Privacy notice Microsoft 365
Information pursuant to Art. 13, 14 of the GDPR about the use of your personal data
Responsible entity and contact information
The responsible entity within the meaning of data protection law is
Nexia GmbH
Wirtschaftsprüfungsgesellschaft | Steuerberatungsgesellschaft
Georg-Glock-Straße 4, 40474 Düsseldorf, Germany
You will find further information about our company, details of the persons authorized to represent us and also further contact options in our Legal Notice on our website. https://www.nexia.de/legal-notice
Contact details of the data protection officer: datenschutz@nexia.de
Purpose of the processing
Nexia GmbH uses various applications within the Microsoft 365 cloud service, including in particular Word, Excel, PowerPoint, Outlook, OneDrive, SharePoint, and Microsoft Forms.
These applications are used for internal and external collaboration, communication, document processing, and the organization of business processes.
Microsoft Forms may be used in particular for registrations, requests for information, surveys, feedback, internal data collection, and similar forms. The specific purpose of each form is described in the form itself or in the accompanying information.
Depending on the purpose, the forms may be directed at employees, clients, business partners, event participants, or other individuals.
Legal basis for data processing
The applicable legal basis depends on the specific purpose for which Microsoft 365 and Microsoft Forms are used.
Processing may in particular be carried out:
- for the performance of a contract or in order to take steps prior to entering into a contract pursuant to Article 6(1)(b) GDPR;
- for compliance with a legal obligation pursuant to Article 6(1)(c) GDPR;
- for the purposes of the legitimate interests pursued by Nexia GmbH pursuant to Article 6(1)(f) GDPR, in particular for the organization of business processes, communication, the conduct of surveys, and the improvement of our services;
- in the employment context on the basis of Section 26 of the German Federal Data Protection Act (BDSG); or
- on the basis of consent pursuant to Article 6(1)(a) GDPR, where consent is required in the individual case.
Where consent is requested, it is voluntary and may be withdrawn at any time with effect for the future. Where necessary, we will provide information about the specific purpose and the applicable legal basis directly in the relevant form or in the accompanying information.
Which data is processed?
When using Microsoft 365, different types of data are processed. The scope of the data depends on what data you store in these cloud applications and what synchronization you set.
When Microsoft Forms is used, the following categories of personal data may be processed, depending on the specific form:
- basic identification and contact data, such as name, company, job title, email address, or telephone number;
- information from a Microsoft 365 user account, where participation requires sign-in;
- information you provide in selection fields, rating fields, or free-text fields;
- data relating to registrations, appointment requests, feedback, or survey responses;
- technical connection and usage data generated when the form is accessed and used; and
- the date and time of participation or submission.
The specific information processed in each case is determined by the relevant form. Optional information will be identified accordingly, unless its voluntary nature is already clear from the context.
Please do not enter any special categories of personal data or confidential information in free-text fields unless such information is expressly required and requested for the relevant purpose.
When using Microsoft 365, personal data is processed in the course of your professional activities, which your organization provides, for example, via your user account. The type and scope of personal data processed about you depends primarily on what information you or others process about you with Microsoft 365 when using Microsoft Office (Word, Excel, PowerPoint), Exchange, OneDrive and SharePoint. The data is generally stored on Microsoft servers in the European Union (EU). Microsoft has taken extensive data protection measures and has also concluded the EU standard contractual clauses, which ensure that the service provider is committed to complying with European data protection law. The Microsoft Cloud also has ISO27001 certification, among other things.
Scope of the processing
Automated decision-making within the meaning of Art. 22 GDPR is not used.
Recipients / data transfer
Within Nexia GmbH, access to personal data is limited to those employees and business units that require the data for the relevant purpose.
Microsoft processes personal data as a service provider engaged by us in connection with the provision of Microsoft 365 and Microsoft Forms.
When Microsoft Forms is used, access to the responses is granted in particular to the employees responsible for creating, administering, and evaluating the relevant form. Personal data will be disclosed to additional recipients only where this is necessary for the stated purpose, required by law, or based on your consent.
Where additional recipients are involved, they will be identified in the relevant form or in the accompanying information.
Data processing outside the European Union
Data processing outside the European Union does not take place as a matter of principle, as we have limited our storage location to data centers in the European Union. The data is encrypted during transport via the Internet and thus protected against unauthorized access by third parties.
Your rights as a data subject
You have the right to obtain information about the personal data concerning you. You can contact us for information at any time.
In the case of a request for information that is not made in writing, we ask for your understanding that we may require proof from you that you are the person you claim to be.
Furthermore, you have a right to rectification or deletion or to restriction of processing, insofar as you are entitled to this by law.
Finally, you have a right to object to processing within the scope of legal requirements.
A right to data portability also exists within the framework of data protection law.
Deletion of data
We delete personal data once it is no longer required for the relevant processing purpose and no statutory or contractual retention obligations prevent its deletion.
Data collected through Microsoft Forms is generally deleted once the relevant form has been closed, the evaluation has been completed, and further storage is no longer required for the stated purpose.
A longer retention period may be necessary in particular where the data:
- is required for the performance of a contract or the organization of an event;
- is subject to statutory retention obligations;
- is required to document consent that has been given; or
- is necessary for the establishment, exercise, or defense of legal claims.
Where a different retention period applies to a specific form, this will be explained in the form itself or in the accompanying information.
Right of complaint to a supervisory authority
You have the right to complain about the processing of personal data by us to a data protection supervisory authority.
Modification of this privacy notice
We revise this data privacy notice in the event of changes to data processing or other occasions that make this necessary. You will always find the current version on this page.
Additional Information About Privacy at Microsoft
For more information about Microsoft’s processing of personal data and the privacy and security measures applicable to Microsoft cloud services, please visit:
Microsoft Privacy Statement:
https://www.microsoft.com/en-us/privacy/privacystatement
Microsoft Trust Center – Privacy:
https://www.microsoft.com/en-us/trust-center/privacy
Information About the Microsoft EU Data Boundary:
https://learn.microsoft.com/en-us/privacy/eudb/eu-data-boundary-learn
Last update of the Microsoft 365 privacy notice: 07/2026