Terms & Conditions
Last updated: 16 August 2026 • Version 4.0
Please read these Terms and Conditions carefully before using dotCLOUD Assessor. These terms govern your access to and use of our Microsoft 365 security assessment platform.
Legal
Terms and Conditions
The terms on which dotCLOUD Consulting (Schweiz) GmbH provides the dotCLOUD Assessor Microsoft 365 security and compliance assessment platform to business customers.
1 The provider
- Legal entity
- dotCLOUD Consulting (Schweiz) GmbH
- Registered office
- Bahnhofstrasse 9
8952 Schlieren
Switzerland - Commercial register
- CHE-450.836.600
- Telephone
- +41 (43) 217 80 40
- contact@dotcloud.ch
- Platform
- assessor.dotcloud.pro
2 Definitions
- “dotCLOUD”, “we”, “us”
- dotCLOUD Consulting (Schweiz) GmbH, as identified in clause 1.
- “Customer”, “you”
- The legal entity that registers for and uses the Service. The Service is offered to businesses and other organisations only, and not to consumers.
- “Service” or “Platform”
- The dotCLOUD Assessor software-as-a-service platform made available at assessor.dotcloud.pro, including the assessment engine, the customer portal and the reports it produces.
- “Tenant”
- The Customer’s Microsoft 365 / Microsoft Entra ID directory to which the Service is connected.
- “Authorised User”
- An individual authorised by the Customer to access the Service using a Microsoft 365 work or school account belonging to the Tenant.
- “Admin Consent”
- The tenant-wide grant of application permissions made by a Global Administrator of the Tenant on Microsoft’s consent screen, which is a precondition to any assessment.
- “Assessment”
- A scan of the Tenant’s configuration against the control set implemented by the Service, and the resulting findings, evidence and score.
- “Report”
- A document generated by the Service that presents the results of an Assessment.
- “Customer Data”
- Data relating to the Customer that is processed by the Service, including configuration data read from the Tenant, Assessment evidence, and account and registration data.
- “DPA”
- The Data Processing Agreement between the parties governing our processing of personal data as processor.
3 Scope and acceptance
3.1 These Terms and Conditions (the “Terms”) govern the Customer’s access to and use of the Service. They are accepted when the Customer submits a registration for the Service, when an Authorised User first signs in, or when the Service is otherwise used, whichever occurs first.
3.2 These Terms, together with the DPA, our Privacy Policy and any order form, quotation or written service description agreed between the parties, constitute the entire agreement for the Service. In the event of conflict, the order form prevails over these Terms, and these Terms prevail over any other document.
3.3 Any general terms and conditions of the Customer are expressly excluded and do not become part of the agreement, even if we do not object to them and perform the Service without reservation.
3.4 The Service is provided exclusively to businesses and other organisations acting in a professional capacity. It is not directed at consumers.
4 The Service
4.1 dotCLOUD Assessor performs automated security and compliance assessments of a Microsoft 365 tenant. It connects to the Tenant using Microsoft Graph and the administrative interfaces published by Microsoft, evaluates the Tenant’s configuration against recognised security baselines, assigns a severity-weighted score, and presents prioritised findings and remediation guidance.
4.2 Assessments are evaluated against a control set derived from the CIS Microsoft 365 Foundations Benchmark, supplemented by dotCLOUD’s own security baseline. References to frameworks such as ISO 27001, NIST or Cyber Essentials are provided as subject-matter mappings for the Customer’s convenience.
Such references do not constitute certified equivalence, a certification, an accreditation, or an audit opinion, and neither the Service nor any Report certifies compliance with any standard, framework or legal obligation.
4.3 Certain controls in the benchmark cannot be evaluated through any published Microsoft interface. The Service identifies these openly as requiring manual verification and excludes them from the score, rather than presenting an unverified result. A result of “needs review” means that a control could not be determined automatically; it does not mean the control has failed, nor that it is satisfied.
4.4 A completed Report becomes visible to the Customer when released within the Service. dotCLOUD may review an Assessment before release for quality assurance purposes.
