Privacy Policy
AvdControl ("we", "us") provides AvdControl, a hosted console for Azure Virtual Desktop. This policy explains how we handle personal data across our public website at avdcontrol.com, our customer tenant consoles, and our support channels.
We act in two different roles, and the difference matters for your rights. For our website, marketing, billing and account administration we are a controller, and this policy applies directly. For the data inside a customer's tenant — including information about that customer's staff, contractors and Azure Virtual Desktop end users — we are a processor acting on our customer's instructions, and our Data Processing Addendum governs that processing. If your employer uses AvdControl and you want to know why your session activity is visible, your employer is the controller and you should contact them first.
1. Personal data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account and user data | Name, work email address, role, organisation name and subdomain, password hash, multi-factor authentication status, single sign-on subject identifier, account status | You, your administrator, or your identity provider via single sign-on or SCIM provisioning |
| Billing and contact data | Billing email, plan, subscription and trial status, payment and invoice records, cancellation reason where you give one | You, and Stripe as our payment processor |
| Azure Virtual Desktop session data | User principal names, session host and host pool names, session state, idle time, last input and start times | Collected from your Azure environment using the access your administrator granted |
| Audit and security records | Who did what and when, the action taken, before and after values, IP address, whether a AvdControl operator was acting on your behalf | Generated by the service as you use it |
| Support and help-request data | Requester name, email, role, ticket subject and body, message thread, the page you were on, and small image attachments you upload | You, when you contact us or raise a help request |
| Credentials and secrets | Azure application client secrets, identity provider client secrets, SCIM token hashes, multi-factor secrets and backup codes — always encrypted or hashed at rest | You, during setup |
| Technical and website data | IP address, approximate location derived from it, device and browser information, pages viewed, referring page, and session cookies | Automatically, when you use the website or console |
| Sales and enquiry data | Your name, email, company and the content of your message | You, when you email us or request a demo |
2. Why we use it, and our lawful basis
Where UK or EU data protection law applies, we rely on the following bases. Where UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies, we rely on the corresponding grounds of contractual necessity, legitimate interest, legal obligation and consent.
| What we do | Lawful basis |
|---|---|
| Create and administer accounts, provide the console, authenticate users, and provide support | Performance of a contract with our customer; our legitimate interest in serving the organisation you belong to |
| Take payment, prevent payment fraud, and keep accounting records | Performance of a contract; legal obligation; legitimate interest |
| Keep the service secure: audit logging, rate limiting, abuse detection, investigating incidents, enforcing our Terms | Legitimate interest in the security and integrity of the service and in protecting our customers and ourselves; legal obligation |
| Operational emails about your account, such as credential expiry, trial end, billing and security notices | Performance of a contract; legitimate interest |
| Improve and troubleshoot the service using aggregated or de-identified technical information | Legitimate interest in maintaining and improving our product |
| Website analytics through cookies | Your consent, which you can give or withdraw in the cookie banner |
| Marketing emails to business contacts who asked to hear from us | Consent, or legitimate interest in business-to-business marketing, with an unsubscribe option in every message |
| Respond to legal requests, defend claims, and comply with sanctions and export controls | Legal obligation; legitimate interest in establishing, exercising or defending legal claims |
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use customer data to train generally available machine learning models.
3. Data we read from your Azure environment
AvdControl connects to your Azure environment using an application registration that you create and control in your own Microsoft Entra ID tenant, with the roles described in our setup guide. Within that scope, the service reads Azure Virtual Desktop inventory and session information, and can disconnect a session, sign a user out of a session, or send a message to a session.
- We only read what the roles you granted allow. We do not read mailboxes, files, documents, keystrokes or screen content, and the service does not record or view desktop sessions.
- Session records include the user principal name of the person signed in, which is personal data about your staff or contractors. You are the controller for that data, and you are responsible for informing them.
- You can revoke our access at any time by removing the role assignments or deleting the application registration. That takes effect immediately for future collection.
- Azure client secrets you give us are encrypted before storage, and we notify your owners before a secret expires.
6. Where data is stored, and international transfers
The hosted service and its database currently run in United Kingdom (London). Support attachments are stored alongside the application in the same region. We may add further hosting regions — for example in the United States — to reduce latency or to meet customer residency requirements. When we do, we will update this policy and the sub-processors page, and we will tell customers in advance where the change affects where their data rests.
