Terms of Service
Please read these terms carefully before using ControlHub365
1 Introduction
Welcome to ControlHub365. These Terms of Service (“Terms”) govern your use of the ControlHub365 platform and services (“Service”) operated by PC Buddy 247 (“Company”, “we”, “us”, or “our”), a company registered in England and Wales.
By accessing or using our Service, you agree to be bound by these Terms. If you disagree with any part of these Terms, you may not access the Service.
ControlHub365 provides Microsoft 365 security monitoring, optimisation, and management services designed to help organisations protect and get the most from their Microsoft 365 environment.
2 Definitions
- “Customer” refers to the organisation or individual who subscribes to our Service.
- “End User” refers to individuals within the Customer’s Microsoft 365 tenant whose activity is monitored by the Service.
- “Tenant”refers to the Customer’s Microsoft 365 environment.
- “Audit Data” refers to the activity logs and metadata collected from the Customer’s Microsoft 365 tenant.
- “Platform” refers to the ControlHub365 web application and associated infrastructure.
3 Account Registration & Access
3.1 Eligibility
To use ControlHub365, you must:
- Be at least 18 years of age
- Have the authority to bind your organisation to these Terms
- Have Global Administrator or equivalent privileges in your Microsoft 365 tenant to grant the necessary API permissions
3.2 Account Security
You are responsible for:
- Maintaining the confidentiality of your account credentials
- All activities that occur under your account
- Notifying us immediately of any unauthorised access or security breach
3.3 API Permissions
ControlHub365 requires read-only API access to your Microsoft 365 tenant to function. By connecting your tenant, you consent to granting these permissions and confirm you have the authority to do so on behalf of your organisation.
4 Data Collection & Privacy
To provide our security monitoring and optimisation services, ControlHub365 collects and processes certain data from your Microsoft 365 environment. We are committed to transparency about what data we collect and how it is used.
4.1 Account & Registration Data
When you register for ControlHub365, we collect:
- Full Name – For account identification and communication
- Email Address – For account access, alerts, and support communications
- Company Name – For account records and billing purposes
- Phone Number – For support and urgent security notifications
4.2 Microsoft 365 Sign-In Activity Data
To detect suspicious logins and unauthorised access, we collect:
| Data Type | Purpose |
|---|---|
| Email Address | Identify which user performed the sign-in |
| IP Address | Detect logins from unusual or suspicious locations |
| Country/Location | Geographic analysis and impossible travel detection |
| Device Information | Identify device type, operating system, and browser used |
| Sign-In Status | Track successful logins, failures, and MFA challenges |
| Timestamp | Record when sign-in activity occurred |
4.3 Exchange & Mailbox Activity Data
To monitor for email-based threats and policy violations, we collect:
| Data Type | Purpose |
|---|---|
| Email Subject Lines | Identify bulk deletions and suspicious activity patterns |
| Folder Names | Track folder creation, deletion, and permission changes |
| Folder Activity | Monitor moves, deletions, and access to sensitive folders |
| Mail Rule Names | Detect hidden forwarding rules and malicious inbox rules |
| Mail Rule Configuration | Analyse rule actions (forward, delete, move) for threats |
| Mailbox Permissions | Track delegate access and permission changes |
Important: ControlHub365 does not access, read, or store the content/body of emails. We only collect metadata (subject lines, folder names, rule names) necessary for security monitoring purposes.
4.4 Administrative Activity Data
To detect privilege escalation and unauthorised changes, we monitor:
- Admin role assignments and changes
- User creation, modification, and deletion
- Group membership changes
- Application consent grants
- Security policy modifications
4.5 Data Storage & Retention
All data collected by ControlHub365 is:
- Processed and stored exclusively in United Kingdom data centres
- Encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Retained for 12 months from collection date, unless otherwise agreed
- Automatically deleted after the retention period expires
4.6 Data Sharing
We do not sell, rent, or trade your data. We only share data in the following circumstances:
- With your organisation’s administrators – To provide security alerts and reports
- With service providers – Limited to infrastructure providers necessary to operate the Service, bound by confidentiality agreements
- For legal compliance – When required by law, court order, or regulatory authority
- With your consent – For any other purpose, only with your explicit permission
5 Service Description & Limitations
5.1 Service Scope
ControlHub365 provides:
- Automated monitoring of Microsoft 365 audit logs
- AI-powered risk assessment and alerting
- Security event notifications and reports
- User verification prompts for suspicious activity
- Long-term audit log retention
5.2 Service Limitations
ControlHub365 is a monitoring and alerting service. We do not :
- Guarantee prevention of all security incidents
- Provide insurance or indemnification against breaches
- Replace the need for comprehensive security policies and training
- Take automated remediation actions without explicit configuration (Managed Security tier only)
5.3 Service Availability
We strive for 99.9% uptime but do not guarantee uninterrupted service. Scheduled maintenance will be communicated in advance where possible. Service availability depends on Microsoft 365 API availability, which is outside our control.