4.5 We may improve, modify or extend the control set, the scoring methodology and the functionality of the Service. Because scoring methodology may change, scores from Assessments run at different times are not necessarily comparable; historic scores are preserved as issued and are not recalculated.
5 Registration and approval
5.1 Registration is by application. Submitting the registration form creates a request only; it does not create an account, does not create a tenant record, and does not grant access. We may accept or decline any application at our discretion and are not obliged to give reasons.
5.2 Access to the Service is granted exclusively through Microsoft Entra ID authentication. The Service maintains no passwords. We do not issue, store or reset credentials, and Authorised Users must not be asked to create any.
5.3 The Customer is responsible for the acts and omissions of its Authorised Users, for keeping the list of Authorised Users current, and for promptly disabling accounts in its own directory when access should cease. Because authentication is performed by Microsoft, removing or disabling an account in the Tenant removes access to the Service.
6 Authority to grant Admin Consent
6.1 Before any Assessment can be performed, a Global Administrator of the Tenant must grant Admin Consent to the application permissions set out in the Service’s Security & Privacy Center and in our Privacy Policy.
6.2 The Customer warrants that the individual granting Admin Consent is duly authorised to do so on behalf of the Customer, that the Customer has the right to permit the Service to read the Tenant’s configuration, and that all internal approvals, notifications, consultations and works council or similar procedures required in the Customer’s organisation have been completed beforehand.
6.3 The Customer may pause the connection at any time within the Service, or revoke consent entirely by removing the enterprise application in the Microsoft Entra admin centre. Pausing takes effect immediately, and an Assessment that has been queued but not yet started will be cancelled rather than executed.
6.4 Where consent is paused, revoked, or where Microsoft withdraws or restricts the permissions, the Service will be unable to perform Assessments. This is not a defect in the Service, and no liability arises from it.
7 Read-only scope
7.1 The Service is read-only in respect of the Tenant. It does not create, modify or delete any object, setting, policy or user in the Customer’s Microsoft 365 environment, and it will not do so even at the request of an administrator. Remediation of findings is performed by the Customer, or under a separate engagement.
7.2 The Service evaluates configuration and telemetry metadata only. It does not read, process or store the contents of mailboxes, files, documents, Teams chats or channel conversations, meeting recordings, calendars, or any other user communication or content, and it does not access passwords, password hashes, authentication codes or session tokens. This is a contractual commitment, and it is enforced by the permissions the Service requests and by the design of the assessment engine.
7.3 Where a finding must identify an object in order to be actionable, the Service records identifiers and display names — such as a mailbox address, group name or policy name — and nothing more.
8 Nature of the assessment
8.1 An Assessment is an automated technical evaluation of tenant configuration at a point in time. It reflects only the state that the Service was able to read at the moment the scan ran, and only in respect of the controls it implements.
8.2 An Assessment is not a penetration test, a vulnerability scan of endpoints or networks, a forensic investigation, an audit within the meaning of any auditing standard, a legal opinion, or a statement of compliance with any statute, regulation or certification scheme.
8.3 A Report does not warrant that the Tenant is secure, that no vulnerability or misconfiguration exists outside the evaluated control set, or that a breach or compromise has not occurred or will not occur. A favourable score does not evidence the absence of risk.
8.4 The Service depends on interfaces operated by Microsoft. Availability, completeness and accuracy of the data returned by those interfaces, and the licensing tier of the Tenant, may limit what can be evaluated. Where data is unavailable, the Service reports the control as undetermined rather than inferring a result.
8.5 The Customer remains at all times responsible for the security, configuration, administration and regulatory compliance of its own Microsoft 365 environment.
9 Implementing recommendations
9.1 Reports contain remediation guidance, which may include configuration steps and PowerShell or command-line examples. That guidance is advisory.
These recommendations are based on standard Microsoft 365 security baselines and CIS benchmarks. Every IT environment is unique. Applying these changes may impact user workflows, legacy applications, or third-party integrations. Please review carefully and verify all PowerShell commands before executing them in a production environment. dotCLOUD assumes no liability for system disruptions caused by implementing these changes.
