This Privacy Policy applies to Azure Marketplace solutions provided by Summain Oy (“Summain”).
Controller and Processor Roles
For the purposes of the General Data Protection Regulation (“GDPR”), Microsoft acts as the data controller for personal data processed in connection with the Azure Marketplace purchasing, billing, and subscription management processes. Summain does not determine the purposes or means of such processing and does not act as a controller for Azure Marketplace transactional data.
In the context of providing Azure Marketplace solutions as managed services, Summain acts as a data processor on behalf of the customer (the data controller), processing personal data solely in accordance with the customer’s instructions and as necessary to provide the service.
Data Transfers and Disclosure
Solutions purchased from the Azure Marketplace do not transmit personal data to Summain or to third parties for the benefit of Summain, except for information generated as part of the Azure Marketplace purchasing process, which is collected and controlled by Microsoft in accordance with its own privacy policies and data processing agreements.
Summain does not disclose, sell, or otherwise make personal data available to third parties for commercial purposes.
Access to Personal Data in Managed Services
As Summain’s Azure Marketplace offerings are delivered as managed services, Summain may have authorized access to customer‑managed Azure resources. This access may, in limited and necessary circumstances, allow Summain to view personal data contained in resource activity logs, such as authenticated user names and email addresses.
Such access:
- Is limited to what is necessary for service delivery, monitoring, maintenance, support, security, and troubleshooting;
- Does not constitute independent collection or profiling of personal data by Summain; and
- Is subject to appropriate technical and organizational measures to protect personal data in accordance with Article 32 of the GDPR.
Authentication and Logging Data
Due to the use of Microsoft authentication services within the solutions, certain personal data is processed during authentication and authorization, as well as for the purposes of auditability, security, and accountability. This data may include:
- Authenticated user name
- Authenticated user email address
This personal data is processed and stored within the applicable Microsoft identity service, such as Microsoft Entra ID, Microsoft Entra ID for Workforce, or Microsoft Entra External ID (Configuration Tenant), and within the solution itself. Processing is strictly limited to legitimate purposes under Article 6(1)(b) and/or Article 6(1)(f) of the GDPR, such as performance of a contract and ensuring system security.
Data Protection Principles
Summain processes personal data in accordance with the GDPR principles of:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
Personal data is not retained longer than necessary for the purposes for which it is processed, unless a longer retention period is required by law or agreed with the data controller.
