Privacy Policy
Draft for legal review. Resource Lens is operated by Firesub AB. This page describes the product data visible in the current implementation and must be approved before it is treated as the final privacy notice.
Data processed
- Microsoft Entra identity and tenant information needed for authentication, workspace membership, display names, roles, and audit attribution.
- Selected management groups, subscriptions, resource types, and Resource Lens role assignments.
- Azure inventory, configuration, cost, Advisor, monitoring, activity-log, and retail-pricing signals available through the read-only access granted by the customer.
- Analysis prompts, trace events, user responses, recommendation evidence, reports, and generated implementation artifacts.
- Azure Marketplace subscription status, plan, billing period, Resource Lens token usage, and configured overage cap.
- Email address, display name, saved setup step, and delivery status used for incomplete-setup reminders.
- Product feedback and permission to contact the user when voluntarily provided.
How data is used
- Authenticate users and enforce workspace, app-role, tenant, and subscription boundaries.
- Run requested Azure cost analysis and present evidence-backed recommendations.
- Operate live status, audit traces, billing controls, support, reliability, and security safeguards.
- Send up to four personalized reminders over one week when a user leaves setup incomplete. The sequence stops when setup resumes or completes, and every message provides an unsubscribe action.
- Process feedback and improve the Resource Lens experience.
Access and customer control
Azure access is controlled through the Resource Lens enterprise application and role assignments selected by the customer. Resource Lens does not use those roles to modify customer resources. Authorized administrators can revoke individual roles, remove all access from a subscription, remove users or groups in Microsoft Entra, or start the protected workspace-reset workflow.
Profile information
Delegated Microsoft Graph User.Read can be used to show the signed-in user's display name and profile photo. Tenant-wide consent is optional, profile photos are requested directly from Microsoft Graph, and initials are used when a photo is unavailable.
Optional product analytics
With your optional analytics-cookie consent, Resource Lens uses Microsoft Clarity across resourcelens.com and portal.resourcelens.com to measure navigation, conversion funnels, clicks, scrolling, and masked session replay. Portal regions containing identity, tenant, subscription, resource, cost, recommendation, artifact, notification, settings, or agent-conversation content are explicitly masked.
After sign-in, the browser derives separate one-way hashes for the user and tenant so sessions from the same user or tenant can be grouped without sending the underlying Microsoft Entra identifiers, tenant name, email address, or display name to Clarity. Analytics is disabled unless consent is granted and is never initialized on local, development, test, or preview environments. You can withdraw consent from the cookie-preferences control on either site.
Retention and deletion
The workspace reset process locks the workspace, coordinates Marketplace cancellation, and schedules permanent removal of saved database records and archived analysis data after a seven-day recovery period. The customer separately removes the Resource Lens enterprise application from Microsoft Entra.
Service providers and terms
Resource Lens relies on Microsoft Azure, Microsoft Entra, Microsoft Marketplace, configured Azure AI services, and Resend for transactional email delivery. Setup-reminder unsubscribe tokens are stored only as cryptographic hashes. Applicable Marketplace terms and the final Firesub AB privacy documentation govern the production service.