Privacy Policy
Last updated: 24 July 2026
Operator / data controller: CrossTenant Ltd, a company registered in England & Wales (company no. 17349672), registered office Unit 82a James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE, United Kingdom. Contact: [email protected].
This policy explains what information CrossTenant (“we”, “us”) accesses, how we use it, what we do and do not store, and the choices and rights you have. It covers both this website (crosstenant.com) and the CrossTenant application — a Google Workspace management console used by managed service providers (“MSPs”) to administer their customers’ Google Workspace organisations. CrossTenant is operated from the United Kingdom.
1. What CrossTenant is, and whose data is involved
CrossTenant is an administration tool. A customer organisation’s Google Workspace super-administrator authorises CrossTenant (via Google OAuth consent and, for some features, domain-wide delegation) so that the MSP the organisation has contracted can perform Workspace administration on its behalf — user lifecycle management, security remediation, device actions, mail and Drive governance, and compliance reporting.
Three kinds of people interact with CrossTenant:
- MSP operators — the engineers who sign in to the console;
- Customer administrators — the Workspace admins who authorise access for their organisation;
- End users of customer organisations — whose directory and account information is displayed to authorised MSP operators as part of administration. End users do not interact with CrossTenant directly.
For customer organisation data, the customer organisation remains the data controller; CrossTenant processes that data on the instructions of the organisation and its contracted MSP, solely to provide the administration features described here, under a written data processing agreement (Article 28 UK GDPR). For the data CrossTenant holds in its own right — MSP-operator accounts and audit logs — CrossTenant is the data controller. Individuals within a customer organisation should raise requests about their Workspace data with their own organisation (the controller) first.
2. Information we access through Google APIs
When a customer administrator authorises CrossTenant, the console accesses Google Workspace data via Google’s APIs, limited to the scopes granted. Depending on the features in use, this includes:
| Category | Examples | Used for |
|---|---|---|
| Directory data | Users, groups, organisational units, aliases, admin roles | The Users/Groups pages; lifecycle actions the MSP performs (create, suspend, reset password, offboard) |
| Device data | ChromeOS, mobile, and endpoint inventory; device telemetry | Fleet inventory and security actions (approve, block, wipe, deprovision) |
| Mail settings | Forwarding, delegates, send-as, vacation responders, IMAP/POP settings | Mail governance — auditing and remediating risky mailbox configuration. We access mailbox settings, not the content of email messages. |
| Drive data | Storage quota, file metadata and sharing/ownership information, shared drive membership, Drive activity records | Storage administration, offboarding ownership transfers, sharing governance |
| Calendar data | Calendar lists, sharing ACLs, bookable resources | Calendar governance and resource management |
| Audit & usage reports | Login/admin/token/Drive audit events; product usage metrics | Activity feeds, security signals, adoption reporting |
| Configuration & licensing | Admin policy settings, licence assignments, Vault matters and holds (metadata only) | Security-posture snapshots, licence management, compliance overviews |
CrossTenant’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use this information (purposes and lawful bases)
- Solely to provide the console’s administration features to authorised MSP operators acting for the customer organisation.
- We do not use Google user data for advertising, and we do not sell it to anyone.
- We do not use Google user data to train machine-learning or AI models.
- Humans at CrossTenant do not read Google user data except with the customer’s or MSP’s explicit permission for support, where required for security investigation or abuse prevention, or where required by law.
For the data CrossTenant controls in its own right, our UK GDPR Article 6 lawful bases are:
- Operator accounts — performance of a contract (Art 6(1)(b)) with the MSP and/or our legitimate interests (Art 6(1)(f)) in operating a secure console.
- Audit logs — our legitimate interests (Art 6(1)(f)) in securing and operating the console and keeping an accountable record of administrative actions.
Providing your name and email is necessary to create an operator account; without it we cannot grant you console access. For customer Workspace data, CrossTenant is a processor and the customer organisation, as controller, is responsible for the lawful basis.
4. What we store — and what we don’t
CrossTenant does not store your Workspace content. Every page in the console is a live fetch from Google’s APIs: the data is retrieved, displayed to the authorised operator, and discarded. There is no database and no cache of customer directory, mail, Drive, calendar, or device data.
What the service does retain, for as long as the relationship is active:
- Authorisation credentials — the OAuth tokens and service-account configuration a customer administrator grants, stored isolated per customer and used only to make the API calls described above. Revoking access (in the Google Admin Console or via Google account settings) invalidates these immediately.
