CrossTenant

Privacy Policy

Last updated: 31 August 2026

Operator / data controller: CrossTenant Ltd, a company registered in England & Wales (company no. 17349672), registered office Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom. Contact: toby@crosstenant.com. Our registration with the Information Commissioner’s Office (ICO) is in progress; the registration number will be published here once issued.

This policy explains what information CrossTenant (“we”, “us”) accesses, how we use it, what we do and do not store, and the choices and rights you have. It covers both this website (crosstenant.com) and the CrossTenant application — a Google Workspace management console used by managed service providers (“MSPs”) to administer their customers’ Google Workspace organisations. CrossTenant is operated from the United Kingdom.

1. What CrossTenant is, and whose data is involved

CrossTenant is an administration tool. A customer organisation’s Google Workspace super-administrator authorises CrossTenant (via Google OAuth consent and, for some features, domain-wide delegation) so that the MSP the organisation has contracted can perform Workspace administration on its behalf — user lifecycle management, security remediation, device actions, mail and Drive governance, and compliance reporting.

Three kinds of people interact with CrossTenant:

For customer organisation data, the customer organisation remains the data controller; CrossTenant processes that data on the instructions of the organisation and its contracted MSP, solely to provide the administration features described here, under our written data processing agreement (Article 28 UK GDPR) with the MSP. For the data CrossTenant holds in its own right — MSP-operator accounts and audit logs — CrossTenant is the data controller. Individuals within a customer organisation should raise requests about their Workspace data with their own organisation (the controller) first.

2. Information we access through Google APIs

When a customer administrator authorises CrossTenant, the console accesses Google Workspace data via Google’s APIs, limited to the scopes granted. Depending on the features in use, this includes:

CategoryExamplesUsed for
Directory dataUsers, groups, organisational units, aliases, admin rolesThe Users/Groups pages; lifecycle actions the MSP performs (create, suspend, reset password, offboard)
Device dataChromeOS, mobile, and endpoint inventory; device telemetryFleet inventory and security actions (approve, block, wipe, deprovision)
Mail settingsForwarding, delegates, send-as, vacation responders, IMAP/POP settingsMail governance — auditing and remediating risky mailbox configuration. We access mailbox settings, not the content of email messages.
Drive dataStorage quota, file metadata and sharing/ownership information, shared drive membership, Drive activity recordsStorage administration, offboarding ownership transfers, sharing governance
Calendar dataCalendar lists, sharing ACLs, bookable resourcesCalendar governance and resource management
Audit & usage reportsLogin/admin/token/Drive audit events; product usage metricsActivity feeds, security signals, adoption reporting
Configuration & licensingAdmin policy settings, licence assignments, Vault matters and holds (metadata only)Security-posture snapshots, licence management, compliance overviews

CrossTenant’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How we use this information (purposes and lawful bases)

For the data CrossTenant controls in its own right, our UK GDPR Article 6 lawful bases are:

Providing your name and email is necessary to create an operator account; without it we cannot grant you console access. For customer Workspace data, CrossTenant is a processor and the customer organisation, as controller, is responsible for the lawful basis.

4. What we store — and what we don’t

CrossTenant keeps no copy of your Workspace. There is no database and no cache: every screen in the console is a live read from Google’s APIs, rendered for the authorised operator and then discarded. Google-returned directory, mail, file, and calendar observations are not kept as a console data store. An operator may deliberately save a joiner role template containing the configuration described below. We never store message bodies, file contents, document text, or passwords — anywhere, at any time, including while a change is waiting for approval.

Five categories of data do rest on the console, each for a stated purpose and period:

When a customer offboards, their stored credentials and configuration are deleted. Customers and MSPs can request deletion at any time via the contact below; access can also be revoked unilaterally and immediately on the Google side. The audit log is the single exception, and is retained to its 24-month cap as described above.

5. Optional AI features

CrossTenant includes optional AI features: executive summaries on generated reports and an assistant in the console. When used, these send the operator’s typed question together with sanitised configuration and posture context — settings values, counts, metrics, and summary statistics (for example “3 users have external forwarding enabled”) — to Anthropic’s Claude API to generate text. Every AI request passes through a redaction guard: no mailbox or file content is ever sent. The assistant can additionally draft a proposed administrative action, but a draft is only ever a proposal — the assistant cannot execute anything. An authorised operator must review, confirm, and execute every action, and AI-assisted actions are marked as such in the audit log. Where an AI-drafted action is parked for a second operator’s approval, the approval record additionally holds the operator’s typed question (truncated) while that record is retained, so the change can be traced back to what was asked; the durable audit log itself deliberately does not retain the question text. Per Anthropic’s API terms, data sent to the API is not used to train Anthropic’s models. If you prefer these features not be used for your organisation, tell your MSP — they are optional and can be left unused.

