Privacy Policy
Version 1.0 · Effective 2026-07-03
This Privacy Policy explains how DK Solution ("we", "us") collects and uses information through DKS Migration Tools (the "Service") — the public site, the authenticated Portal, and the DKS Migration Agent. It applies to the organizations and individuals who register for and administer the Service ("you"); it is not a substitute for your own privacy notice to the end users whose mailboxes or files you migrate.
1. Information We Collect
- Account & organization information — name, business email, company, phone, country, and the details you provide when creating an organization or completing onboarding.
- Migration configuration — source/destination endpoint hostnames, tenant/client identifiers, and connection credentials. Credential secrets (client secrets, service-account keys, IMAP passwords) are encrypted at rest before being stored, and are never displayed again once saved.
- Migration content, transiently — while a migration job runs, the Service and Agent read the mail, calendar, contact, or file items you've configured from the source and write them to the destination you've configured. This content is processed only to carry out the migration you requested; the Service does not retain a separate permanent copy of migrated content once a job completes, beyond the operational logs described below.
- Operational & audit logs — per-item migration status (counts, success/failure, timestamps), account audit events (sign-ins, admin actions), and consent records (see §6), each with a timestamp and IP address.
- Support & contact content — anything you submit through a support ticket or the contact form.
2. How We Use Information
To provide and operate the Service (run migrations, show progress and reports); to authenticate you and enforce access control; to send transactional email (account verification, password reset, license/order notifications, support replies); to respond to support requests; to maintain security and audit logs; and to meet our own legal and contractual obligations, including keeping evidence of your acceptance of these policies.
3. Sharing & Subprocessors
We do not sell personal data. Information is shared only with the systems needed to run the Service you configured, for example:
- Microsoft 365 / Microsoft Graph API — when a migration or transactional email targets or is sent through a Microsoft 365 tenant you've connected;
- Google Workspace API — when a migration targets or sources a Google Workspace domain you've connected;
- An SMTP relay — as a fallback transport for transactional email if Microsoft 365 delivery is unavailable.
Each of the above is invoked only for the migration or notification you configured — not for any secondary use.
4. Data Retention
Account and organization data is retained while your account is active, and for a reasonable period after for legal, audit, and dispute-defense purposes. Migration item logs and audit logs are retained as an operational and compliance record. Consent records (§6) are retained indefinitely as evidence of acceptance and are never deleted or altered. You may request deletion of your account data, subject to what we are required to retain by law or for legitimate audit purposes.
5. Security Measures
Connections to the Portal are encrypted in transit (HTTPS). Session cookies are
HttpOnly, Secure, and SameSite=Lax. Stored
credential secrets are encrypted at rest. Administrative actions are recorded in an
append-only audit trail. Multi-factor authentication is available for Portal accounts.
See our Security page for more —
these are descriptions of our controls, not a claim of any certification or regulatory
compliance.
6. Consent Records
When you accept these Terms or this Privacy Policy (for example when registering), we record the email address, the document and version accepted, the date/time, your IP address, and your browser's user-agent string. This is kept specifically so that acceptance of these documents can be verified later if ever disputed — it is not used for any other purpose.
7. Your Rights
You may request access to, correction of, or deletion of your account information by contacting us through our Contact page. We will respond within a reasonable time, subject to the retention exceptions described in §4.
8. Cookies
The Portal uses a single first-party session cookie to keep you signed in. We do not use third-party advertising or tracking cookies.
9. Children's Privacy
The Service is a business tool and is not directed at, or knowingly used to collect information from, children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by a new version number and effective date at the top of this page.
11. Contact
Questions about this Privacy Policy can be sent through our Contact page.