- Operator accounts and access policy — MSP operator sign-in identities (name, email), role and permission assignments, session records, and a short per-operator sign-in history (timestamp, identity provider, IP address, browser user-agent; the most recent sign-ins only, visible to that operator). Retained while the operator/MSP relationship is active, then deleted.
- Audit logs — a per-customer record of every write operation performed through the console: the timestamp, the customer tenant, the operator (identity and email), the action and its target, a bounded summary of the configuration fields that changed, and the result. Audit entries contain no message or file content and no credentials — they exist so administrative actions are accountable. Audit logs are retained for a maximum of 24 months, then automatically deleted.
- Report, schedule and alert configuration — report templates, schedules, alert rules, notification recipient addresses and any webhook endpoint URLs, operator-authored policy baselines and report notes, and customer-supplied branding (name/logo) used on generated reports.
When a customer offboards, their stored credentials and configuration are deleted. Customers and MSPs can request deletion at any time via the contact below; access can also be revoked unilaterally and immediately on the Google side.
5. Optional AI features
CrossTenant includes optional AI features: executive summaries on generated reports and an advisory assistant in the console. When used, these send aggregated report data (counts, metrics, and summary statistics — for example “3 users have external forwarding enabled”) to Anthropic’s Claude API to generate text. The assistant is advisory only — it produces text and performs no administrative actions. Per Anthropic’s API terms, data sent to the API is not used to train Anthropic’s models. If you prefer these features not be used for your organisation, tell your MSP — they are optional and can be left unused.
6. Who we share information with
We share data only with the service providers needed to run CrossTenant:
- Google — inherently: the console operates on Google Workspace via Google’s APIs, under the customer administrator’s authorisation.
- Anthropic PBC (United States) — only the aggregated report data described in section 5, and only when AI features are used. No Workspace message or file content is sent to Anthropic.
- Cloudflare, Inc. (United States) — hosts this website and provides DNS/network services for crosstenant.com.
International transfers. Anthropic and Cloudflare process data in the United States. These transfers are made under appropriate safeguards: for Cloudflare, the UK Extension to the EU–US Data Privacy Framework; for Anthropic, Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum, incorporated via Anthropic’s Data Processing Addendum.
We do not sell personal data. We do not share it with advertisers. We may disclose information if required by law, or to protect the rights, safety, or security of CrossTenant, our customers, or others.
7. This website
crosstenant.com is a static informational site. It sets no advertising or tracking cookies. Standard server logs (IP address, user agent, pages requested) may be processed by our hosting provider, Cloudflare, for security and performance purposes.
8. Security
- All data in transit is encrypted with TLS; credentials, audit logs and configuration reside on disk-encrypted infrastructure.
- Credentials and audit logs are isolated per customer; one customer’s authorisation can never access another customer’s data.
- Access follows least privilege: read-only customers get read-only API tokens, and privileged operations request only the scopes they need, per operation.
- Write operations require explicit operator confirmation and are recorded in the per-customer audit log.
- MSP operator access is governed by per-customer, per-area role-based access control.
In the event of a personal-data breach affecting your data, we will notify affected customer administrators without undue delay and meet our regulatory notification obligations.
The CrossTenant console uses only strictly-necessary cookies (your sign-in session) and browser local storage for interface preferences (theme, sidebar state, customer scope, table layout); it stores no customer or tenant data in the browser, and sets no advertising, analytics, or tracking cookies, so no cookie-consent banner is required.
9. Your rights
Where UK GDPR / GDPR or similar laws apply, you have rights over your personal data, including access, correction, deletion, restriction of processing, data portability, and objection. For operator-account and audit-log data (where CrossTenant is the controller) these are exercised directly with us; for customer Workspace data (where CrossTenant is a processor) requests go to the customer organisation and we assist. If you are an end user of a customer organisation, your organisation (the data controller) and its MSP are usually the right first contact — but you can also reach us directly below and we will help route your request. Customer administrators can revoke CrossTenant’s access entirely at any time in the Google Admin Console or via Google account permissions. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner’s Office (ICO).
CrossTenant does not carry out solely-automated decision-making or profiling that produces legal or similarly significant effects. AI features are advisory only and a human operator decides and confirms every action.
10. Children
CrossTenant is a business administration tool and is not directed at children. We do not knowingly collect personal data from children, except insofar as a customer organisation’s directory may include accounts it administers (for example, in education deployments), which we process only on that organisation’s instructions.
11. Changes to this policy
We will post any changes to this policy on this page and update the “Last updated” date above. Material changes affecting how Google user data is handled will be communicated to customer administrators before they take effect.
12. Contact
The data controller for this service is the entity named at the top of this policy. Questions, requests, or concerns: [email protected].