6. Who we share information with

We share data only with the service providers needed to run CrossTenant:

The complete, always-current list — including each provider’s purpose, the data it can reach, its processing location, and the transfer mechanism relied on — is published at crosstenant.com/subprocessors. That page is the canonical list and governs if this section ever falls out of step with it. For a Customer whose DPA is already in force, we publish and email notice of a later provider addition or replacement at least 30 days before it begins processing personal data under that DPA. Providers already listed as Current when a Customer contracts form part of the disclosed list authorised at signing.

International transfers. Anthropic and Cloudflare process data in the United States, and Microsoft may use locations outside the United Kingdom as permitted by its DPA. These transfers are made under appropriate safeguards: for Cloudflare, the UK Extension to the EU–US Data Privacy Framework; for Anthropic, Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, incorporated via Anthropic’s Data Processing Addendum; and for Microsoft, the 2021 Standard Contractual Clauses and UK International Data Transfer Addendum in Microsoft’s Products and Services Data Protection Addendum.

We do not sell personal data. We do not share it with advertisers. We may disclose information if required by law, or to protect the rights, safety, or security of CrossTenant, our customers, or others.

7. This website, and the console’s own server logs

crosstenant.com is a static informational site. It sets no advertising or tracking cookies. Standard server logs (IP address, user agent, pages requested) may be processed by Cloudflare, which hosts the site, for security and performance purposes.

Separately, the private hosted console runs on Microsoft Azure in the UK West region and is reached through Cloudflare’s authenticated edge and outbound-only tunnel. Cloudflare processes console traffic while proxying it, but API responses are marked non-cacheable. The console application writes operational logs on its Azure-hosted server — the ordinary record of requests, warnings, and errors that any server produces, used for diagnosis and for detecting problems. Where a call to Google fails, the error text Google returns is recorded, and that text can include a domain name, a user’s email address, or a project identifier. These logs are not a data store and are not queried as one; they are held on the same infrastructure, under the same access controls, as everything else described in section 8, and are rotated and discarded on the operating system’s ordinary schedule.

8. Security

A fuller technical description — including what we deliberately do not claim — is published at crosstenant.com/security. Security issues can be reported to security@crosstenant.com; our disclosure policy is on the support page.

In the event of a personal-data breach affecting your data, we will notify affected customer administrators without undue delay and meet our regulatory notification obligations.

The CrossTenant console uses only strictly-necessary cookies (your sign-in session) and browser local storage for interface preferences (theme, sidebar state, customer scope, table layout); it stores no customer or tenant data in the browser, and sets no advertising, analytics, or tracking cookies, so no cookie-consent banner is required.

9. Your rights

Where UK GDPR / GDPR or similar laws apply, you have rights over your personal data, including access, correction, deletion, restriction of processing, data portability, and objection. For operator-account and audit-log data (where CrossTenant is the controller) these are exercised directly with us; for customer Workspace data (where CrossTenant is a processor) requests go to the customer organisation and we assist. If you are an end user of a customer organisation, your organisation (the data controller) and its MSP are usually the right first contact — but you can also reach us directly below and we will help route your request. Customer administrators can revoke CrossTenant’s access entirely at any time in the Google Admin Console or via Google account permissions. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ICO).

CrossTenant does not carry out solely-automated decision-making or profiling that produces legal or similarly significant effects. AI features are advisory only and a human operator decides and confirms every action.

10. Children

CrossTenant is a business administration tool and is not directed at children. We do not knowingly collect personal data from children, except insofar as a customer organisation’s directory may include accounts it administers (for example, in education deployments), which we process only on that organisation’s instructions.

11. Changes to this policy

We will post any changes to this policy on this page and update the “Last updated” date above. Material changes affecting how Google user data is handled will be communicated to customer administrators before they take effect.

12. Contact

The data controller for this service is the entity named at the top of this policy. Questions, requests, or concerns: toby@crosstenant.com.