Terms for the IVON incident investigation
Applicable to the free, one-off IVON incident investigation that starts as soon as an administrator of your Microsoft 365 environment grants consent to the Attic application in Microsoft Entra ID.
Version 2026.8.22 · 22 August 2026
English edition of the authoritative Dutch version; in the event of any discrepancy, the Dutch version prevails.
In short
You grant consent, the investigation starts immediately and the report appears in your browser. That screen is the only place where you receive the report: no report is sent by email and there is no shareable link. If you close the browser screen, the report is gone — even if 24 hours have not yet passed. If you want to keep it, download it from that screen before you close it. As soon as the report is ready the access token expires and Attic can no longer read anything from your environment; the application itself remains in Entra ID until you remove it. Everything we retrieved for the investigation, and our own copy of the report, expires within 24 hours of delivery. The investigation is free of charge. After you grant consent you receive one email containing the follow-up offer and the record of what you accepted; that email carries an unsubscribe link at the bottom.
Part A — Terms
1. Parties and acceptance
1.1 These terms apply between Attic B.V., Chamber of Commerce number 83973206, Molenstraat 36, 4761 CL Zevenbergen, the Netherlands (hereinafter: "Attic") and the legal entity whose Microsoft 365 environment is connected to the investigation on this basis (hereinafter: "Customer").
1.2 These terms come into effect at the moment an administrator of Customer grants consent to the Attic application in Microsoft Entra ID. By granting that consent, the administrator accepts these terms, including the processing arrangements in Part B. There is no other act of acceptance.
1.3 The administrator who grants the consent declares that they are authorised to do so on behalf of Customer.
1.4 For every acceptance, Attic records: Customer's Microsoft Entra tenant ID, the administrator account that granted the consent, the time in UTC, the permissions granted and the version number of these terms. The email Customer receives after granting consent (article 7.2) states the title, the URL and the accepted version number of these terms. Attic retains an unaltered copy of every published version, available on request via [email protected], so that it can be established afterwards what was accepted.
1.5 The version in force at the moment of acceptance applies to that investigation. Later versions have no retroactive effect.
2. What the investigation is
2.1 Attic carries out one single investigation on the Microsoft 365 environment for which the consent was granted: it reads the security data from that environment (including Microsoft Defender, Microsoft Sentinel and Microsoft Entra ID), assesses the security incidents arising from it and delivers a report on those findings.
2.2 The investigation starts immediately after the consent is granted. The report appears in the same browser screen and is bound to that session: there is no shareable link and the report is not sent by email. If Customer closes the browser session, the report is gone — including within the 24 hours referred to in B.5. If Customer wishes to keep the report, they download it from that screen before closing it. The application also actively points this out on delivery of the report. After that, Attic can no longer provide Customer with a copy either.
2.3 The scope of the permissions granted is shown in Microsoft's consent screen at the moment they are granted. Attic does not request more permissions than are needed for this investigation.
2.4 The permissions requested are read permissions only: SecurityIncident.Read.All, plus openid, profile and email for sign-in. Attic makes no changes in Customer's environment and, with these permissions, is unable to do so.
3. End of access
3.1 The investigation is complete as soon as the report has been delivered. At that moment the access token expires: from then on, Attic can no longer read anything from Customer's environment. The Attic application itself subsequently remains in Microsoft Entra ID as an enterprise application until Customer removes it. Attic does not remove it. Removal works as follows: Microsoft Entra ID → Enterprise applications → [ATTIC] IVON Incident Investigation → delete.
3.2 Customer may also withdraw the consent earlier, in the same place, or report this via [email protected].
3.3 The investigation does not convert into a service or a subscription and is not repeated automatically. A further investigation requires new consent; continuous service provision requires a separate agreement.
4. What the investigation is not
4.1 The investigation is not a monitored service: no service level agreements, no response times, no undertaking as to availability, and no obligation to signal, follow up or escalate. Customer remains responsible for the security of its own environment and for acting on the report.
4.2 Findings and recommendations are produced in part by automated analysis. They are a snapshot and an advice, not a guarantee of completeness or accuracy, and not an obligation of result.
