What we collect, and what we refuse to.
We sell a security assessment. A privacy policy that overstates its own compliance would be a poor advertisement for that, so this one states what we actually do and names the law it does or does not fall under.
01 — Who we are
tenantsquared.com and the TenantSquared Baseline are operated by Patriot 7Six LLC, a Texas limited liability company doing business as TenantSquared. Patriot 7Six LLC is the controller of the personal data described here. Written notice reaches us at:
Patriot 7Six LLC
5900 Balcones Drive #28228
Austin, TX 78731
USA
privacy@patriot7six.com
This policy covers this website and the Baseline assessment we deliver to clients. It is written for the people who use them: prospective and current clients, and anyone who visits the site.
02 — What we collect
What you type into a form
Three forms on this site collect information, and each one collects only what its page shows you. Nothing here is optional-but-hidden, and no form asks for a contract number, a CAGE code, or anything else that could carry Controlled Unclassified Information.
| Form | Fields |
|---|---|
| Checkup | Name, work email, company. |
| Baseline request | Name, work email, company, your role, Microsoft 365 seat count, license plan if you know it, whether you hold or expect DoD contracts or flow-down requirements, free text about what prompted the request, and how you heard about us. |
| Discovery survey | Role, seat count, who owns security at your company, monthly security spend, what triggered your interest, evidence timeline, reaction to price, purchase authority, and what would make the decision easy. |
A submission is associated with the identifier stored by the analytics cookies described below, so that a second enquiry from you is recognised as yours instead of creating a duplicate record. Turning analytics off stops that identifier from being set or sent.
What is collected because you loaded a page
We record page views, clicks on links and buttons, and browser errors, so we can see which pages lead to an enquiry and which ones fail. An identifier is stored in your browser, and an approximate city is derived from your IP address rather than the address being kept as part of the record.
We do not record your screen, your keystrokes, or the contents of anything you type into a page. We do not build an individual profile of visitors: no one signs in here, and our analytics is configured so that a visitor who is never identified never gets a person record. Ordinary server logs, which include IP addresses, are kept briefly so outages and abuse can be diagnosed.
The cookies and their lifetimes are itemised in the Cookie Policy, along with the switch that turns the optional ones off.
03 — Assessment data and the CUI rule
During a Baseline we read configuration and reporting data from your Microsoft 365, Active Directory, or Azure environment: policy settings, role assignments, licensing, authentication methods, and audit configuration. It includes the names, email addresses, and sign-in configuration of the accounts in your environment, because an account inventory is most of what a hygiene review looks at.
We do not read content. The access you grant carries no permission to read mailboxes, files, document libraries, chat messages, or notebooks. Read-only is the whole design: nothing we run writes to your environment, changes a setting, or creates an account. The most common engagement uses an interactive sign-in that expires with the session and leaves no standing access behind.
We never collect or store Controlled Unclassified Information. This is a product rule, not a preference. If CUI would have to enter the assessment for a finding to be made, the finding does not get made. If you believe CUI has reached us in error, write to privacy@patriot7six.com and we will destroy it and confirm in writing.
TenantSquared renders no compliance verdicts. Findings are mapped to NIST SP 800-171 control families so you can answer a prime’s questionnaire in its own vocabulary. Nothing we produce says you are compliant.
04 — Why we hold it, and on what basis
Form submissions exist so we can answer you, send the Checkup you asked for, scope an engagement, and understand what small defense suppliers need. Analytics exists so we can tell which pages lead to a request. Assessment data exists to produce your findings report. Server logs exist to keep the site running and to investigate abuse.
For anyone whose data is protected by the European or United Kingdom General Data Protection Regulation, the lawful bases we rely on are these. Answering your enquiry and running a secure website rest on our legitimate interests in operating and defending the business. Delivering an assessment rests on the contract with your company. Analytics rests on your consent, which we ask for before anything loads if you are in the EEA or the UK, and which you can withdraw at any time using the switch below. Keeping invoices and contracts rests on our legal obligations.
We do not use any of it for advertising, we do not sell it, and we do not share it for cross-context behavioural advertising. If that ever changes, this policy changes first and the change gets its own notice.
