Last updated 22 September 2026
Leysa helps IT teams run everyday Microsoft 365 tasks — onboarding, offboarding, password resets, access changes and reports — with approvals and an audit trail. This policy explains what information Leysa handles, why, where it's kept, and for how long. Questions: support@leysa.ai.
Who is responsible for what
For the people and data in your Microsoft 365 organisation, your organisation decides what Leysa is used for, and Leysa processes that information on your behalf. For the accounts of people who sign in to Leysa, Leysa is responsible for that information.
What we collect
- Your Leysa account: name, email address, the workspace you belong to, your role and which areas you can use.
- What you ask Leysa to do: the details entered into each automation (for example a new starter's name, job title, manager and groups), who requested it, who approved it, when, and the outcome of each step.
- Report results: when you run a report, the list it produces (for example user names, email addresses and last sign-in dates).
- Temporary passwords: when Leysa sets a password it is stored encrypted until the one-time link is opened or expires (at most 7 days), then destroyed.
- Microsoft 365 connection: your organisation's Microsoft tenant ID and a short-lived access token (encrypted).
- Early access requests: if you ask for early access on leysa.ai, the email address you enter and any name, company and company size you choose to add, so we can confirm your request, decide who to invite first and invite you. We send one confirmation when you ask and one email when trials open, and nothing else.
- Billing: if your workspace subscribes, our payment provider Stripe collects and holds the card details. Leysa never sees or stores them; we keep only Stripe's reference numbers for your account and subscription, and whether your plan is active.
- Trial record: so each Microsoft 365 organisation gets one free trial, we keep a one-way scrambled (hashed) form of its Microsoft tenant ID. It can't be turned back into the ID.
- AI assistant: messages you type are sent to our AI provider to get a reply. Leysa does not store the conversation.
- Technical data: error reports (with names, email addresses and IDs removed before they leave our servers) and basic request logs.
We don't sell personal information, use it for advertising, or read your mail or files.
Why we use it
- To run the automations you request and show you their results.
- To keep an audit trail of who did what, and to send the notifications and approvals you've set up.
- To keep the service secure, fix problems and prevent abuse.
Where it's stored
Leysa's database and servers are in Sydney, Australia. Some of the services listed below process data in other countries (for example email delivery and error reporting). Messages to the AI assistant are processed in the United States.
How long we keep it
- Run history (who ran what, on whom, and the outcome): 24 months.
- Report results: 90 days, after which the run stays in Activity but its list is cleared.
- One-time password links: destroyed when opened or when they expire (at most 7 days); a record that a link existed is kept for 30 days.
- In-app notifications: 90 days.
- Your account and workspace: until you delete them. The workspace Owner can delete the whole workspace in Settings → Profile, which removes everything above straight away.
- If a free trial or paid plan ends and isn't renewed: the workspace and everything in it is deleted 30 days later. The Owner is emailed 7 days before and again the day before.
- Early access requests: until you've been invited and created your account, or until you ask us to remove you.
- The hashed trial record: kept after a workspace is deleted, because its only purpose is to recognise an organisation that has already had a trial.
Services we use (sub-processors)
| Service | What for | Where |
|---|---|---|
| Vercel | Hosting the Leysa application | Sydney, Australia |
| Neon | Database | Sydney, Australia |
| Anthropic | AI assistant replies (not used to train its models) | United States |
| Resend | Sending emails (sign-in links, approvals, password links) | Japan |
| Stripe | Payments, subscriptions and invoices | United States |
| Sentry | Error reports, with personal details removed | United States |
| Cloudflare | Domain name service for leysa.ai | Global |
| Microsoft | Your own Microsoft 365 organisation, which Leysa acts on at your request | Your tenant's region |
Your rights
You can ask to see, correct or delete the personal information we hold about you, or object to how it's used, by emailing support@leysa.ai. If your information is in Leysa because of your employer's workspace, we'll work with them to respond. You can also complain to your local privacy regulator (in Australia, the Office of the Australian Information Commissioner).
Security
See our Security page for how data is protected. Report a security issue to security@leysa.ai.
Changes
We'll update the date at the top when this policy changes, and tell workspace Owners about significant changes.