Privacy Policy

Effective August 18, 2026

OutfIT is an internal IT-operations application provided by Convergent Energy and Power (“Convergent,” “we,” “us”). It runs on top of your organization’s Microsoft 365 tenant to manage app governance and the employee lifecycle. This policy explains what personal data OutfIT processes, why, who it is shared with, how long it is kept, and the choices available to the people it describes.

Who this applies to

OutfIT is a business tool used by IT, HR, and administrators within an organization that licenses it. The people whose data appears in OutfIT are primarily employees, new hires, and administrators of that organization. It is not a consumer product and has no public sign-up: access requires signing in with a Microsoft work account.

Where OutfIT processes personal data on your organization’s behalf, your organization is the data controller and Convergent acts as a processor under its agreement with you.

Data we collect

We collect and process the following categories of personal data:

  • Account & identity data — name, work email/UPN, department, manager, role, and group memberships, sourced from Microsoft Entra ID via single sign-on.
  • New-hire & onboarding data — personal and job details entered during intake, including personal email and phone, mailing address, start date, role type, hardware and software selections, and background-check status.
  • Uploaded documents — files you attach to requests, tasks, or onboarding records (for example invoices, contracts, or supporting PDFs and images).
  • Content you submit to AI features — meeting notes, questions to the Task Center copilot, and document text you choose to have summarized or extracted (see Use of AI).
  • Operational & audit data — request and task history, approvals, provisioning results, and security/audit logs, along with technical metadata such as correlation IDs used for troubleshooting.

OutfIT does not sell personal data and does not use it for advertising.

How we use it

We use personal data only to operate the service, specifically to:

  • Route app requests and new-hire onboarding through their approval and provisioning steps.
  • Create and manage Microsoft accounts, licenses, and group memberships in your tenant.
  • Maintain the app inventory and governance records.
  • Provide optional AI-assisted summaries, extraction, and copilot answers where enabled by your administrator.
  • Secure the service, prevent abuse, keep audit trails, and meet legal and compliance obligations.

Use of AI

OutfIT includes optional features that use artificial intelligence, powered by Anthropic’s Claude models accessed through the Anthropic API. These features are enabled by your administrator and include:

  • Summarizing manager meeting notes.
  • The Task Center copilot (“Ask Convergent”), which answers questions from the tasks you can already see and proposes actions for you to confirm.
  • Extracting structured facts from spend and contract documents you provide.
  • Generating renewal-negotiation briefs from structured contract facts only (no free-text personal content).

When you use these features, the relevant text you submit is sent to Anthropic to generate the result. AI output is treated as a draft or proposal for human review — it does not make final decisions on its own, and proposed actions run through the normal, audited paths only after a person confirms them. We do not use your data to train third-party AI models.

These AI features are a general productivity aid, not a crisis, medical, legal, or emergency service, and should not be relied on as one.

Third parties & sub-processors

We share personal data with the service providers below strictly to operate OutfIT. Each processes data on our or your organization’s behalf under its own contractual and security obligations. We do not share personal data with third parties for their own marketing.

ProviderPurposeData involved
Microsoft (Entra ID, Graph, Defender for Cloud Apps, Azure)Identity and single sign-on, account/license/group provisioning, shadow-IT discovery, and hosting (Azure Blob Storage, database).Directory identity, employee and new-hire profile data, uploaded documents.
Anthropic (Claude API)Optional AI features: meeting-note summaries, the Task Center copilot, and document/contract fact extraction.Only the specific text submitted to a given feature — e.g. meeting notes or a document's text. Structured facts only for renewal briefs.
WorkablePre-filling the new-hire intake form from an accepted-offer or hired candidate.Candidate name, contact details, job/role, and start date.
HuduApp inventory of record, synced daily.App/vendor and contract metadata (no employee personal data).
Google Maps Geocoding / OpenStreetMap NominatimVerifying a new hire's mailing address for equipment shipment.The address entered on the equipment form.
Upstash (Redis)Rate limiting, when configured.Coarse request metadata (e.g. hashed identifiers / IP), not profile content.

We may also disclose data where required by law or to protect the rights, safety, and security of our users and the service.

Retention & deletion

We retain personal data for as long as needed to provide the service and to meet your organization’s legal, audit, and record-keeping requirements, then delete or anonymize it.

Uploaded files are deletable. When you delete a document or attachment, or delete the request, task, or onboarding record it belongs to, the underlying file is removed from storage. Document uploads are held in a private storage container with no public access; files are served only through short-lived, access-controlled links.

How we protect data

  • Access requires Microsoft single sign-on; there are no anonymous accounts.
  • Role-based access controls limit who can see sensitive fields and take administrative actions.
  • Document storage is private by default and encrypted in transit and at rest by our hosting provider.
  • A strict Content Security Policy, per-request nonces, rate limiting, and audit logging protect the application surface.

No system is perfectly secure, but we design OutfIT to minimize the risk and to keep it under your organization’s control.

Your rights & choices

Depending on your location and your organization’s policies, you may have the right to access, correct, delete, or restrict the processing of your personal data, or to object to certain processing. Because your organization controls the data in its OutfIT tenant, please direct such requests to your organization’s IT or HR administrator, who can action them or forward them to us.

You can reach us directly at the address below with any privacy question or request.

Changes to this policy

We may update this policy as the service changes. When we do, we will revise the effective date above and, where changes are material, provide notice through the product or to your administrator.

Contact us

For questions about this policy or your personal data, contact us at privacy@convergentep.com.