoms. You may request a summary of that assessment using the contact details in Section 12.

4. Microsoft Integration

The Add-in operates within the Microsoft 365 ecosystem and relies on Microsoft Entra ID for sign-in.

Your use of Microsoft Outlook and Microsoft 365 is governed by Microsoft's own privacy terms.

5. Data Sharing and Sub-processors

We do not sell your data and we do not share it with advertising networks. We share information only with the service providers necessary to operate the Add-in:

In addition, we use the following infrastructure and operational sub-processors:

We do not use general-purpose analytics or marketing telemetry (for example, Google Analytics, Mixpanel, or Application Insights).

Data location and overseas disclosure. The information we store is held in Australia: our database is hosted in the Sydney region, and our application backend and encryption-key storage run in the Microsoft Azure Australia East region. The Add-in's static web files — which contain no personal information — are served from a Microsoft Azure region in the United States.

Two of the companies operating that Australian infrastructure are themselves based overseas. Where the data sits and who operates it are separate questions, and both matter: the data stays in Australia, but the company operating it may be able to reach it from where it is. Our database provider is Neon, LLC, whose parent company Databricks, Inc. is based in the United States — this is the store that holds everything described in Section 2. Our email provider, SMTP2GO, sends from its Sydney, Australia data centre but is operated by a company based in New Zealand, so email-related data may be accessible to it there.

Two further providers process data overseas outright. Sentry, our error-monitoring provider, is based in the United States, so the error and diagnostic identifiers sent to it are processed overseas. Cloudflare operates a global network, so requests are handled at whichever of its locations is nearest to you.

Transfers of European and UK personal data. Australia has not been the subject of an adequacy decision by the European Commission. We do not currently have Standard Contractual Clauses or a UK International Data Transfer Addendum in place, and we cannot supply them today. Where an organization subject to the EU or UK GDPR wants to use the Add-in, we will put a written data processing agreement in place with it first — incorporating the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved, and supported by an assessment of the laws of the destination country. If that applies to your organization, contact us using the details in Section 12 before deploying the Add-in. New Zealand, where our email provider is domiciled, is covered by an EU adequacy decision.

We choose sub-processors whose own published terms and security commitments are consistent with this policy, and we name every one of them above. We have not yet completed a formal assessment of each provider's contractual terms against the Australian Privacy Principles.

We may also disclose information if required to do so by law or valid legal process, or to protect the rights, safety, and security of our users and the Service.

6. Data Retention

To request deletion of your data, contact us at [email protected] (see Section 8).

7. Data Security

We apply technical and organizational measures to protect your information, including:

No method of transmission or storage is completely secure, but we work to protect your information using industry-standard practices.

8. Your Rights

Wherever you are, you can ask us to:

If you are in the European Union or the United Kingdom, or another jurisdiction with equivalent laws, you may additionally have rights to:

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

How to exercise these rights. For the comments, notes, memberships, and preferences held in the Add-in, your organization is the controller — it decides what is kept and for how long, and it is best placed to confirm your identity. Direct those requests to your organization's administrator; where they ask us to act, we assist them promptly. For the information we hold as controller in our own right — feedback, support requests, and operational logs — contact us directly at [email protected].

Your private notes are an exception, in one direction. Your organization can have them deleted, but it cannot get a copy: we do not release note content to your administrator, or to anyone else, on anyone's instruction but yours. To get a copy of your own notes, use the export in the Add-in, or write to us at [email protected] from the address on your account. The only circumstance in which we would disclose note content otherwise is where a law or legal process compels us to.

We respond to requests within one month of receiving them. If a request is complex, or you have made several, we may extend that by up to two further months, and will tell you within the first month if we do.

One thing to know about deletion. We take nightly backups and keep them for a limited period (see Section 6). When we erase something from our live systems it is gone from them immediately, but it continues to exist in backup copies until those copies expire — in the worst case about 44 days later. We never use a backup to bring erased data back into service, and if we ever have to restore from one to recover from data loss, we re-apply any erasures as part of that recovery.

9. Cookies and Local Storage

The Add-in does not use cookies for authentication. Sign-in tokens are obtained through Office.js and sent in the request authorization header; they are not persisted in cookies.

The Add-in may use the browser's local storage within the task pane to remember user-interface state (such as onboarding progress or dismissed banners). This data stays on your device and is not used for tracking.

This storage exists only to provide the task pane you have opened: without it the pane cannot remember the state it was left in between sessions. It is not used for advertising, analytics, profiling, or tracking you across sites, and we do not display a consent banner for it.

10. Children's Privacy

The Add-in is intended for use by organizations and their staff through Microsoft 365 work or school accounts that the organization provisions. It is not directed to children.

We are not involved in the creation of these accounts and do not receive any date-of-birth or age information about users, so we have no means of independently verifying a user's age. Because access to the Add-in is provisioned and approved by your organization's administrators, your organization is responsible for ensuring that the individuals it authorizes to use the Add-in meet the applicable age requirements (see the Eligibility section of our Terms of Service). Consistent with this, we do not knowingly collect personal data from anyone under the age of 16.

If you or your organization believe that a child has provided us with personal data, contact us at [email protected] and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" above and communicate material changes through the Add-in or by other reasonable means. Your continued use of the Add-in after changes take effect constitutes acceptance of the revised policy.

12. Contact Information

For privacy questions or to exercise your rights, contact us at:

We have not appointed a Data Protection Officer; the operator named above is the contact point for all privacy matters.