Assetto

Privacy

Last updated 31 August 2026

Nuestro aviso de privacidad se publica en inglés. El texto en inglés es la versión auténtica.

Who we are

Semplicita B.V. (“Semplicita”, “we”) provides Assetto, a security posture and configuration drift service for Microsoft 365. For questions about this notice or about your personal data, contact privacy@semplicita.eu.

This website

This site is a static website. It sets no cookies, runs no advertising or tracking scripts, and does not profile visitors. You are not asked to accept cookies because there are none to accept.

Aggregate, non-identifying traffic statistics may be collected using privacy-preserving analytics that do not set cookies, do not track visitors across sites, and do not collect personal data. Our hosting provider processes your IP address transiently in order to deliver the page and to protect the site from abuse.

When you contact us or book a demo

If you email us or book a call, we process the details you provide — typically your name, email address, employer and whatever you choose to tell us — in order to respond and to arrange the meeting. The legal basis is our legitimate interest in responding to business enquiries, and steps taken at your request prior to entering a contract.

We do not sell personal data, and we do not share it for advertising.

The Assetto service

When your organization uses Assetto, we act as a processor and your organization is the controller. We process data on your documented instructions under a data processing agreement.

What the service processes:

  • Configuration metadata from your Microsoft 365 tenant — policies, role assignments, sharing and device configuration settings.
  • Limited directory attributes needed for posture assessment, such as account names and whether an account is capable of multi-factor authentication.
  • Account details of your users of Assetto — name, email address or UPN, and organization role.

Mailbox contents, files, documents and messages are never accessed. See our security page for the full access model.

Where data is held

Customer data is hosted in European Union (Azure North Europe). In normal operation it is not transferred outside the European Union.

Retention

Configuration snapshots and drift history are retained for as long as your organization maintains its subscription, so that historical comparison and compliance evidence remain available. On termination, data is deleted within a defined period agreed in your contract. Enquiry correspondence is kept only as long as needed for the enquiry and our legitimate business records.

Subprocessors

We use a small number of providers to deliver the service, including cloud infrastructure and email. A current list is available on request and is provided as part of the data processing agreement.

Your rights

Under the GDPR you have the right to access, correct, delete, restrict and object to the processing of your personal data, and the right to data portability. Where we act as a processor for your employer, please direct your request to them and we will assist them in fulfilling it.

You also have the right to lodge a complaint with your national supervisory authority.

Changes

If this notice changes materially, we will update the date at the top and, where the change affects customers, tell them directly.