ALM XPP MCP is operated by Alim Ben Helal, acting as data controller for the data described in this policy. For anything relating to your personal data, contact alim@almxpp.com. To report a security vulnerability, see security.txt.
When you create an account we store your email address, full name, company, professional role and, if you choose to provide it, your LinkedIn URL. Your password is never stored: we keep only a salted hash. Legal basis: performance of the contract.
We record the IP addresses used to sign in, so that we can alert you to access from an unrecognised location and block credential-stuffing attempts. API tokens are stored as hashes only. Legal basis: legitimate interest in securing the service.
Every tool call produces a metering record: the tool name, your account identifier, the timestamp, the response time and the response size. The first text argument of the call is also recorded, truncated to 500 characters. For a search this means the search terms; for an object lookup, the object name. This is what lets us enforce plan quotas, bill accurately and investigate incidents.
We want to be explicit rather than reassuring: this argument capture means that if you pass identifying or confidential text as the first parameter of a tool call, that text is stored. It is never used for advertising, resold, or used to train any model. It is visible to you in your dashboard and included in your data export.
Legal basis: performance of the contract (billing) and legitimate interest (abuse prevention).
Administrative and security-relevant actions are written to an append-only audit log, retained for 12 months. Legal basis: legitimate interest and legal accountability obligations.
Uploading a custom model, connecting an Azure DevOps repository or attaching a context document is always opt-in and always initiated by you. The content is indexed so that the service can answer questions about your own code. It remains yours, is never shared with other customers, and is deleted when you delete the model. If you never upload anything, the service works entirely against the standard Microsoft D365 platform index.
The application and all persistent storage run in Microsoft Azure, West Europe (Netherlands). Data at rest is encrypted; the account store is additionally encrypted with AES-GCM. All traffic is served over TLS 1.2 or higher.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, storage, container registry | West Europe (EU) |
| Brevo | Transactional email only (sign-up, password reset, service alerts) | European Union |
No sub-processor outside the European Union is engaged, and no data leaves the EU. The language model is self-hosted on our own infrastructure, in the same region as the rest of the platform: your content is never sent to a third-party model provider. Where a feature lets you supply your own model provider key, you contract with that provider directly and we are not party to it.
| Category | Retention |
|---|---|
| Account data | Until you delete your account |
| Usage / metering records | Retained for billing and dispute resolution |
| Audit log | 12 months |
| Uploaded models and documents | Until you delete them |
| Backups | Rolling; overwritten as newer backups are taken |
Under the GDPR you may access, rectify, erase, restrict or object to the processing of your personal data, and receive it in a portable format. Two of these are self-service, and both take effect immediately:
For any other request, write to alim@almxpp.com. We answer within 30 days. You also have the right to lodge a complaint with your national supervisory authority (in France, the CNIL).
Access is role-based and denied by default; administrative actions are logged; secrets are held as platform secrets rather than in source; backups are taken and the restore procedure is tested and documented with a measured recovery time. We do not claim to be certified under ISO 27001 or SOC 2 — see our security and compliance page for exactly what has and has not been independently verified.
If a breach affects your personal data and presents a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you directly without undue delay where the risk is high.
Material changes to this policy will be announced by email to registered users before they take effect. The date at the top of this page always reflects the current version.