05 — Who else sees it
A small number of service providers process data on our behalf so that the site, our contact records, and the assessment platform can run. Each is bound by a written contract that permits it to act only on our instructions, forbids it from using your data for its own purposes, and requires it to protect the data. None of them is an advertising network or a data broker. Clients who need the providers identified for a vendor review get that list in writing under the engagement agreement.
Outside those providers, we disclose personal data only when a law or valid legal process requires it, when it is needed to establish or defend a legal claim, or if the business is sold or merged, in which case the buyer inherits this policy until it publishes its own and tells you.
Reading configuration from your own Microsoft environment does not send your data to Microsoft through us. That relationship is yours, under your own agreement with them.
06 — Cookies and your opt-out
If you are visiting from the European Economic Area or the United Kingdom, analytics does not run until you agree to it. Everywhere else it runs on arrival and a notice tells you so. The control below reflects whichever applies to you, and it takes effect immediately: collection stops and anything already stored is revoked.
Checking your current setting…
The setting is stored in this browser only. Clearing site data, using a different browser, or browsing privately will start you back at the default, which is on.
If your browser or an extension sends a Global Privacy Control signal, we treat it as an opt-out and this site will not override it. That is enforced in code, not just described here.
07 — How long we keep it
We keep personal data only as long as it serves the purpose it was collected for, then delete it. What that means in practice depends on the data: an enquiry we never hear from again is deleted once it is clearly stale, and assessment findings are kept while they are useful to the client for renewals and audits, then deleted. Ask us to delete something sooner and we will, unless a law requires us to keep it.
Some records we cannot delete on request. Invoices, contracts, and tax records are kept for as long as federal and Texas law require, and anything under a legal hold is kept until the hold lifts.
08 — Your rights
Ask us and we will tell you what we hold about you, correct it, delete it, restrict or stop a particular use of it, or send you a copy in a portable format. Where we rely on your consent you can withdraw it at any time, which does not affect what we did before you withdrew it. Write to privacy@patriot7six.com.
We answer within 45 days. We will not charge you, and we will not treat you differently for asking. We may need to confirm who you are before we act, which is a protection for you rather than an obstacle.
We sell to United States companies and do not market to people outside the country. We grant the rights above to anyone who asks regardless of where they live, including people covered by the European or United Kingdom GDPR, whether or not a statute compels us. Anyone covered by the GDPR also keeps the right to complain to their national supervisory authority, and nothing here waives that.
09 — Where US law lands
Being straight about which statutes actually reach us matters more than claiming all of them. The Texas Data Privacy and Security Act, Chapter 541 of the Texas Business and Commerce Code, applies to a person who conducts business in Texas, processes or sells personal data, and “is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies.” Section 541.107 forbids a small business from selling sensitive personal data without the consumer’s prior consent. Patriot 7Six LLC is an SBA small business, so most of Chapter 541 does not reach us by its own terms, and the part that does is satisfied by the fact that we sell no personal data at all.
The California Consumer Privacy Act has revenue and volume thresholds we do not meet. We honour the same access, correction, deletion, and portability requests anyway. If we ever cross one of those thresholds, this policy will say so plainly rather than quietly starting to matter.
If you are in Texas and believe we have mishandled your data, you may complain to the Texas Attorney General.
10 — How we protect it
Data is encrypted in transit and at rest. Access is limited to the people who need it for the work in front of them, enforced by role rather than by convention, and administrative credentials are never exposed to a browser. The Security page answers the questions a vendor review tends to ask.
No system is perfect and we will not pretend otherwise. If we discover a breach affecting your data, we will tell you what happened, what was affected, and what we did about it.
11 — Children, location, and changes
This is a business-to-business service. It is not directed at children, and we do not knowingly collect data from anyone under 18. If we learn we have, we delete it.
We operate in the United States and the data described here is processed in the United States. If you use this site from elsewhere, your information is transferred here. Where a transfer of European or United Kingdom personal data needs a safeguard, we use the European Commission’s standard contractual clauses and the United Kingdom addendum.
When this policy changes, the effective date at the top changes with it. A change that materially affects what we collect or who receives it gets a notice on the site, and an email if we have your address because you asked us for something.
12 — Contact
Privacy questions, requests, and complaints go to privacy@patriot7six.com, or to the mailing address in section 01. A real person reads that inbox.