Security & data protection

Written for IT administrators and DPOs. Last reviewed July 2026.

You're granting a third party access to your directory. That deserves a straight answer to three questions: what do we access, what do we store, and how is it protected?

What we access — and what we don't

SyncMyGAL uses four Microsoft Graph application permissions, approved once by your admin on the official Microsoft consent screen. This is the exact list that screen will show you — we never request anything beyond it:

The last two exist so you can narrow the sync, never to widen it. Leave the scoping rules empty and organizational contacts off, and they are simply never called.

We do not request access to email content, calendars, files, chats, or any other workload. We can't read a single message — the permissions don't allow it, and that's enforced by Microsoft, not by our promises. You can revoke access at any moment from your Entra ID portal, which cuts us off instantly.

What we store

Notably, we do not build a copy of your directory. GAL data is read from Graph, written to your employees' mailboxes, and discarded from memory. Your data lives in your tenant, not in our database.

How the service is protected

GDPR

Questions we welcome

If your security team has a vendor questionnaire, send it — answering those is part of the job, not an imposition. Reach us at security@syncmygal.com.

See pricing

Put your whole directory in every pocket.

Flat pricing per company, not per user. Live in 5 minutes — nothing to install on phones.

Request early access