MARS Security
Legal

Privacy Policy

Mars for Microsoft Teams

Effective date: 28 May 2026 · Last updated: 28 May 2026

This Privacy Policy explains how Mars Security ("Mars", "we", "us", or "our") collects, uses, and protects information in connection with the Mars Security app for Microsoft Teams (the "Teams App"). For the in-product Mars platform itself (app.marssec.ai), a separate, customer-facing privacy notice applies and is provided to each customer under contract.

If you have any questions about this policy, contact us at mars-support@marssec.ai.

1. Who we are

Mars Security operates the Mars threat-hunting and detection engineering platform, and the Mars Security app for Microsoft Teams that integrates with it. The data controller for the purposes of this policy is Mars Security. You can reach our privacy contact at mars-support@marssec.ai.

2. Scope of this policy

This policy applies to the Mars Security app for Microsoft Teams, covering everything Mars does in your Microsoft Teams workspace. It does not cover the authenticated Mars platform at app.marssec.ai, which is governed by your organization's contract with Mars and its associated customer-facing privacy notice.

3. Information we collect from Microsoft Teams

The Mars Teams App is notification-only: it posts hunt-completion cards to the channels you configure. To do this, Mars receives and stores the following:

  • Microsoft 365 tenant identifier. The Azure AD / Microsoft 365 tenant ID you provide when connecting the integration, used to target your tenant when listing channels and posting messages. The Teams bot itself is operated by Mars; we do not store a per-customer bot token.
  • Team and channel metadata. The team and channel identifiers and display names that Mars reads (via Microsoft Graph) so you can choose a destination channel, and the identifier of the channel you select to receive hunt notifications.
  • Messages Mars itself sends. The content of the hunt-completion cards Mars posts into your selected channel. Mars retains these for operational logging and troubleshooting.

4. How we use information

We use the information above strictly to:

  • Deliver the Teams App's feature (post hunt-completion cards to the channel you configure).
  • List your teams and channels so you can choose a notification destination.
  • Operate, secure, and troubleshoot the service, including investigating misuse or abuse.
  • Comply with legal obligations.

We do not use your data for advertising, profiling unrelated to security investigations, building external products, or training general-purpose AI models. We do not sell your data.

5. Lawful basis for processing (EEA / UK)

Where the EU/UK General Data Protection Regulation applies, our lawful bases are: (a) performance of a contract with your organization, (b) our legitimate interests in operating and securing the service, and (c) compliance with legal obligations.

6. How we share information

We share information only with trusted subprocessors that help us operate the service. A full list is available on our sub-processors page. Current categories include:

  • Cloud infrastructure providers (e.g., Amazon Web Services) for hosting, storage, and networking.
  • LLM providers (e.g., OpenAI, Anthropic, Azure OpenAI) used by Mars's investigation and hunting agents. Data is sent under contractual terms that prohibit using it to train general-purpose models.
  • Operational tooling such as error monitoring and logging providers.

We do not share your data with third parties for their own marketing or advertising purposes.

7. How we protect information

Mars applies industry-standard safeguards including TLS in transit, encryption at rest, tenant-scoped handling of integration credentials, least-privilege access controls, audit logging, and regular security review of code and dependencies.

8. Data retention

  • Teams configuration (your tenant ID and selected destination channels) is retained until you remove the integration, or until your contract with Mars ends, whichever comes first.
  • Operational logs (including cards Mars sent) are retained for up to 90 days by default, then automatically deleted.
  • Hunt and investigation outputs are retained according to your organization's contract with Mars and are governed by the in-product privacy notice.

You can request deletion at any time by emailing mars-support@marssec.ai.

9. Your rights

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your data, subject to legal retention obligations.
  • Portability: request a copy of your data in a machine-readable format.
  • Objection / restriction: object to or restrict certain processing.

To exercise any of these rights, contact mars-support@marssec.ai.

10. International data transfers

Mars and its subprocessors operate in multiple regions. Your data may be processed in jurisdictions other than the one you live in. Where required, we rely on appropriate safeguards for cross-border transfers.

11. Children's privacy

Mars is a B2B security product and is not intended for individuals under 16. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Effective date" above and, where appropriate, by notice through the Mars platform. Continued use of the Teams App after an update constitutes acceptance of the revised policy.

13. Contact us

Questions, requests, or complaints can be sent to mars-support@marssec.ai.

14. Governing law

This policy and any disputes relating to it are governed by the laws of the State of Israel, without regard to its conflict-of-laws principles. Nothing in this policy limits any non-waivable rights you may have under applicable local law.

MARS Security © 2026
SOC 2AWS Marketplace