9.2 The Customer is solely responsible for deciding whether to implement any recommendation, for assessing its impact on the Customer’s environment, for testing it before deployment to production, and for maintaining the ability to reverse it. We strongly recommend that changes be validated in a test environment or against a limited pilot group first.
9.3 Nothing in a Report constitutes an instruction to make a change, and the presence of a finding does not oblige the Customer to act on it.
10 Customer obligations
The Customer shall:
- provide accurate and complete registration information and keep it up to date;
- ensure that Admin Consent is granted only by a duly authorised person (clause 6);
- ensure that its use of the Service, and its provision of access to the Tenant, complies with all laws applicable to it, including data protection and employment law;
- make any internal notifications to its own personnel that such law requires;
- keep Reports and exported data secure, given that they describe the configuration of the Customer’s environment;
- notify us without undue delay of any unauthorised access to the Service of which it becomes aware.
11 Acceptable use
The Customer shall not, and shall not permit any third party to:
- connect the Service to a Microsoft 365 tenant that the Customer is not authorised to have assessed;
- use the Service to assess a third party’s environment without that party’s documented authorisation;
- attempt to gain unauthorised access to the Service, to another customer’s data, or to the underlying infrastructure;
- probe, scan or test the vulnerability of the Service, or circumvent any authentication, rate-limiting or access control, without our prior written consent;
- reverse engineer, decompile or disassemble the Service, or attempt to derive its source code or control logic, except to the extent such restriction is prohibited by mandatory law;
- resell, sublicense, or make the Service available to third parties as a service, other than under an agreed partner arrangement;
- use the Service in a way that interferes with its operation or impairs its availability to others.
12 Availability and support
12.1 We will use commercially reasonable endeavours to make the Service available, but unless a service level agreement has been separately agreed in writing, the Service is provided without any guaranteed level of availability.
12.2 Planned maintenance will be notified in advance within the Service where reasonably practicable. Urgent maintenance necessary to preserve security or integrity may be carried out without notice.
12.3 Assessments are executed as queued background work. Duration varies with the size of the Tenant, the scope requested and the responsiveness of Microsoft’s interfaces, including request throttling applied by Microsoft. No completion time is guaranteed.
12.4 Support is provided by email during Swiss business hours (Monday to Friday, 08:00 to 17:00 CET, excluding public holidays at our registered office), unless otherwise agreed.
12.5 For support purposes, authorised dotCLOUD personnel may view the Service as the Customer sees it. Such access requires a recorded business justification, is read-only, is time-limited, and is written to a tamper-evident audit record. It does not extend the permissions held against the Tenant.
13 Fees and payment
13.1 Fees, the subscription term, the number of tenants covered and the assessment volume included are as stated in the applicable order form or quotation. Where no fee has been agreed, the Service is provided for evaluation purposes only and may be withdrawn at any time.
13.2 Unless stated otherwise, all fees are exclusive of value added tax and other applicable duties, which are payable in addition by the Customer.
13.3 Invoices are payable within 30 days of the invoice date without deduction. In the event of late payment, we may charge default interest at the statutory rate and may suspend the Service in accordance with clause 21.
13.4 The Customer may not set off any claim against our fees unless the claim is undisputed or has been finally determined by a competent court.
14 Intellectual property
14.1 The Service, including its software, assessment engine, control mappings, remediation library, scoring methodology, report templates, documentation and branding, remains the exclusive property of dotCLOUD or its licensors. Nothing in these Terms transfers any intellectual property right.
14.2 Subject to payment of the applicable fees, the Customer is granted a non-exclusive, non-transferable, non-sublicensable right, for the term of the agreement, to access and use the Service for its own internal business purposes.
14.3 The Customer may use, reproduce and share Reports internally, and may disclose them to its auditors, insurers and professional advisers, provided that such recipients are bound by an obligation of confidentiality. Reports may not be published, or used for the purpose of marketing a competing service, without our prior written consent.
