(Version: Oktober 2025)
1. Introduction
This Privacy Policy explains how 4 Dash Solutions GmbH (“we”, “us”, or “our”) handles information in connection with the Copilot Companion app.
Copilot Companion is a Copilot Agent developed for use within the Microsoft ecosystem. It supports organizations in adopting and using Microsoft Copilot effectively.
We take privacy and data protection seriously. This policy describes the limited data interactions that may occur when using Copilot Companion.
2. Data Responsibility
4 Dash Solutions GmbH acts as an independent provider of the Copilot Companion Agent.
The Agent operates within the Microsoft environment and uses Microsoft identity, access, and data services.
In most scenarios, we do not have direct access to user or organizational data.
Any processing or storage of user content, prompts, or context data is handled by Microsoft under its own privacy and compliance framework.
3. Data Collected or Accessible
Copilot Companion itself is designed to minimize data collection.
Depending on your organization’s configuration and Microsoft’s data policies, the following limited data interactions may occur:
- Usage metadata: Non-personal information such as timestamps, feature usage frequency, or diagnostic events, provided automatically by Microsoft.
- License and billing data: Information about subscriptions, purchases, or renewals via the Microsoft Marketplace.
- Support inquiries: If you contact us (e.g. via email), we may process your name, contact details, and request information.
We do not intentionally collect or store user-generated content (e.g., chat prompts, Copilot results, documents, or emails).
4. Data Processing by Microsoft and Third Parties
Copilot Companion runs entirely within Microsoft infrastructure.
Any data processing related to user authentication, chat context, or AI interactions is managed by Microsoft Corporation and its affiliated entities.
We have no control over and no insight into where or how Microsoft stores or processes customer data.
For details on Microsoft’s data processing, please refer to the official documentation:
👉 Microsoft Privacy Statement
When Copilot Companion triggers external actions or integrations (e.g., Microsoft Teams, SharePoint, Power Automate), data may be transmitted to those services under the user’s control and configuration.
5. Purpose and Legal Basis
Any data potentially processed by us is used solely for:
- Maintaining service functionality and reliability
- Providing customer support and license verification
- Meeting legal and contractual obligations (e.g. billing, compliance)
The legal basis for processing such data is Art. 6(1)(b) and (f) GDPR (performance of a contract and legitimate interest).
6. Data Storage and Retention
We do not store customer data from Copilot Companion sessions on our own systems.
Any technical or billing data received via Microsoft is retained only as long as legally required (e.g. accounting retention periods under § 147 AO).
Diagnostic or support-related data is deleted after the issue is resolved, unless statutory retention periods apply.
7. Data Security
All data transmissions between Copilot Companion and Microsoft services are protected by TLS encryption.
We apply technical and organizational measures to protect any limited information we process (e.g. support data, license info) against unauthorized access or disclosure.
8. User Rights under GDPR
If and to the extent we process personal data, you have the following rights under GDPR:
- Right to access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
Requests can be directed to:
📧 datenschutz@4-dash.de
If your data is processed within Microsoft systems, we may forward your request to Microsoft, which acts as the data controller in that case.
9. Data Transfers and International Processing
Since all core processing occurs within Microsoft’s systems, international data transfers (e.g. to the USA) may occur according to Microsoft’s compliance framework.
Microsoft provides adequate safeguards through EU Standard Contractual Clauses (SCCs) and other approved mechanisms.
4 Dash Solutions GmbH does not initiate or control such data transfers.
10. Children’s Privacy
Copilot Companion is intended for business use and not directed at children under 16 years of age. We do not knowingly collect or process data from minors.
11. Updates to This Policy
We may update this Privacy Policy to reflect changes in law, Microsoft infrastructure, or our own business operations.
The latest version will always be available at the link provided in the Microsoft Store listing.
12. Contact Information
4 Dash Solutions GmbH
Rosenstraße 61
66773 Schwalbach, Germany
📧 datenschutz@4-dash.de
Supervisory authority for data protection complaints:
Landesbeauftragte für Datenschutz und Informationsfreiheit Saarland
Postfach 10 26 22, 66026 Saarbrücken
www.datenschutz.saarland.de
13. Legal Notice
- For all transactions via Microsoft Marketplace, 4 Dash Solutions GmbH uses the Standard Contract for Microsoft Marketplace as the End User License Agreement (EULA).
- Microsoft acts as the data controller for all processing conducted within its own environment.
- 4 Dash Solutions GmbH does not independently store, analyze, or resell user data from Copilot Companion.
