Skip to Microsoft 365 data details

Optional Microsoft 365 connection

Microsoft 365, connected on purpose.

Osynk accesses a Microsoft 365 mailbox only after an authorised user chooses Email Intelligence, reads the in-product disclosure, and continues to Microsoft's permission screen. Mailbox access is never enabled by default.

Exact access

The permission matches the job.

Email Intelligence requests only the Microsoft Graph permissions needed to ingest eligible customer email and send visible replies through the connected mailbox. All four are delegated permissions, which means Osynk acts only as the signed-in user and only on that user's mailbox.

Mail.Read

Read mailbox content

Used by Email Intelligence to ingest eligible customer email into the selected Business Unit.

  • Reads relevant messages, headers, participants, bodies, folders, and attachments.
  • Imports selected content into the customer's Osynk workspace.
  • Supports routing, business records, evidence, and user-visible email workflows.
Mail.Send

Send through the mailbox

Used by Email Intelligence to send user-visible replies through the connected mailbox.

  • Sends messages or replies through the connected mailbox.
  • Does not permit Osynk to delete mailbox messages.
  • Does not permit Osynk to modify or delete existing mailbox messages.
User.Read

Identify the connection

Used to show and verify which Microsoft account completed the connection.

  • Reads the signed-in user's basic profile and mailbox address.
  • Prevents the wrong mailbox from being attached during a reconnect.
  • Does not grant access to Teams, SharePoint, OneDrive, or Calendar, and does not use Microsoft as the Osynk sign-in method.
offline_access

Keep the connection working

Used to refresh access without asking the user to sign in again for every sync.

  • Issues a refresh token so scheduled mailbox synchronisation can continue.
  • Grants no additional data beyond the permissions listed above.
  • Stops working once the grant is revoked at the Microsoft end.

For Microsoft 365 administrators

Your tenant policy decides who can approve this.

Mailbox permissions are not in Microsoft's default low impact set. In many Microsoft 365 organisations an administrator, rather than the individual user, has to approve the connection. That is a decision made by your tenant's consent policy, not by Osynk.

1

User consent

Where tenant policy permits it, the mailbox owner approves the connection for their own mailbox on Microsoft's permission screen.

2

Administrator consent

Where tenant policy requires it, Osynk directs the user to request approval. An administrator reviews the same permission list before any mailbox data is read.

3

Administrator removal

An administrator can remove the Osynk enterprise application from the tenant at any time, which ends access for every mailbox connected under it.

Before access begins

Microsoft access happens in this order.

Visiting Osynk or opening a mailbox setup page does not connect a mailbox. The user must take the affirmative consent step.

01

Choose Email Intelligence

An authorised workspace user starts the Microsoft 365 mailbox setup.

02

Read the disclosure

Osynk explains the purpose, access, retention, regions, and deletion behavior.

03

Continue to Microsoft

Microsoft lists the requested permissions and asks the account holder, or a tenant administrator, for approval.

04

Use Email Intelligence

Only the approved connection can read or send mailbox data for the disclosed purpose.

Two independent controls

Storage location is not AI location.

Customers select these separately. The authenticated disclosure shown before consent presents the workspace's actual choices.

Data Storage Region

Durable customer files and backups

The workspace's storage choice controls the configured regional stores for durable customer files and backups.

European UnionUnited StatesCanada

This selector is not a blanket claim about primary databases, identity and session data, security logs, or data that remains within Microsoft's systems.

AI Processing Region

Amazon Bedrock inference

Where an Email Intelligence workflow uses AI, the relevant content is processed through Amazon Bedrock in the chosen AI geography.

European UnionUnited StatesCanada

AI Processing Region can differ from Data Storage Region. If a required Bedrock capability is unavailable in the selected geography, Osynk does not silently reroute it elsewhere.

Retention and control

Disconnect stops access. Revocation happens at Microsoft.

These are separate actions, and Osynk states plainly what it can and cannot do. Disconnecting a mailbox permanently deletes Osynk's stored Microsoft credentials for that mailbox and stops all further synchronisation and sending. Osynk cannot itself withdraw the permission you granted: removing a delegated grant requires tenant administrator permissions that Osynk deliberately never requests. The grant is withdrawn at the Microsoft end, by the mailbox owner or an administrator. Disconnect also does not erase messages, attachments, or business records already imported into the workspace.

1

Disconnect the mailbox

Use Email Intelligence mailbox settings. Osynk deletes the stored access and refresh tokens for that mailbox and stops reading and sending immediately.

2

Withdraw the permission at Microsoft

Review and remove Osynk under your own account at myapplications.microsoft.com. A Microsoft 365 administrator can instead remove the Osynk enterprise application from the tenant, which ends access for every mailbox connected under it.

3

Delete imported content

Delete the relevant record or account content using Osynk's controls, or follow the Data Deletion instructions. Email Intelligence evidence can remain after disconnect until the customer deletes the corresponding data or account.

4

Backup rotation completes deletion

Deleted copies can remain inside encrypted rolling backups for up to 30 days, after which the rotated copy is no longer retained, subject to documented legal-retention exceptions.

How the data is used

Your mailbox data is used for the feature you chose.

Osynk uses Microsoft Graph data only to provide or improve the visible feature the customer enabled, secure it, comply with law, or respond to the customer's support request. Where an Email Intelligence workflow uses AI, the relevant content is processed through Amazon Bedrock in the workspace's chosen AI geography, and customer content is not used to train generalized or foundation models.

Not soldNot used for advertisingNot used for creditworthinessNot used to train generalized AI modelsNo unrelated human reading

One honest detail about revocation timing: if you withdraw the permission at Microsoft without also disconnecting in Osynk, an access token Osynk already holds can remain technically valid until it expires. No new token is issued after revocation, and disconnecting in Osynk deletes the stored tokens outright.

Full documents

The short page links to the long rules.

These documents govern Osynk's handling of personal data, service use, and deletion requests.

Questions or deletion requests: contact@osynk.ai