Privacy Notice — Askme Office 365 Add-ins
This notice describes how personal data is processed by the Askme add-ins for Microsoft 365:
- Askme for Word — sends the open Word document to Askme Sign as a draft signature case.
- Askme for Outlook — creates a structured request in Askme Desk from an email.
- Askme Notify — delivers Askme notifications in Microsoft Teams.
It covers these applications specifically, not the askme.it website. For the website, see the general privacy notice. For the Askme mobile app, see the mobile app privacy notice.
Last updated:
Data controller
Lascaux S.r.l. a socio unico, Arezzo, Italy — VAT and tax code 01805480512.
Contact for data protection matters:
Important: where your data goes
These add-ins are not standalone services. They are front-ends to an Askme environment operated by your own organization (Askme Sign, Askme Desk). When you use them, your content is sent to your organization's environment — the one whose URL is configured in the add-in.
Your organization is the controller of the data held in that environment; Lascaux acts as processor under the agreement in place with your organization. This notice describes what the add-ins transmit and where.
Askme for Word
| Data | Purpose | Destination | Retention |
|---|---|---|---|
| The document open in Word, converted to PDF | Create the signature case | Your organization's Askme Sign environment | Per your organization's retention policy |
| Files you attach | Supporting documents of the case | Same | Same |
| Case name, workflow type, notes you enter | Case metadata | Same | Same |
| Askme Sign URL | Remember your configuration | Your browser's local storage, on your device | Until you clear it |
| Askme Sign API token | Authenticate you towards Sign | Askme service, encrypted at rest (AES-256-GCM) | Until expiry or your revocation |
Nothing is transmitted until you confirm the send. The document is not modified: a PDF copy is produced and the original file is left untouched.
No artificial intelligence processing takes place in Askme for Word, and no content is sent to any analysis service.
Askme for Outlook
| Data | Purpose | Destination | Retention |
|---|---|---|---|
| Subject, body and thread text of the email you act on | Classify the request and extract its attributes | Askme AI service | Not stored; not used to train models |
| Sender name and email address | Identify the requester among your organization's contacts | Your organization's Askme Desk environment | Per your organization's retention policy |
| Attachments you select, and the optional PDF copy of the message | Attach them to the request | Same | Same |
| Request fields you confirm | Create the request | Same | Same |
| Askme Desk and AI service URLs, your username | Remember your configuration | Your browser's local storage, on your device | Until you clear it |
| Askme Desk password, AI service API key | Authenticate you | Askme service, encrypted at rest (AES-256-GCM) | Until your revocation |
The add-in reads only the message you explicitly act on. It does not enumerate, modify or
delete other items in your mailbox; it requests the minimum Outlook permission (ReadItem)
required to do so.
Nothing reaches Askme Desk until you confirm. Every field suggested by the AI service remains editable before confirmation.
Askme Notify
| Data | Purpose | Destination | Retention |
|---|---|---|---|
| Your Microsoft 365 email address and Teams conversation reference | Deliver notifications addressed to you | Askme service | Until the app is uninstalled |
| Notification content sent by Askme modules | Show it to you in Teams | Microsoft Teams | Per Microsoft's retention for Teams messages |
| Messages you send to the bot | Answer your question | Askme AI service | Not stored; not used to train models |
The bot cannot message you until you have opened it at least once. Notifications are only delivered to the address they are addressed to.
Credential handling
Passwords, API tokens and API keys entered in the add-ins are not stored in your browser. They are transmitted once over HTTPS to the Askme service, encrypted at rest with AES-256-GCM, and your browser retains only a random opaque reference. The secret is never returned to the browser: the Askme service injects it into calls to your organization's environment.
This is why the credential fields appear empty when you reopen the settings. Each add-in offers a command to revoke the stored credentials.
What we do not do
- We do not use your documents, emails or messages to train AI models.
- We do not sell or share your content with third parties.
- We do not collect analytics or behavioural telemetry from the add-ins. Server-side operational logs record technical request data for reliability and security purposes.
- We do not access your mailbox, documents or Teams data other than what you explicitly act on.
Transfers and sub-processors
All traffic is encrypted in transit (HTTPS). Requests reach only Askme services and the Askme environment configured by your organization; requests to any other host are rejected.
Sub-processors and hosting locations:
Your rights
Under the GDPR you have the right to access, rectify, erase and restrict the processing of your personal data, to object to processing and to data portability.
Because the content processed by these add-ins is held in your organization's Askme environment, requests concerning it should be addressed to your organization as controller. For requests concerning Lascaux as controller, or for any question about this notice, write to .
You also have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali).
Changes to this notice
Changes are published on this page, with the "Last updated" date above. Material changes affecting how the add-ins process personal data will be communicated to customer organizations through the contractual channels in place.
Contact
Askme support: support.askme.it — [email protected]