5. Free of charge, and liability
5.1 The investigation is carried out free of charge. Attic's liability for damage arising from or connected with the investigation is excluded, save in the case of intent or wilful recklessness on the part of Attic.
5.2 This does not limit the liability that follows mandatorily from the GDPR towards data subjects or supervisory authorities, nor liability for damage resulting from death or personal injury.
6. Confidentiality and the report
6.1 Attic treats what it sees in Customer's environment as confidential, does not use it for its own purposes, does not combine it with data from others and does not train any models on it.
6.2 The rights to the service, the software and the reporting format rest with Attic. The data from Customer's environment and the content of the report belong to Customer, who is free to use the report within its own organisation.
7. The report, the email after the investigation, and unsubscribing
7.1 The report is not sent by email. Attic delivers the report solely in the browser screen of the session in which the investigation was carried out (article 2.2). There is no shareable link. If Customer wishes to keep a copy, they download the report from that screen.
7.2 The email after the consent. After the consent is granted, Attic sends one email to the administrator's email address as obtained through that consent. It states the title, the URL and the accepted version number of these terms, and the follow-up offer: a separate fourteen-day trial period, or moving directly onto the paid service. In addition, Attic may use that email address to inform Customer about its own, similar services. Attic collects no other address for this purpose.
7.3 Unsubscribing. Every message carries an unsubscribe link at the bottom. Unsubscribing is possible at any time and is free of charge, using that link or by sending a message to [email protected]. Unsubscribing has no effect on the investigation or the report; those go ahead as normal.
8. Governing law
8.1 Dutch law. Disputes are submitted to the District Court of Zeeland-West-Brabant, Breda location.
Part B — Processing agreement (Art. 28 GDPR)
B.1 Roles and status. For the personal data that Attic processes from Customer's Microsoft 365 environment during the investigation, Customer is the controller and Attic is the processor. This Part B is the data processing agreement within the meaning of Art. 28(3) GDPR. It is concluded electronically by the granting of the consent; the parties agree that this qualifies as in writing within the meaning of that article. For the data about the administrator personally, Attic is the controller — see Part C.
B.2 Subject matter, nature, purpose and duration. One-off triage and analysis of security incidents and misconfigurations in Customer's environment, with a view to the report. The processing lasts for as long as the investigation runs, plus the retention period set out in B.5.
B.3 Data and data subjects. The following are processed: identity and authentication data (usernames, email addresses, role information, sign-in history, MFA status, risk events), device and session data (endpoint IDs, device names, IP addresses, threat signals), incident and alert data including the content that Microsoft Defender or Sentinel includes in an alert (occasionally fragments of email content or file names), audit logs, and configuration and posture data. Data subjects: end users and administrators within Customer's environment, and external individuals insofar as their data appears in an incident.
B.4 Instructions. These terms, this Part B and the permissions granted with the consent constitute Customer's complete written instructions. Attic does not process for its own purposes and does not process for the training of models. Customer may issue additional instructions via [email protected]; if a statutory obligation requires Attic to process beyond those instructions, Attic notifies Customer beforehand, unless that law prohibits it.
B.5 Retention and deletion. Within 24 hours of delivery of the report, the data collected for the investigation, the report and the session expire. Those 24 hours run from the end of the run, not from its start. If Customer closes the browser session sooner, the report is already gone at that moment. This means that everything Attic retrieved from Customer's environment disappears, as does Attic's own copy of the report; after that, Attic no longer holds a copy and can no longer provide Customer with one. If Customer does not keep a downloaded copy of its own (article 2.2), the report is gone. The original data remains in Customer's environment, unaffected. Attic confirms the deletion in writing on request.
B.6 Security (Art. 32 GDPR). Least privilege and mandatory multi-factor authentication; encryption in transit (TLS 1.2 or higher) and at rest; per-tenant token scoping that technically enforces that no data is retrieved from any other environment; the access token expires as soon as the run is complete; the report is bound to the browser session that carried out the investigation, is not reachable via a shareable link and is not sent by email; execution in a clean runtime with no remnants of earlier investigations; logging of access to customer data; a duty of confidentiality and a Certificate of Conduct (Verklaring Omtrent het Gedrag) for staff. Attic is undergoing certification for ISO/IEC 27001:2023, with the Stage 2 audit planned for Q4 2026.
