FAQ - BeZoned and data

Last updated 20 August 2026 · Written for IT, procurement and data protection teams evaluating Bezoned

Bezoned adds a virtual office to the Microsoft Teams you already use. Because of how it is built, most of your people's information never leaves your own Microsoft 365 environment. This page explains, in plain terms, what does reach us and what we do with it.

The short version

Bezoned runs on top of your Microsoft 365 tenant. When someone opens their virtual office, their name, photo and colleagues are read live from Microsoft and shown on screen — they are not copied into our systems and kept there.

What we hold is mostly the shape of your office: which offices exist, which rooms and tables are in them, and which Teams channels are connected. Alongside that we hold identifiers — random strings issued by Microsoft — that let us ask Microsoft for the right information at the right moment.

Stays with Microsoft

Never copied into our systems

  • Names Your people's names and display names are read from Microsoft each time a screen needs them.

  • Email addresses With the narrow exceptions described further down.

  • Chat messages All conversations stay in Microsoft Teams. We can see that a conversation exists, never what is in it.

  • Meeting and call content No audio, no video, no recordings, no transcripts.

  • Passwords and sign-in details Signing in is handled entirely by Microsoft. We never see a credential.

  • Files and documents Bezoned does not read or store the contents of your SharePoint or OneDrive.

Held by Bezoned

What we keep, and why

  • Your office layout Offices, rooms, tables and the channels linked to them.

  • Microsoft user identifiers A random ID per person, issued by Microsoft. On its own it is not a name or an address.

  • Where someone is right now Which office a person is in and whether they are available, away or busy — so colleagues can see them. Current status only; we keep no history of it.

  • A cached profile photo A copy of the Teams profile picture, so avatars load quickly.

  • Your organisation's billing details Company name, address and subscription information.

  • How the product is used Events such as "an office was opened" or "a meeting started", recorded against a scrambled identifier rather than a name.

Where email addresses come into it

We have tried to keep email addresses out of Bezoned, and in normal use your people's addresses are not stored. There are three specific situations where an address does reach us, and we would rather name them than imply the number is zero.

Setting up your organisation

When Bezoned is installed we read your organisation's contact details from Microsoft, including a technical contact address. Where your tenant has no such address configured, the address of the person who installed Bezoned is used instead.

Starting a trial

We record the address of the person who starts a trial, so our team can reach them about it.

Getting started with the product

As people work through the first steps of setting up their office, we record their address in our customer relationship system so our team can offer help at the right moment.

And if someone reports a problem

When one of your users sends us an error report from inside Bezoned, that report reaches our support channel with their address and network address attached, so we can investigate what went wrong for them specifically.

Your organisation's data is kept separate

Every customer gets their own dedicated database. Your offices, your rooms and your people's status live in a separate store from every other Bezoned customer — not in a shared table with a column marking which rows are yours.

This is a deliberate design choice. It means the isolation between customers is enforced by the infrastructure rather than by application code remembering to filter correctly.

One shared record, deliberately

A single central register holds the commercial relationship — organisation name and contact details, subscription and licence information, and which of your users hold a seat. It also holds the product usage events described above.

Everything about your virtual offices and the people in them sits in your own separate database.

Who else is involved

Bezoned relies on a small number of established providers to run. These are the ones that may handle information relating to your people.

Microsoft Azure

Hosts the Bezoned service, its databases and stored files, and provides the chat and presence services behind the product.

Cloudflare

Powers the live video and audio when your people join a table or a room. The call itself runs through Cloudflare; we keep only a reference to the session.

HubSpot

Our customer relationship system. Holds the email addresses described in the section above, so our team can support you.

Sentry

Alerts our engineers when something breaks. Error reports can include identifiers relating to the person who hit the problem.

How long we keep it, and how to have it removed

While your organisation uses Bezoned, we keep the information described above so the product works. Your people's availability is the exception: it is overwritten as they move around, so there is no record of where anyone has been.

12 month after your organisation stops using Bezoned, we will, after a warning, delete all data. If one of your people asks for their information to be removed, contact us and we will carry it out. The same applies to a request to see what we hold about a particular person.

Hosting region

All the data we host are on Microsoft Azure data centers placed inside the EU GDPR regime, which is the strictest standard we could hold ourselves to.

Questions

If your data protection team needs detail beyond this page - a full record of processing, a data processing agreement, or answers to a security questionnaire - we are happy to provide it.

Contact privacy@bezoned.com.