This English text is a convenience translation. The German version is authoritative. Maßgeblich ist die deutsche Fassung.
Last updated: 23 August 2026
TenantOne ("we", "us") provides security and governance assessments for SaaS tenants — currently Google Workspace and Atlassian (Jira/Confluence) — at tenantone.io. The service is operated by Valerii Novokhyzhnii, trading as Webdesign VALNOVO, Klosterstr. 3, 71394 Kernen im Remstal, Germany — see our Imprint for full legal details. For any privacy matter, contact us at privacy@tenantone.io or hallo@valnovo.de. Given the size and nature of our processing activities, we are not required to appoint a Data Protection Officer under Art. 37 GDPR; the contact above handles all data protection matters.
TenantOne is a business-to-business (B2B) service intended for use by organizations and the IT administrators, security teams and other staff they authorize. It is not directed at, and should not be used by, individuals under the age of 18 or for purely personal or household purposes. If you register on behalf of an organization, you confirm that you are authorized to do so and that your organization has reviewed this policy.
Account data: your name, email address and a hashed password when you create a TenantOne account; for team members you invite, the email address you enter and the acceptance status of the invitation.
Tenant configuration data: when an administrator connects a Google Workspace tenant, we read configuration and audit metadata through official Google APIs using read-only scopes: user directory attributes (names, email addresses, admin status, 2-Step Verification status, sign-in timestamps, recovery email/phone, organizational unit), group settings, domain records, third-party OAuth grant metadata, security-relevant audit log events, storage usage, and — where Drive scanning is separately enabled via domain-wide delegation — Drive file metadata (name, owner, sharing exposure). When an administrator connects an Atlassian site, we read configuration metadata through official Atlassian Cloud APIs using read-only scopes: Jira project attributes (key, name, lead, activity timestamps), permission schemes and project roles, group names, Confluence space attributes and activity timestamps, and installed Marketplace app metadata. If an organization administrator additionally supplies a read-only organization API key, we also read organization-level metadata: managed account attributes (Account ID, display name, email address, account status, product access and last-active timestamps), organization role assignments, API token metadata (label, owner, creation, expiry and last-used timestamps — never the token value), the authentication policy state recorded for managed accounts, and the native backup policy configuration. This organization key is optional, is stored encrypted, is never required to run an assessment, and can be removed at any time. Where an Atlassian Account ID, display name or email is stored in connection with a scan or OAuth grant, we report those Account IDs to Atlassian via the Personal Data Reporting API on a recurring cycle and erase or refresh them when Atlassian instructs us to. We do not read the content of emails, files, documents, issues or pages.
DNS data: we look up public DNS records (SPF, DKIM, DMARC, MX) for your verified domains.
Technical and session data: basic server logs (IP address, timestamp, requested URL), and, for signed-in sessions, the IP address and browser user agent associated with your login session, used for account security, fraud prevention and troubleshooting, retained for a limited period as described in Section 10.
Cancellation requests: if you use the contract cancellation form, we process the email address, optional name and optional note you provide, together with the requested termination date, to process and confirm your cancellation (see Section 12).
Exclusively to evaluate your tenant's security configuration, compute findings and risk scores, display them to authorized users of your organization, generate reports, notify you about new findings, administer your account and team, and process cancellation requests. We do not sell data, do not use it for advertising, and do not share it with third parties except the recipients listed in Section 9.
We process account and tenant data to perform our contract with you (Art. 6(1)(b) GDPR) and, for security logging, fraud prevention and exercising or defending legal claims, on the basis of our legitimate interest (Art. 6(1)(f) GDPR). Where we send you optional product updates, we rely on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of processing before withdrawal. Processing of statutory cancellation requests under § 312k BGB is based on our legal obligation and the performance of the underlying contract (Art. 6(1)(b) and (c) GDPR).
For your account data (Section 3, "Account data"), TenantOne acts as the data controller within the meaning of the GDPR.
For personal data contained in the tenant you connect (Google Workspace or Atlassian) (e.g. your employees' names, email addresses or audit log entries), your organization is the data controller and TenantOne acts solely as a processor acting on your documented instructions, within the meaning of Art. 28 GDPR. Your organization remains responsible for having a valid legal basis to have this data processed and for informing the individuals concerned. We offer a Data Processing Agreement (DPA) reflecting Art. 28 GDPR requirements, including sub-processor authorization, confidentiality, security measures and assistance obligations; request a copy at privacy@tenantone.io.
TenantOne's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is used only to provide the security assessment features visible to you, is never used to develop or train generalized AI/ML models, and is never sold.
Risk scores and findings are generated automatically by comparing your tenant's configuration against CIS-aligned benchmarks. This is automated processing, but it does not amount to a decision producing legal effects concerning you or a similarly significant effect within the meaning of Art. 22 GDPR: findings are informational, are reviewed by your own administrators, and require your organization's own action to be applied. We do not make any fully automated decisions about you or your organization that have legal or similarly significant effects.
We only disclose personal data to the following categories of recipients, each acting as our processor or as an independent controller for their own service, and only to the extent necessary to provide TenantOne:
We do not use any analytics or advertising trackers, and we do not sell or rent personal data to any third party. Where a transfer occurs outside the EEA, it is covered by an adequacy decision or by Standard Contractual Clauses (or an equivalent safeguard); a copy of the relevant safeguard is available on request at privacy@tenantone.io.
We apply technical and organizational security measures to protect your data against unauthorized access, loss or misuse. Application data, including data read from Google Workspace or Atlassian, is stored in an access-controlled database on servers in the European Union (Hetzner, Finland). All traffic to and from TenantOne is encrypted in transit via TLS. OAuth refresh tokens — the credential that grants us access to your tenant — are additionally encrypted at rest with AES-256-GCM, and access to production systems is limited to authorized personnel. You can revoke TenantOne's access at any time in the Google Admin console / Google account settings, or for Atlassian under Connected apps in your Atlassian account settings.
Retention periods:
We set a small number of strictly necessary cookies, and one optional Preferences cookie that requires your consent before it is set. We do not use tracking, analytics or advertising cookies on tenantone.io or app.tenantone.io. When you first visit, a cookie banner lets you accept all cookies, reject the optional one, or open detailed settings; you can change your choice at any time via the "Cookie preferences" link in the footer or on our Cookie Policy page. The cookies we set are:
| Cookie | Purpose | Duration |
|---|---|---|
| better-auth.session_token | Keeps you signed in; identifies your authenticated session. | Up to 7 days, or until logout |
| g_oauth_state | CSRF protection during the Google Workspace connection flow. | A few minutes (deleted after callback) |
| a_oauth_state | CSRF protection during the Atlassian connection flow. | A few minutes (deleted after callback) |
| cookie_consent | Remembers your cookie preference so we don't ask again on every visit. | 180 days |
| sidebar_state (optional) | Remembers whether the dashboard sidebar is expanded or collapsed. Only set if you accept the "Preferences" category. | 7 days |
The first three cookies above are technically necessary within the meaning of § 25 (2) TTDSG / Art. 6(1)(b) and (f) GDPR and do not require consent. The sidebar_state cookie is optional and is only set after you actively opt in (Art. 6(1)(a) GDPR / § 25 (1) TTDSG).
Under the GDPR, you have the right to:
To exercise any of these rights, contact privacy@tenantone.io. We respond within 30 days. If personal data relates to a Google Workspace tenant your organization connected, we may direct certain requests to your organization's administrator, who is the controller for that data (see Section 6).
We may update this policy as the service evolves. Material changes will be announced by email or in-app notice before they take effect, and the "Last updated" date above will reflect the date of the latest revision.