14.4 Configuration data read from the Tenant, and the Assessment evidence derived from it, remain the Customer’s. We may compile aggregated and irreversibly anonymised statistics that do not identify the Customer, any Tenant or any individual, and may use those statistics to improve and benchmark the Service.
14.5 Where the Customer submits feedback or suggestions, we may use them without restriction or obligation.
15 Confidentiality
15.1 Each party shall keep confidential all non-public information of the other party that is disclosed in connection with the Service and is either marked as confidential or would reasonably be understood to be confidential. Assessment results and Reports are the Customer’s confidential information.
15.2 Confidential information may be disclosed only to those personnel and sub-contractors who need it in order to perform the agreement and who are bound by equivalent obligations.
15.3 These obligations do not apply to information that is or becomes public without breach, was lawfully known before disclosure, is independently developed, or must be disclosed by law or by order of a competent authority — in which case the disclosing party shall, where lawful, inform the other party in advance.
15.4 These obligations survive termination for a period of five years, and indefinitely in respect of information that constitutes a trade secret.
16 Data protection
16.1 Each party shall comply with the data protection law applicable to it, including the Swiss Federal Act on Data Protection and, where applicable, the EU General Data Protection Regulation and the UK GDPR.
16.2 In respect of personal data contained in Tenant configuration and Assessment evidence, the Customer acts as controller and dotCLOUD acts as processor. That processing is governed by the DPA, which meets the requirements of Article 28 GDPR and forms an integral part of this agreement. Acceptance of the DPA within the Service is a precondition to Assessments being performed.
16.3 We process personal data only on the Customer’s documented instructions, which comprise this agreement, the DPA and the Customer’s use of the Service, save where required otherwise by law binding on us.
16.4 Details of the data processed, hosting location, sub-processors, retention periods and security measures are set out in our Privacy Policy, which forms part of these Terms.
16.5 The Customer acknowledges that the audit records described in the Privacy Policy are held in an append-only ledger and, by design, cannot be altered or deleted. Those records contain identities and actions, never message or file content.
17 Sub-contractors
17.1 We may engage sub-contractors and sub-processors in the provision of the Service, and remain responsible for their performance as for our own.
17.2 The Service is hosted on Microsoft Azure and depends on interfaces operated by Microsoft. The Customer acknowledges that the Service cannot be provided without them.
18 Warranties and disclaimers
18.1 We warrant that the Service will be provided with the reasonable skill and care to be expected of a competent provider of comparable services.
18.2 Save as expressly stated in these Terms and to the fullest extent permitted by applicable law, the Service and all Reports are provided “as is” and “as available”. We give no warranty that the Service will be uninterrupted or error-free, that every misconfiguration or vulnerability will be detected, that any finding is free from error, or that the Service or any Report will meet the Customer’s particular requirements or achieve compliance with any standard or legal obligation. All warranties, conditions and terms implied by statute or common law are excluded to the maximum extent permitted.
18.3 In particular, and without limitation, we give no warranty in respect of results that depend on data made available by Microsoft, or of controls that Microsoft does not expose through a published interface.
19 Limitation of liability
19.1 We are liable without limitation for damage caused intentionally or by gross negligence, for death or personal injury, and for any other liability which cannot be limited or excluded under mandatory applicable law.
19.2 Subject to clause 19.1, our aggregate liability arising out of or in connection with the agreement, whether in contract, tort or otherwise, shall not exceed the total fees paid by the Customer for the Service in the twelve (12) months preceding the event giving rise to the claim. Where the Service has been provided without charge, our aggregate liability shall not exceed CHF 1,000.
19.3 Subject to clause 19.1, we shall not be liable for loss of profit, loss of revenue, loss of anticipated savings, loss of business or goodwill, loss or corruption of data, or any indirect or consequential loss.
19.4 Subject to clause 19.1, we accept no liability for any interruption, outage, loss of access, data loss, degradation of service, incompatibility with legacy applications or third-party integrations, or other disruption arising from the Customer implementing, or omitting to implement, any recommendation contained in a Report. The Customer alone decides which changes to make to its environment, and does so having been advised in clause 9 to review and test them first.
