Privacy Policy

Last updated: 13 August 2026

1. Who we are

Gridavera is a product of Enabler Business Intelligence FZ-LLC, a Free Zone Limited Liability Company registered in the Ras Al Khaimah Economic Zone, United Arab Emirates, with its registered office at FDAM0994, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. In this policy, “Gridavera”, “we”, “our” and “us” mean Enabler Business Intelligence FZ-LLC.

For any question about this policy or about your data, contact support@gridavera.com.

2. What this policy covers

This policy covers the Gridavera for Excel add-in, the admin portal at admin.gridavera.com and the cloud services behind them, together called the “Service”, and it also covers the gridavera.com website, including the contact form and the demonstration booking page. Where a section applies to only one of these, it says so.

3. Our two roles

Gridavera acts in two different capacities, and the difference determines who you should contact about your data.

As a controller. For your account, billing and subscription data, your Gridavera configuration, the activity records described in section 4, and everything described in section 5 about the website, Gridavera decides why and how the data is processed and is the controller.

As a processor. For the contents of the SharePoint lists that Gridavera reads and writes on your instructions, and for the user records your administrators load into Gridavera in order to configure access, Gridavera acts on behalf of your organisation. Your organisation is the controller and Gridavera is a processor.

Where Gridavera acts as a processor, an individual’s request to see or delete that data should be made to their own organisation. Gridavera will help that organisation respond.

4. What we collect through the Service

Account information

When you register, we collect company name, contact name, email address, phone number, Microsoft 365 tenant ID (automatically from your sign-in), and country.

Authentication data

We use Microsoft Entra ID, previously called Azure Active Directory, for authentication. When you sign in we receive your email address and display name from your Microsoft 365 profile, your tenant identifier, and an authentication token used to verify your identity. We do not receive or store passwords.

People your administrators add

To configure who can see and edit what, your administrators record users in Gridavera. For each user this includes an email address, assigned roles, and the dimension filter values that determine which rows that person can see. This can include external guest users from outside your organisation, where you have invited them into your Microsoft 365 tenant.

Gridavera does not obtain this information from those individuals directly. It comes from your organisation, which decides who is added.

Activity records

We record the actions taken in the add-in and the admin portal. Each record includes the tenant, the site, the acting user, a timestamp, and a description of what changed. Recorded actions include data loads and submissions, dimension edits, configuration changes, user and role changes, encryption key operations, backup and restore, billing events, and administrator succession requests.

We also collect IP addresses, add-in version and browser information.

Support access to your data. When you raise a support request we may need to look at your tenant’s records to investigate. Two distinct levels of access exist, and both are logged.

Gridavera support staff can view your tenant’s activity records in order to diagnose problems, and can export them and provide them to your administrators on request.

Separately, with your administrator’s explicit opt-in, a member of Gridavera support can open a temporary session to read configuration and dimension lists in your SharePoint site while investigating an issue. These sessions require your administrator to enable the option first and are refused outright if they have not; are read-only, so support cannot create, modify or delete data through them; never expose transaction or fact data; expire automatically after 30 minutes by default and can never be issued for longer than 60 minutes; can be revoked by us or by you at any time; and are recorded in your own audit log, showing the individual support engineer’s identity, so every access is visible to you rather than only to us.

Support access never includes your Microsoft 365 credentials, and never includes workbook content, which we do not retain at all.

Support requests

When you submit a support request from inside the add-in, your recent session log is attached automatically so that we can diagnose the problem. It contains your recent add-in activity and identifiers such as your tenant ID. Before a log leaves your device, an automated filter removes recognised secrets and email addresses.

If you contact us by email instead, we process whatever you choose to send us.

Your SharePoint content

The add-in reads from and writes to the SharePoint lists you configure. That content stays in your Microsoft 365 tenant. We do not copy it into our systems and we do not retain it. Where a submission fails, we retain a short, automatically redacted extract of the error message returned by SharePoint in order to diagnose the failure.

Gridavera offers two write modes, and they differ in one respect that matters here. In Standard mode, the add-in writes to SharePoint directly using your own Microsoft 365 token, and the contents of your lists do not pass through Gridavera’s systems at any point. In Secure mode, writes are routed through a Gridavera Azure Function so that your users do not need direct write access to SharePoint. In that mode the values you submit pass through our infrastructure in transit. They are not stored there.

Your administrators can also browse SharePoint list contents and version history through the admin portal, including exporting a record’s change history or reconstructing a list as it stood on a chosen date. That content is read from your tenant when the page is opened and is not retained by us.

Configuration backups

If you use the backup feature, we store a copy of your Gridavera configuration in our cloud so that it can be restored. That configuration includes the user records described above, meaning user email addresses, role assignments and per-user access filters.

Data written into your workbook

When the add-in loads data into Excel, it writes metadata rows into the workbook that include the site name, the view name, the version, a timestamp, and the email address of the signed-in user. That information travels with the file wherever you send it.

Payment data

If you subscribe to a paid plan, payment processing is handled by Stripe. We do not store card numbers. We receive subscription status, plan details, and payment confirmation from Stripe. Stripe’s own privacy policy governs how it handles your payment information.

