Passa al contenuto principale

Privacy Notice — Askme Office 365 Add-ins

This notice describes how personal data is processed by the Askme add-ins for Microsoft 365:

  • Askme for Word — sends the open Word document to Askme Sign as a draft signature case.
  • Askme for Outlook — creates a structured request in Askme Desk from an email.
  • Askme Notify — delivers Askme notifications in Microsoft Teams.

It covers these applications specifically, not the askme.it website. For the website, see the general privacy notice. For the Askme mobile app, see the mobile app privacy notice.

Last updated:

Data controller

Lascaux S.r.l. a socio unico, Arezzo, Italy — VAT and tax code 01805480512.

Contact for data protection matters:

Important: where your data goes

These add-ins are not standalone services. They are front-ends to an Askme environment operated by your own organization (Askme Sign, Askme Desk). When you use them, your content is sent to your organization's environment — the one whose URL is configured in the add-in.

Your organization is the controller of the data held in that environment; Lascaux acts as processor under the agreement in place with your organization. This notice describes what the add-ins transmit and where.

Askme for Word

DataPurposeDestinationRetention
The document open in Word, converted to PDFCreate the signature caseYour organization's Askme Sign environmentPer your organization's retention policy
Files you attachSupporting documents of the caseSameSame
Case name, workflow type, notes you enterCase metadataSameSame
Askme Sign URLRemember your configurationYour browser's local storage, on your deviceUntil you clear it
Askme Sign API tokenAuthenticate you towards SignAskme service, encrypted at rest (AES-256-GCM)Until expiry or your revocation

Nothing is transmitted until you confirm the send. The document is not modified: a PDF copy is produced and the original file is left untouched.

No artificial intelligence processing takes place in Askme for Word, and no content is sent to any analysis service.

Askme for Outlook

DataPurposeDestinationRetention
Subject, body and thread text of the email you act onClassify the request and extract its attributesAskme AI serviceNot stored; not used to train models
Sender name and email addressIdentify the requester among your organization's contactsYour organization's Askme Desk environmentPer your organization's retention policy
Attachments you select, and the optional PDF copy of the messageAttach them to the requestSameSame
Request fields you confirmCreate the requestSameSame
Askme Desk and AI service URLs, your usernameRemember your configurationYour browser's local storage, on your deviceUntil you clear it
Askme Desk password, AI service API keyAuthenticate youAskme service, encrypted at rest (AES-256-GCM)Until your revocation

The add-in reads only the message you explicitly act on. It does not enumerate, modify or delete other items in your mailbox; it requests the minimum Outlook permission (ReadItem) required to do so.

Nothing reaches Askme Desk until you confirm. Every field suggested by the AI service remains editable before confirmation.

Askme Notify

DataPurposeDestinationRetention
Your Microsoft 365 email address and Teams conversation referenceDeliver notifications addressed to youAskme serviceUntil the app is uninstalled
Notification content sent by Askme modulesShow it to you in TeamsMicrosoft TeamsPer Microsoft's retention for Teams messages
Messages you send to the botAnswer your questionAskme AI serviceNot stored; not used to train models

The bot cannot message you until you have opened it at least once. Notifications are only delivered to the address they are addressed to.

Credential handling

Passwords, API tokens and API keys entered in the add-ins are not stored in your browser. They are transmitted once over HTTPS to the Askme service, encrypted at rest with AES-256-GCM, and your browser retains only a random opaque reference. The secret is never returned to the browser: the Askme service injects it into calls to your organization's environment.

This is why the credential fields appear empty when you reopen the settings. Each add-in offers a command to revoke the stored credentials.

What we do not do

  • We do not use your documents, emails or messages to train AI models.
  • We do not sell or share your content with third parties.
  • We do not collect analytics or behavioural telemetry from the add-ins. Server-side operational logs record technical request data for reliability and security purposes.
  • We do not access your mailbox, documents or Teams data other than what you explicitly act on.

Transfers and sub-processors

All traffic is encrypted in transit (HTTPS). Requests reach only Askme services and the Askme environment configured by your organization; requests to any other host are rejected.

Sub-processors and hosting locations:

Your rights

Under the GDPR you have the right to access, rectify, erase and restrict the processing of your personal data, to object to processing and to data portability.

Because the content processed by these add-ins is held in your organization's Askme environment, requests concerning it should be addressed to your organization as controller. For requests concerning Lascaux as controller, or for any question about this notice, write to .

You also have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali).

Changes to this notice

Changes are published on this page, with the "Last updated" date above. Material changes affecting how the add-ins process personal data will be communicated to customer organizations through the contractual channels in place.

Contact

Askme support: support.askme.it[email protected]