6 Subscription & Payment
6.1 Pricing
Pricing is based on the number of licensed Microsoft 365 users in your tenant. Current pricing is available on our website. We reserve the right to modify pricing with 30 days' notice.
6.2 Billing
Subscriptions are billed monthly in advance per user with an active paid Microsoft 365 licence (Business Basic, Business Standard, Business Premium, E3, E5, etc.). User counts are reviewed at the end of each billing period. Unlicensed users, shared mailboxes without a licence, users with only free licences, and guest accounts are not counted. Annual billing is available on request, with usage reviewed every 3 months.
6.3 Free Trial
ControlHub365 trial includes all monitoring features with no restrictions. Managed 365 trial includes full security monitoring and incident response. Advanced security measures and 365 administration (user management, policies) activate on valid subscription.
6.4 Refunds
Annual subscriptions may be cancelled within 14 days of purchase for a full refund. After 14 days, annual subscriptions are non-refundable but will remain active until the end of the billing period. Monthly subscriptions may be cancelled at any time and will remain active until the end of the current billing period. No refunds are provided for partial months.
6.5 Minimum Licence
A minimum of 1 user licence is required. Non-licensed users, shared mailboxes, and external guests are covered at no additional cost.
7 Customer Responsibilities
As a Customer, you agree to:
- Provide accurate and complete registration information
- Maintain valid Global Administrator or equivalent access for API connectivity
- Inform affected End Users that their Microsoft 365 activity is being monitored
- Comply with all applicable data protection laws, including GDPR
- Use the Service only for lawful business purposes
- Not attempt to reverse engineer, decompile, or extract source code from the Platform
- Not resell or redistribute the Service without written consent
8 Intellectual Property
The ControlHub365 platform, including all software, designs, logos, and documentation, is the intellectual property of PC Buddy 247. Your subscription grants you a limited, non-exclusive, non-transferable licence to use the Service for your internal business purposes only.
You retain ownership of all data you provide to us. We claim no ownership over your Microsoft 365 data or audit logs.
9 Limitation of Liability
To the maximum extent permitted by law:
- Our total liability for any claims arising from the Service shall not exceed the fees paid by you in the 3 months preceding the claim
- We are not liable for any indirect, incidental, special, consequential, or punitive damages
- We are not liable for any losses resulting from security breaches, data loss, or service interruptions beyond our reasonable control
- We are not liable for actions taken or not taken based on alerts or reports generated by the Service
10 Indemnification
You agree to indemnify and hold harmless PC Buddy 247, its owners, employees, and agents from any claims, damages, or expenses arising from:
- Your use of the Service
- Your breach of these Terms
- Your violation of any applicable laws or regulations
- Your failure to inform End Users of monitoring activities
11 Termination
11.1 By You
You may terminate your subscription at any time by contacting us. Your access will continue until the end of the current billing period.
11.2 By Us
We may suspend or terminate your access immediately if:
- You breach these Terms
- You fail to pay applicable fees
- Your use poses a security risk to our Platform or other customers
- Required by law or regulatory authority
11.3 Effect of Termination
Upon termination:
- Your access to the Platform will be revoked
- Your data will be retained for 30 days, during which you may request export
- After 30 days, all your data will be permanently deleted
- We will disable auditing and monitoring of your Microsoft 365 tenant. Support and management services will cease immediately. You may revoke API access to your tenant at any time via your Microsoft 365 Admin Center.
12 Changes to Terms
We may update these Terms from time to time. We will notify you of any material changes by email or through the Platform at least 30 days before they take effect. Continued use of the Service after changes become effective constitutes acceptance of the new Terms.
13 Governing Law & Disputes
These Terms are governed by the laws of England and Wales. Any disputes arising from these Terms or the Service shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Before initiating legal proceedings, both parties agree to attempt to resolve disputes through good-faith negotiation for a period of at least 30 days.
14 General Provisions
- Entire Agreement: These Terms constitute the entire agreement between you and PC Buddy 247 regarding the Service.
- Severability: If any provision of these Terms is found unenforceable, the remaining provisions shall continue in effect.
- Waiver: Failure to enforce any provision does not constitute a waiver of that provision.
- Assignment: You may not assign your rights under these Terms without our written consent. We may assign our rights to a successor in the event of a merger, acquisition, or sale of assets.
- Force Majeure: We are not liable for delays or failures caused by circumstances beyond our reasonable control.
Questions About These Terms?
If you have any questions about these Terms of Service, please contact us:
PC Buddy 247 , 18 Dallisons road, Hibaldstow, North Lincolnshire, ENG, United Kingdom