19.5 Subject to clause 19.1, we shall not be liable for any security incident, breach or compromise of the Customer’s environment, save to the extent directly caused by our breach of these Terms.
19.6 Any claim must be brought within twelve (12) months of the Customer becoming aware of the circumstances giving rise to it.
20 Term and termination
20.1 The agreement commences on acceptance in accordance with clause 3 and continues for the term stated in the order form, or until terminated where no term is stated.
20.2 Either party may terminate for convenience on thirty (30) days’ written notice, unless a fixed term has been agreed, in which case termination for convenience takes effect at the end of that term.
20.3 Either party may terminate with immediate effect if the other commits a material breach that is not remedied within thirty (30) days of written notice, or becomes insolvent or subject to comparable proceedings.
20.4 On termination, access to the Service ceases. The Customer should export any Reports it wishes to retain before the effective date. On written request made within thirty (30) days of termination we will return or delete Customer Data in accordance with the DPA, subject to retention required by law and to the append-only audit records described in clause 16.5.
20.5 Clauses 7.2, 14, 15, 16, 18, 19, 24 and 25 survive termination, together with any other provision that by its nature is intended to survive.
21 Suspension
We may suspend access to the Service, in whole or in part and with immediate effect, where required to protect the security or integrity of the Service or of another customer, where required by law or by Microsoft, where the Customer is in material breach of clause 11, or where fees remain unpaid more than thirty (30) days after the due date and after written reminder. We will restore access as soon as the cause of suspension is resolved and, where practicable, will notify the Customer in advance.
22 Force majeure
Neither party is liable for any failure or delay in performance caused by circumstances beyond its reasonable control, including acts of public authority, armed conflict, natural events, epidemics, industrial action, failure of telecommunications or energy supply, and failure, suspension or material change of services operated by Microsoft or other upstream providers. Payment obligations already accrued are not affected.
23 Changes to these Terms and to the Service
23.1 We may amend these Terms with effect for the future. We will notify the Customer of any material amendment at least thirty (30) days before it takes effect, by email or within the Service.
23.2 If the Customer objects in writing before the amendment takes effect, the Customer may terminate the agreement with effect from that date. Continued use of the Service after the effective date constitutes acceptance.
23.3 We may modify the functionality of the Service, provided that the overall functionality contracted for is not materially reduced during a paid term.
24 General provisions
24.1 Severability. If any provision is or becomes invalid or unenforceable, the validity of the remaining provisions is unaffected. The invalid provision shall be replaced by a valid one that comes closest to the commercial intent of the parties.
24.2 Assignment. The Customer may not assign or transfer the agreement without our prior written consent. We may assign the agreement to an affiliate or in connection with a merger, reorganisation or sale of the business to which it relates.
24.3 No waiver. Failure or delay in exercising a right does not constitute a waiver of it.
24.4 Notices. Notices shall be given in writing to the addresses in clause 1 or to the Customer’s registered contact address. Email is sufficient, except for notices of termination, which must be given in writing.
24.5 No partnership. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between the parties.
24.6 References. Neither party may use the other’s name or logo publicly without prior written consent.
24.7 Language. These Terms are concluded in English. Where a translation is provided for convenience, the English version prevails.
25 Governing law and jurisdiction
25.1 These Terms and any contract concluded on the basis of them are governed exclusively by Swiss law, to the exclusion of its conflict-of-laws rules and of the United Nations Convention on Contracts for the International Sale of Goods.
25.2 The exclusive place of jurisdiction for all disputes arising directly or indirectly out of the contractual relationship shall be the competent courts at the registered office of dotCLOUD Consulting (Schweiz) GmbH in Schlieren, Canton of Zurich, Switzerland. We reserve the right to bring proceedings at the Customer’s seat.
26 Contact
- Contractual matters
- contact@dotcloud.ch · +41 (43) 217 80 40
- Privacy matters
- privacy@dotcloud.pro
- By post
-
dotCLOUD Consulting (Schweiz) GmbH
Bahnhofstrasse 9
8952 Schlieren
Switzerland