AvdControl is established in the United Arab Emirates, and our personnel and some sub-processors are located outside the United Kingdom and the European Economic Area. This means personal data may be accessed from, or transferred to, countries whose data protection laws differ from those where the data was collected.
Where we transfer personal data out of the UK or EEA, we put in place an appropriate safeguard, which will normally be the UK International Data Transfer Agreement or the UK Addendum to the European Commission's Standard Contractual Clauses, or the Standard Contractual Clauses themselves, together with a transfer risk assessment and technical measures such as encryption in transit and at rest. Where a transfer is to a country the UK or the European Commission has found to provide adequate protection, we rely on that finding. You can request a copy of the safeguards we use, with commercial terms redacted, from [email protected].
7. How long we keep it
We keep personal data only as long as we need it for the purposes above, then delete it or aggregate it so it no longer identifies anyone. Specific periods include:
| Data | Retention |
|---|---|
| Azure Virtual Desktop session records | Deleted automatically 14 days after collection |
| Portal sign-in sessions | Expire after 14 days; operator sessions after 8 hours |
| SCIM provisioning tokens | Expire 90 days after creation unless a shorter period is set |
| Audit and security records | Kept for the life of the tenant, then deleted with it, unless needed for an open investigation or legal claim |
| Account and user records | Kept while the account is active, then deleted with the tenant |
| Support and help-request threads and attachments | Deleted with the tenant, or sooner on request where we no longer need them |
| Billing, invoice and tax records | Kept for as long as applicable tax and accounting law requires, typically up to seven years |
| Website analytics | Retained by Google for the period set in our Analytics property, and only where you consented |
| Tenant data after termination | Archived, then deleted normally within 30 days, except where law requires retention. Backups age out on their own cycle |
8. How we protect it
- Data is encrypted in transit, and Azure and identity provider secrets, multi-factor secrets and backup codes are encrypted or hashed before storage with rotatable keys.
- Passwords are hashed with a slow, salted algorithm and are never stored or logged in plain text.
- Each tenant's data is isolated, and every data access path is scoped to a single tenant; we test this automatically as part of our build.
- Multi-factor authentication is mandatory for owners, administrators and our own operators, and can be required for all users in a tenant.
- Sign-in attempts are rate limited per account and per network address, and privileged actions are recorded in an audit trail.
- Access to production systems is limited to the personnel who need it, and we hold Cyber Essentials certification.
If a personal data breach affects your data, we will notify the affected customer without undue delay and, for data we process on your behalf, within the timescales set out in the Data Processing Addendum, with the information you need for your own regulatory reporting.
9. Your rights
Depending on where you are, you may have the right to ask for access to your personal data, correction of it, deletion of it, restriction of or objection to our processing, portability of data you gave us, and withdrawal of any consent you gave. You can also object to direct marketing at any time.
- If we are the controller — for example you are a website visitor, a sales contact, or a billing contact — email [email protected] and we will respond within one month, extendable where the request is complex. We may need to verify your identity.
- If your employer or another organisation uses AvdControl and your request concerns data inside their tenant, contact them: they are the controller and decide the outcome. If you contact us instead, we will refer you to them, and we will support them in answering you.
- Exercising these rights is free, and we will not treat you differently for doing so.
We do not carry out automated decision-making that produces legal effects or similarly significant effects on individuals, and we do not profile individuals for marketing.
10. Children
AvdControl is a business tool that is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, tell us at [email protected] and we will delete it.
11. Changes to this policy
We will update this policy as the service and the law change, and will change the effective date at the top of the page. Where a change materially affects how we use personal data, we will give notice by email to account contacts or by a notice in the service before it takes effect.
12. Contact and complaints
Data protection enquiries and rights requests: [email protected]. Security reports: [email protected]. Anything else: [email protected]. We will provide our registered entity details and postal address on request. We do not currently operate in a way that requires a UK or EU representative, and we will appoint and publish one if that changes.
If you are unhappy with how we handled your data, please tell us first so we can put it right. You also have the right to complain to a supervisory authority: in the United Kingdom the Information Commissioner's Office, in the EEA your local authority, and in the United Arab Emirates the UAE Data Office.