FAQ - BeZoned and data
Last updated 20 August 2026 · Written for IT, procurement and data protection teams evaluating Bezoned
Bezoned adds a virtual office to the Microsoft Teams you already use. Because of how it is built, most of your people's information never leaves your own Microsoft 365 environment. This page explains, in plain terms, what does reach us and what we do with it.
The short version
Bezoned runs on top of your Microsoft 365 tenant. When someone opens their virtual office, their name, photo and colleagues are read live from Microsoft and shown on screen — they are not copied into our systems and kept there.
What we hold is mostly the shape of your office: which offices exist, which rooms and tables are in them, and which Teams channels are connected. Alongside that we hold identifiers — random strings issued by Microsoft — that let us ask Microsoft for the right information at the right moment.
Stays with Microsoft
Never copied into our systems
Names Your people's names and display names are read from Microsoft each time a screen needs them.
Email addresses With the narrow exceptions described further down.
Chat messages All conversations stay in Microsoft Teams. We can see that a conversation exists, never what is in it.
Meeting and call content No audio, no video, no recordings, no transcripts.
Passwords and sign-in details Signing in is handled entirely by Microsoft. We never see a credential.
Files and documents Bezoned does not read or store the contents of your SharePoint or OneDrive.
Held by Bezoned
What we keep, and why
Your office layout Offices, rooms, tables and the channels linked to them.
Microsoft user identifiers A random ID per person, issued by Microsoft. On its own it is not a name or an address.
Where someone is right now Which office a person is in and whether they are available, away or busy — so colleagues can see them. Current status only; we keep no history of it.
A cached profile photo A copy of the Teams profile picture, so avatars load quickly.
Your organisation's billing details Company name, address and subscription information.
How the product is used Events such as "an office was opened" or "a meeting started", recorded against a scrambled identifier rather than a name.
Where email addresses come into it
We have tried to keep email addresses out of Bezoned, and in normal use your people's addresses are not stored. There are three specific situations where an address does reach us, and we would rather name them than imply the number is zero.
Your organisation's data is kept separate
Every customer gets their own dedicated database. Your offices, your rooms and your people's status live in a separate store from every other Bezoned customer — not in a shared table with a column marking which rows are yours.
This is a deliberate design choice. It means the isolation between customers is enforced by the infrastructure rather than by application code remembering to filter correctly.
One shared record, deliberately
A single central register holds the commercial relationship — organisation name and contact details, subscription and licence information, and which of your users hold a seat. It also holds the product usage events described above.
Everything about your virtual offices and the people in them sits in your own separate database.
Who else is involved
Bezoned relies on a small number of established providers to run. These are the ones that may handle information relating to your people.
How long we keep it, and how to have it removed
While your organisation uses Bezoned, we keep the information described above so the product works. Your people's availability is the exception: it is overwritten as they move around, so there is no record of where anyone has been.
12 month after your organisation stops using Bezoned, we will, after a warning, delete all data. If one of your people asks for their information to be removed, contact us and we will carry it out. The same applies to a request to see what we hold about a particular person.
Hosting region
All the data we host are on Microsoft Azure data centers placed inside the EU GDPR regime, which is the strictest standard we could hold ourselves to.
Questions
If your data protection team needs detail beyond this page - a full record of processing, a data processing agreement, or answers to a security questionnaire - we are happy to provide it.
Contact privacy@bezoned.com.