Privacy Policy
Effective August 25, 2026
Who we are
UDDI ("we", "us") is a product of Full Stack Data Solutions, reachable at privacy@uddi.co. UDDI turns the SharePoint content a company already manages into a permission-aware knowledge assistant. This policy covers uddi.co, the UDDI application, and the UDDI bot for Microsoft Teams.
The short version
Your documents stay in SharePoint — UDDI never moves or copies them wholesale. What UDDI stores is a search index: text passages, numeric embeddings of those passages, and the permission metadata needed to enforce who may see what. Every read from Microsoft 365 uses the signed-in user's own delegated permissions, answers are filtered by the asker's identity before retrieval, and your content is never used to train AI models.
Information we process
Account and identity. When you sign in with Microsoft Entra ID we receive your name, email address, directory object id, tenant id, and security-group ids — the minimum needed to know who you are and what you're allowed to see. We do not receive or store your password; authentication happens entirely with Microsoft.
Indexed content. For sources and collections your company connects, we store extracted text in passage-sized chunks, an embedding of each chunk, document names and links back to the source files, and per-document permission metadata captured from SharePoint. We do not store the files themselves. Removing a source deletes its index entries; the SharePoint site is untouched.
Usage. We keep a log of questions asked (the question text, who asked, whether the answer was grounded, and any thumbs feedback), per-user conversation history, and an append-only audit trail of administrative actions. These power the Insights page and your admins' audit review; they stay inside your account.
Billing. Payments are processed by Stripe. We store your plan, subscription status, and seat count; Stripe holds the card details, and we never see full card numbers.
Where data lives
It depends on your plan, and we say so precisely rather than with a slogan. On Starter, the index runs in UDDI's Azure environment, isolated per account. On Business, the index and AI resources live in your own Azure subscription — your data rests inside your tenant. On Tenant-Deployed, the entire application runs in your Azure tenant and your data never leaves it. The data-boundary table on the pricing page states this per tier.
Who else processes data
Microsoft Azure hosts the application, search index, and Azure OpenAI model calls (on Business and Tenant-Deployed tiers, these run in your own subscription). Stripe processes payments. We use no advertising or analytics trackers, and we do not sell or share personal information for advertising. Azure OpenAI does not use your content to train models.
How long we keep things
Account, membership, and billing records last for the life of your account. Question logs and audit events are capped and trimmed oldest-first. Conversation history is kept per user with a cap per person. When your account is deleted, its index entries, logs, and records are deleted; content in your SharePoint was never ours to begin with.
Your choices
Admins can remove sources (deleting their index entries), remove members, and export or request deletion of account data by contacting us. Individuals can ask their admin — or us — about data held on them. If your company has a data-processing agreement with us, its terms control where they are stricter than this policy.
Security
Access requires Microsoft Entra sign-in; there is no anonymous surface. Permission filters are applied before content reaches a model, and grants that cannot be verified fail closed. Secrets are held in Azure Key Vault on production deployments, transport is HTTPS everywhere, and administrative actions are audited. No system is perfectly secure; report concerns to privacy@uddi.co.
Changes
We'll post changes here with a new effective date. Material changes are announced to account admins before they take effect.