Webhooks

If your administrators configure a webhook, Gridavera sends platform event data to the endpoint they nominate. You choose the destination, and you are responsible for what happens to the data once it arrives.

5. What we collect through the website

This section covers gridavera.com only.

Contact form. If you send us a message, we collect your name, email address and the content of your message, together with the page you submitted it from. The message is delivered to us by email. It is not stored in the website database.

Booking a demonstration. The Contact page offers a booking calendar provided by TidyCal. It does not load until you choose to open it. If you open it and book a slot, TidyCal receives the name, email address and any details you enter, along with the other services listed in section 8.

Analytics. We use Google Analytics 4 to understand which pages are read and which campaigns bring visitors. See section 13.

Server and security logs. Our host and the site’s security plugin record requests to the site, including IP address, page path, user agent, and the time of the request. These are used to keep the site available and to detect attacks.

Pricing page. The pricing page fetches current plan information directly from our product backend when you open it, which means your IP address reaches that backend even if you never sign up.

6. How we use information, and on what basis

PurposeBasis
Providing, maintaining and improving the ServicePerformance of our contract with your organisation
Authenticating users and verifying subscriptionsPerformance of contract
Enforcing role and row-level access controlPerformance of contract
Sending transactional email: welcome, trial expiry, payment receipts, dunningPerformance of contract
Providing supportPerformance of contract
Keeping activity records, monitoring for abuse, securing the ServiceOur legitimate interest in operating a secure service
Website analyticsConsent
Responding to website enquiries and demonstration bookingsOur legitimate interest in responding to you, or steps prior to entering a contract
Meeting legal and accounting obligationsLegal obligation

We do not use your data for advertising, we do not sell your data, and we do not use your SharePoint content for any purpose other than delivering the Service.

7. Where information is stored

Your Gridavera account data, configuration, and activity records are stored in Microsoft Azure, in the UAE North region. This covers Azure SQL Database for account, subscription, configuration and activity data, Azure Key Vault for encryption keys and sensitive credentials, Azure Functions for backend processing, Azure Storage supporting the backend, and Azure Application Insights for diagnostic telemetry.

Database backups are geo-redundant, which replicates them to the paired Azure region, UAE Central. Both regions are inside the United Arab Emirates, so your Gridavera data does not leave the country.

Your SharePoint content remains in your own Microsoft 365 tenant and therefore follows your organisation’s own Microsoft 365 data residency settings.

The gridavera.com website is hosted separately by SiteGround, whose contracting entity is established in the United Kingdom. Website data described in section 5 is not stored in the Azure environment above, and none of it forms part of the Service.

8. The third parties we rely on

We use the following providers. We publish changes to this list before they take effect.

For the Service

ProviderEntityPurposeData
Microsoft AzureMicrosoft Corporation and its affiliatesInfrastructure, storage, key managementAccount data, configuration and activity records, all held in the UAE North region
Microsoft 365 and SharePointMicrosoft Corporation and its affiliatesThe data source the add-in reads and writesAuthentication tokens. Your content stays in your tenant
Microsoft Entra IDMicrosoft Corporation and its affiliatesAuthenticationSign-in identity
StripeStripe’s United Arab Emirates entity, as named on our invoicesPayment processing and billingEmail, plan, payment status
SendGridSendGrid, Inc. and Twilio Inc., both Delaware, USA. Global region, United StatesTransactional email: welcome, trial expiry, payment and dunning notices, provisioning confirmations, administrator succession approvalsRecipient name and email address, subject line, message content, and delivery events such as delivered, bounced or unsubscribed

For the website

ProviderEntityPurposeData
SiteGroundSiteGround Hosting Ltd., England and Wales (company number 09348602), with affiliate SiteGround Hosting EOOD, BulgariaWebsite hosting and securityIP address, page path, user agent
Google AnalyticsGoogle LLC and its affiliates, United StatesWebsite analytics, only after you accept analytics cookiesOnline identifiers, pages viewed, approximate location
SendGridSendGrid, Inc. and Twilio Inc., both Delaware, USADelivering contact form messages to usYour name, email address and the message you wrote, since the message is sent to us by email and your address is used as the reply address
TidyCalSumo Group Inc., USA, trading as TidyCalDemonstration booking, loaded only if you choose to open the calendarName, email address, booking details

If you open the booking calendar. The calendar is not loaded unless you ask for it. If you do choose to load it, TidyCal also brings in services we do not control: Microsoft Clarity, which records how the calendar is used, Google Tag Manager and a Google Analytics property belonging to TidyCal, Stripe for fraud prevention, and Bunny CDN, which serves TidyCal’s files. Nothing from this list loads if you do not open the calendar.

Typefaces are served from our own servers, so no font request is made to a third party.

9. International transfers

We are established in the United Arab Emirates, and everything to do with the Service stays there.

Your Gridavera data does not leave the United Arab Emirates. Account data, configuration and activity records are held in Azure UAE North, with backups replicated only to the paired Azure region, UAE Central. Payments are processed by Stripe’s United Arab Emirates entity. Your SharePoint content never leaves your own Microsoft 365 tenant, wherever your organisation has chosen that to be.

