1. What the agent collects
The Amicis Commerce Agent receives only what Microsoft 365 Copilot forwards as part of a tool call. Concretely, that means:
- Tool call arguments — the specific parameters Copilot sends to invoke a capability (for example, a register name, store ID, agent ID, or a free-text search query you asked Copilot to run).
- Identity claims from your Microsoft Entra ID token — your tenant ID and user object ID (OID), as issued by your organization's Entra tenant. We use these to authenticate the request and scope data to your organization.
The Agent Hub does not store conversation transcripts, prompts, or Copilot's responses. Each tool call is processed and discarded.
2. How data flows
- Microsoft 365 Copilot calls our hosted
/mcpendpoint (Azure Container Apps) with a bearer token carrying theAmicis.Commerce.Usescope. - The Agent Hub validates the token against your Entra tenant and routes the tool call to one of two destinations:
- Cloud Hub database (Azure SQL) — for fleet, onboarding, and organization data scoped to your tenant.
- Your organization's configured issue-tracking system — when you ask Copilot to file or search support issues, the Agent Hub routes the request to the backlog system your organization has configured (for example, GitHub, Azure DevOps, Jira, or a help-desk system).
- The tool result is returned to Copilot, which composes the reply you see.
3. Tenant isolation
Every record in our Cloud Hub database is keyed by Microsoft Entra tenant ID. Authenticated requests can only read or modify rows belonging to the caller's tenant.
A small number of tools (notably cross-tenant support-issue search) read from a shared support-data store. Those results are PII-redacted server-side before they leave the Agent Hub — tenant attribution, author identities, and any organization-identifying strings are stripped. No tenant can see another tenant's identifying information.
4. Data retention
- Fleet presence and configuration (agents online/offline, last-connected timestamps, onboarding state) — retained while your organization is active.
- Support issues — retained in your organization's configured issue-tracking system per its own retention policy.
- Conversation history — not stored by the Agent Hub. Microsoft 365 Copilot may retain its own conversation history per your organization's Microsoft 365 policies.
5. Third-party services
- Microsoft Entra ID — authentication and identity.
- Azure Container Apps — hosting of the Agent Hub and Cloud Hub.
- Azure SQL Database — storage of fleet and onboarding data.
- Your organization's issue-tracking system — support issues filed through the agent are routed to your configured backlog system. No issue content is shared across tenants.
Data is used solely to provide the fleet-management service. We do not share tenant data with third parties for advertising or analytics purposes.
6. What we do NOT collect
- No payment-card or financial-account data.
- No customer personally identifiable information (PII) from your retail transactions.
- No transaction details, receipts, or sales records.
- No conversation transcripts or Copilot prompt content.
- No clipboard contents.
- No screenshots or screen recordings.
7. Your rights
For data access, correction, or deletion requests — or any privacy question — contact support@amicissolutions.com. We will respond within a reasonable period and coordinate with your organization's administrator where required.
8. Changes to this notice
We may update this notice to reflect changes to the agent or applicable law. Material changes will be reflected in the "Last updated" date above and, where appropriate, communicated to tenant administrators.
Contact
Amicis Solutions Inc. · support@amicissolutions.com · Terms of Service