Logo Global Meeting Scheduler

Privacy Statement & Data Protection Policy

Last Updated: September 17, 2026 • Publisher: Michael Joseph Francis (mjfnet.com • MPN ID: 7131198)

1. Commitment to Privacy & Zero Knowledge

The Global Meeting Scheduler Outlook Add-in and its companion TzPlanner API (collectively, "the Service") are designed to optimize cross-time-zone meeting schedules without compromising employee privacy or creating surveillance risks.

Core Privacy Guarantee: The Service operates under strict principles of Zero Knowledge and Least Privilege. We do not harvest personal data, do not read meeting contents, and do not maintain centralized employee surveillance databases.

2. Data We Process Transiently in Memory

During active scheduling sessions, the Service reads the following parameters strictly in volatile computer memory to compute fair meeting suggestions:

Data Category Source Purpose
Organizer Profile Microsoft Entra ID / Graph (User.Read) Identifies organizer's local time zone and default working hours.
Attendee Time Zones & Hours Microsoft Graph (MailboxSettings.Read / User.Read.All) Evaluates whether proposed meeting slots fall within attendees' configured working hours.
Group Memberships Microsoft Graph (GroupMember.Read.All) Expands invited Distribution Lists and Microsoft 365 Groups to assess time zone impact for all members.

3. What We NEVER Access or Store

❌ No Meeting Content We never inspect, process, or store meeting subjects, agendas, body text, or attachments.
❌ No Email Inspection We never access email messages, inbox folders, or personal communications.
❌ No Activity Tracking We do not record keystrokes, mouse activity, active window time, or GPS locations.
❌ No Advertising / Tracking Zero third-party marketing cookies, tracking beacons, or telemetry brokers.

4. Service Operational Telemetry (Application Insights)

The TzPlanner API uses Microsoft Azure Application Insights, a first-party monitoring service hosted within the publisher's own Azure subscription, to monitor API health, error rates, and tenant-level adoption trends. This is operational service telemetry, not third-party marketing or advertising analytics.

What Is Collected: HTTP method and route template, response status code, request duration, the calling organization's Microsoft Entra tenant ID (an organizational GUID), and a pseudonymized, one-way salted cryptographic hash of the user identifier (truncated SHA-256). This hash enables aggregate reporting (such as Daily and Monthly Active Users) without storing or exposing raw employee identifiers, user GUIDs (oid), names, or emails.

What Is Automatically Redacted: Some API routes include an attendee's email address in the request path (e.g. /api/profiles/{email}) or in downstream Microsoft Graph calls. Before any telemetry leaves the API process, a redaction processor strips these email addresses from logged URLs and dependency call data, so raw attendee emails are never persisted in Application Insights.

Retention & Access: Telemetry is retained under standard Azure Application Insights retention policy and is accessible only to the publisher via Azure role-based access control. It is never shared with third parties.

5. Privacy-Preserving Hashed Storage Architecture

To comply with European Works Council regulations (BetrVG § 87) and EU GDPR Article 88 (Data Processing in the Employment Context), attendee identifiers are protected using cryptographic hashing:

  • Domain-Salted SHA-256 Hashing: Attendee email addresses are converted into one-way cryptographic hashes before caching preferences.
  • PII Stripping: Real names and email addresses are permanently excluded from storage payloads (`localStorage` and Exchange `roamingSettings`).
  • Non-Adversarial Cohort Aggregation: Collective disruption reports use regional cohort summaries rather than exposing individual employee fatigue surveillance.

6. Security & Technical Safeguards

All communication between your Outlook client and the TzPlanner API is encrypted using **TLS 1.3** and secured via **Microsoft Entra ID Nested App Authentication (NAA)**. No user passwords or long-lived authentication keys are stored by the application.

7. Data Subject Rights & Data Erasure

Under GDPR, CCPA, and global privacy frameworks, users have the right to access, rectify, or purge their data:

  • One-Click Cache Reset: Organizers can clear all local cached preferences anytime in the Add-in Settings panel.
  • Tenant Revocation: Administrators can revoke tenant authorization instantly in the Microsoft Entra admin center.

8. Contact & Inquiries

For inquiries regarding this privacy statement or data protection policies, please contact:

Developer / Publisher: Michael Joseph Francis
Domain: mjfnet.com
Email: gms-privacy@mjfnet.com / gms-support@mjfnet.com