B.7 Sub-processors. For this investigation Attic engages: Hetzner Online GmbH (hosting, Germany and Finland) and Microsoft (Azure, West Europe region; AI inference in Azure AI Foundry, Sweden Central region). The current list is published at atticsecurity.com/en/sub-processors; the list as it reads at the moment the consent is granted is the one that applies. Sub-processors are bound by obligations at least equivalent to this Part B, and Attic remains responsible to Customer for their compliance.
B.8 Location. Processing takes place exclusively within the European Economic Area. No transfer outside it takes place.
B.9 Personal data breaches. Attic reports a personal data breach affecting Customer's personal data within 48 hours of discovery to the administrator account that granted the consent, stating the nature, the likely consequences and the measures taken and proposed. Customer assesses whether to notify the Dutch Data Protection Authority and the data subjects; Attic provides support in doing so.
B.10 Data subject rights. Customer handles requests from data subjects. Attic provides support insofar as reasonably possible, responds within 10 working days and forwards without delay any request that reaches Attic directly. After the 24 hours referred to in B.5, Attic can no longer provide support; the data no longer exists.
B.11 Demonstrating compliance. On request, Attic makes available the information needed to demonstrate compliance with Art. 28 GDPR, and to that end provides the most recent audit report by an independent party as soon as one is available.
Part C — Privacy statement for the IVON incident investigation
This part concerns the data that Attic processes about you as the administrator. Attic is the controller for that data. What happens to the data from your Microsoft 365 environment is set out in Part B; your organisation is the controller for that data and Attic is the processor.
Who we are. Attic B.V., Molenstraat 36, 4761 CL Zevenbergen, the Netherlands, Chamber of Commerce number 83973206. Privacy contact: Erik Remmelzwaal, CEO — [email protected].
What we record about you. Your name and business email address; the name of your organisation and the Microsoft Entra tenant ID of your environment; the time at which you granted the consent, the permissions granted and the version of this document; which link you arrived through; and whether the investigation leads to a follow-up. We receive this data from Microsoft as part of the consent you grant — you do not have to enter it separately.
For what purpose, and on what legal basis.
| Purpose | Legal basis |
|---|---|
| Carrying out the investigation, and delivering the report to you in your browser screen | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) |
| Recording what you accepted and when, and confirming that to you | Legal obligation and legitimate interest: being able to demonstrate that we comply with the rules (Art. 6(1)(c) and (f) GDPR) |
| The email with the follow-up offer, and information about our own, similar services | Legitimate interest: bringing our services to the attention of an organisation that asked for them itself (Art. 6(1)(f) GDPR), with the opt-out set out below |
Unsubscribing. Every message we send you carries an unsubscribe link at the bottom. Unsubscribing is possible at any time and is free of charge, using that link or by sending a message to [email protected]. The investigation and your report go ahead as normal — they are part of what you requested.
Who we share it with. We use HubSpot (EU region) for our customer relationship management; your contact details are held there. The full list of parties that process data on our behalf is published at atticsecurity.com/en/sub-processors. We process exclusively within the EEA.
How long we keep it. The data from your environment, our own copy of the report and your session: within 24 hours of delivery of the report (Part B.5), and the report itself sooner still if you close the browser session. If you want to keep the report, download it from your browser — after that, we cannot give it to you either. Your contact details: 24 months after the investigation, if there is no follow-up; that is a period we have set ourselves. The record of what you accepted and when: for as long as we need to be able to rely on it. If you unsubscribe, we keep at least your email address on a suppression list, precisely so that we do not approach you again.
Your rights. You have the right of access, rectification, erasure, restriction, portability and objection. To exercise them, send a message to [email protected]; we respond within 30 days. We do not take automated decisions about you with legal or similarly significant effects.
Complaints. If you disagree with how we handle your data, let us know via [email protected]. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), www.autoriteitpersoonsgegevens.nl.
Version 2026.8.22 · 22 August 2026 · Attic B.V.
Questions about this document?
Send them to [email protected]. See also our sub-processor list and our general privacy statement.