Two things do involve a transfer outside the United Arab Emirates, and neither concerns your planning data. The first is email delivery, through SendGrid in the United States, which affects the address we send to and the content of the message. The second is the gridavera.com website, which is hosted by SiteGround in the United Kingdom with an affiliate in Bulgaria. If you accept analytics cookies, Google Analytics processes website usage data in the United States, and if you choose to open the booking calendar, TidyCal processes your booking details in the United States.

Where personal data of individuals in the European Economic Area or the United Kingdom is transferred outside those areas, we have a data processing agreement in place with each provider involved, incorporating standard contractual clauses. We have accepted Google’s data processing terms for website analytics. Twilio’s data protection addendum forms part of our agreement with them for email, and because Twilio’s binding corporate rules do not cover the SendGrid service, the standard contractual clauses in that addendum are the mechanism. A data processing agreement is in place with SiteGround for website hosting.

10. How long we keep information

Account data is retained for as long as your account is active, and for 12 months after termination.

Activity records are retained for 12 months, then automatically deleted.

Diagnostic telemetry held in Azure Application Insights is retained for 90 days. The underlying log workspace retains for 30 days.

Database backups support point-in-time restore covering the last 7 days. No long-term backup retention is configured.

Configuration backups are retained according to your subscription tier, which sets how many versions are kept.

Website server and security logs are kept for a limited period so that we can keep the site available and investigate attacks, then discarded.

Contact form messages are retained in our support mailbox. They are not stored in the website database.

Email delivery records held by SendGrid, which record the recipient address, subject and outcome, are retained by SendGrid for a short period set by our plan. Suppression records, meaning addresses that bounced or unsubscribed, are kept until removed so that we do not email them again. We do not track whether you open our emails or click links in them.

Administrator succession approval links expire after 7 days.

The offline cache in the add-in holds configuration and an authentication token for 24 hours by default, configurable by your administrator, and is cleared on sign-out.

On termination we retain your account data and activity records for 12 months, after which they are deleted or anonymised. You may request earlier deletion at any time. Your SharePoint content is unaffected and stays in your Microsoft 365 tenant.

11. Security

All data is encrypted in transit using TLS 1.2 or higher, and at rest using Azure transparent data encryption.

If you enable Gridavera’s optional column-level encryption, values are additionally encrypted with AES-256-GCM before being written to SharePoint. The key is generated and held in Azure Key Vault. It is supplied to the add-in at the point of use in a form the browser cannot export, and it is never written into application configuration. Because we hold the key, a SharePoint administrator cannot read encrypted values, but Gridavera can.

We apply role-based access control, server-side row-level filtering, column-level edit permissions, and a permission check that is re-verified at the point of submission.

We access your tenant only through authorised Microsoft Graph and SharePoint APIs, using tokens scoped to your tenant. The add-in requests the Microsoft permissions User.Read and either Sites.Selected, which grants access only to the sites you nominate, or Sites.Read.All, depending on how your administrator configures it.

If something goes wrong. If a breach affects your personal data and is likely to result in a risk to you, we will notify the affected organisation without undue delay, and regulators where the law requires it.

12. Your rights

You can ask us to give you a copy of your data, correct it, delete it, export it, or stop processing it, and you can withdraw consent where we rely on consent.

Where to send the request. If it concerns your Gridavera account, your configuration, or the website, contact us at support@gridavera.com. If it concerns content in your organisation’s SharePoint lists, or your user record inside a customer’s Gridavera configuration, contact that organisation. As explained in section 3, we act on their instructions for that data, and we will support them in responding to you.

You can export your configuration yourself from the admin portal at any time.

If you are in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation, including the right to complain to your data protection authority.

13. Cookies and local storage

The Excel add-in stores your configuration and a short-lived authentication token in local storage on your device, so that the add-in can open when you are offline. The default is 24 hours, your administrator can change it, and signing out clears it.

The admin and ops portals use session storage for authentication. They do not set advertising cookies.

The gridavera.com website uses Google Analytics 4, which sets identifiers in your browser and processes them on Google’s infrastructure, so that we can see which pages are read and which campaigns bring visitors. We do not use it for advertising and we do not sell the data.

Analytics cookies are not set unless you accept them. If you decline, or if you make no choice at all, no analytics identifier is stored and no analytics data is collected. You can change your mind at any time through the cookie banner.

The website also sets a cookie recording your cookie choices.

The booking calendar on the Contact page is not loaded until you ask for it. If you choose to load it, it sets its own identifiers and those of the services listed in section 8.

14. Children’s privacy

Gridavera is a business application and is not intended for use by anyone under 16. We do not knowingly collect personal information from children.

15. Changes to this policy

We may update this policy. We will notify you of material changes by posting the updated policy here and updating the date at the top. Continuing to use the Service after a change takes effect means you accept the updated policy.

16. Contact us

Enabler Business Intelligence FZ-LLC
FDAM0994, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates
Email: support@gridavera.com
Website: www.gridavera.com

Scroll to top