RK
Rohit Kumar Enterprise M365 Architect

Privacy Policy

Last updated: January 2026

1. Introduction

Rohit Kumar ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your enterprise information. This Privacy Policy outlines our practices regarding data collection, confidentiality, and security when you visit our website or engage our SharePoint and Microsoft 365 architecture consulting services.

2. Information We Collect

We collect information that you voluntarily provide to us when you fill out contact forms, schedule discovery calls, or request enterprise architectural assessments, including:

  • Name, corporate email address, and phone number
  • Company name, job title, and team size
  • Project requirements, migration scopes, and technical environment notes

3. Enterprise Confidentiality & NDA Standards

We recognize that enterprise clients share sensitive architecture diagrams, tenant metrics, and governance requirements. All discussions, environment details, and documentation are strictly confidential and protected by default mutual non-disclosure agreement (NDA) standards before any technical deep-dive occurs.

4. How We Use Your Information

We use the collected information solely for professional engagement purposes:

  • Responding to consulting inquiries and scheduling discovery sessions
  • Delivering custom architecture blueprints, migration roadmaps, and audit reports
  • Improving our website performance and technical resources

5. Data Security

We implement industry-standard administrative, technical, and physical security measures to safeguard your personal and professional data against unauthorized access, disclosure, or alteration.

6. Contact Us

If you have any questions regarding this Privacy Policy or our data practices, please reach out via our Contact Page.

Enterprise Data Confidentiality, Security & Compliance Standards

Non-Disclosure & Client Confidentiality

All consulting engagements, architecture assessments, and source code reviews are governed by binding bilateral Non-Disclosure Agreements (NDAs). Client tenant data, IP configurations, and architectural schematics are never stored on unauthorized secondary hardware.

Least-Privilege Tenant Access & Security Controls

Consulting access is conducted exclusively via client-provisioned guest accounts or dedicated Privileged Identity Management (PIM) accounts requiring hardware MFA and conditional access compliance. Zero client data is transmitted to third-party public AI models.

Data Sovereignty, Retention Schedules & Incident Protocols

Data Processing Addendum (DPA): We execute standard GDPR, CCPA/CPRA, and HIPAA Business Associate Agreements (BAAs) with all commercial clients prior to receiving tenant credentials or conducting system architecture audits.

Log Retention & Destruction: Client diagnostics logs and assessment telemetry collected during health checkups are retained for a maximum of 30 days within an encrypted customer vault before cryptographically secure automated destruction.

Incident Response & Notification: In the unlikely event of an identified security vulnerability or unauthorized access attempt on client infrastructure, our team immediately activates our 1-hour executive notification SLA with root-cause incident forensics.

Security Certifications & Compliance Alignments

ISO 27001 & SOC 2 Type II

Strict physical and logical security protocols governing client communication, architecture assessments, and credential management.

HIPAA BAA Compliance

Standard Business Associate Agreements executed with healthcare and life sciences clients ensuring zero unencrypted PHI storage.

ITAR & CMMC Level 2

US-citizen-only consulting team for defense aerospace clients working in Microsoft 365 GCC High environments.