Privacy policy
1. Controller
CHAOS GmbH, Am Gewerbepark 5, 8241 Dechantskirchen, Austria
Company register no. FN 654219 m
(formerly DRG Services GmbH; renamed August 2026, same legal entity)
E-mail: contact@chaos.ms
Services: portal.chaos.ms, reseller.chaos.ms, selfservice.chaos.ms
Data protection officer (if appointed):
Name: Gerhard Moser
E-mail: gm@ms.at
If you have any questions regarding data protection, you can reach us at the e-mail address provided above.
2. General information on data processing
As a matter of principle, we only process personal data of our users to the extent necessary to provide our products for reviewing and optimising software licences.
This privacy notice applies if:
- you visit one of our websites, social media pages or our business premises,
- you use one of our applications or platforms,
- you register for or participate in virtual or in-person events that we host or attend,
- your employer works with us,
- you contact our customer support,
- you otherwise interact or communicate with us.
In the following, these activities are collectively referred to as “services”.
Detailed information about the cookies we use on our websites can be found in the cookie notice.
3. Data collected and purposes of processing
Contact and business data
This data category includes, among others:
- Company data (name, address, register number)
- Contact details of contact persons (name, e-mail, phone, position)
- Contract data (contract number, term, scope of services)
- Invoicing and payment data
- Usage data of the software
Communication and interaction data
This data category includes data that arises from your interaction with us, e.g. e-mails, chat messages, downloaded files.
Application-related usage data
This category includes information about how and whether certain functions of our services are used, e.g. which applications, which versions, analyses created, information on system configuration, log-file data as well as date and time stamps in connection with the use of the services.
Purpose of processing
Provision of the requested service
To provide the requested service and to ensure that we fulfil our contractual obligations towards you or your organisation. This includes, among other things, resolving technical problems, providing training in connection with our services and answering enquiries we receive via our website, by e-mail or by other means.
Improving and expanding our services
To improve our operations, systems, products and processes and increase their usefulness, we analyse aggregated, anonymised or statistical usage and system data and conduct surveys about our services.
Information security and compliance
We collect and process personal data to protect, investigate and prevent our services against fraudulent, unauthorised or illegal activities, and to prevent and detect attacks on our applications or misuse of our services. To ensure appropriate security of our office premises and to comply with legal and regulatory obligations.
To carry out sales and marketing activities
To inform you about our events, products and services and for direct marketing. To process your registration for our events and to provide you with event materials.
Other permitted purposes
Other permitted purposes include, for example, conducting customer surveys, evaluating our marketing campaigns and analysing and improving our customer relationships.
- Initiation, conclusion and performance of the contractual relationship
- Provision and maintenance of the software
- Customer care and support
- Invoicing and payment processing
The processing of personal data is based on the following legal bases pursuant to Art. 6 GDPR:
- Art. 6(1)(a) GDPR – Consent: where you have given us your explicit consent to the processing
- Art. 6(1)(b) GDPR – Performance of a contract: where the processing is necessary to perform a contract with you or to carry out pre-contractual measures
- Art. 6(1)(c) GDPR – Legal obligation: where the processing is necessary to comply with a legal obligation
- Art. 6(1)(f) GDPR – Legitimate interests: where the processing is necessary to safeguard our legitimate interests, provided that your interests or fundamental rights do not override them
Storage period: For the duration of the contractual relationship and subsequently to fulfil statutory retention obligations (generally 7 years pursuant to §§ 212, 132 of the Austrian Federal Fiscal Code, BAO).
4. Processing on behalf (data processing)
Within the scope of using our software, personal data of end users (employees of our customers) may be processed. In this relationship the customer is the controller (it determines purpose and means: analysis, setup script, administrator consent, setup mode). CHAOS GmbH is software manufacturer and processor. A reseller provides sales and onboarding; it is not the manufacturer and not the operator of the Graph analysis and is not a sub-processor for employee data insofar as it only sees master and order data. Processing at CHAOS takes place on Microsoft Azure, region West Europe (EU).
Retrieval from the Microsoft 365 tenant via Microsoft Graph and the administrator consent for the app are subject to the customer’s Microsoft 365 contract with Microsoft (Microsoft Customer Agreement or Online Services DPA). Subsequent storage and analysis at CHAOS are subject to the data processing agreement with CHAOS GmbH.
Possible categories of end-user data:
- User name and login data
- IP addresses
- Usage behaviour within the software
- Software licence assignments
- Usage and storage metadata (e-mail, Teams, SharePoint, OneDrive) – no site or mail contents
- Security-posture metadata (Secure Score, Identity Protection, Conditional Access), insofar as the chosen setup mode includes this
- AI & Copilot (optional): Copilot usage and licence data, agent inventory and Copilot credit consumption; with the permission AiEnterpriseInteraction.Read.All, metrics from the Copilot interaction history (prompt and response texts are neither stored nor logged)
- Other data transmitted by the customer
Setup modes: Full version (read + optional remediation), -Readonly (read only), -LeastPrivilege (read without unused permissions, in particular without Sites.Read.All and without Defender Hunting/Alert/Incident/Machine). Details in the technical privacy notice (section 4).
Purpose of processing: Exclusively to provide the contractually agreed service (analysis and optimisation of software licences) on the documented instructions of our customer.
Legal basis: Art. 28 GDPR in conjunction with a data processing agreement (DPA)
Particularities of the processing on behalf:
- We process this data exclusively on the documented instructions of the controller (our customer)
- A data processing agreement pursuant to Art. 28 GDPR is concluded with every customer
- All employees with access to the data are bound to confidentiality
- We support our customers in fulfilling data subjects’ rights
- After the end of the service, all data is deleted or returned at the customer’s choice
Important note for end users: If you are an employee of a company that uses our software, your employer is the controller for the processing of your personal data. For information and to exercise your data subject rights, please first contact your employer.
You can find the detailed contractual arrangement in the data processing agreement (Art. 28 GDPR).
5. Disclosure of data
Your personal data is only transferred to third parties if:
- this is necessary for the performance of the contract
- there is a legal obligation
- you have expressly consented
Possible recipients:
- IT service providers (e.g. hosting providers, cloud services) – on the basis of data processing agreements
- Payment service providers
- Tax advisors and auditors
- Authorities where there is a legal obligation
6. Transfer of data to third countries
Your personal data is only transferred to countries outside the European Union or the European Economic Area if this is necessary to perform the data processing agreement or if another legal basis exists. In such cases we ensure that an adequate level of data protection is guaranteed, e.g. by concluding standard contractual clauses.
7. Retention period
We store your personal data only for as long as is necessary to fulfil the purposes stated above or as long as statutory retention obligations exist. Once the purpose ceases to apply or statutory retention periods expire, the data is securely deleted.
8. Your rights
You have the following rights in relation to your personal data:
- Right of access: You have the right to request information about the personal data we process.
- Right to rectification: You may request the correction of inaccurate data or the completion of your personal data.
- Right to erasure: Under certain conditions you may request the deletion of your personal data.
- Right to restriction of processing: Under certain conditions you may request the restriction of the processing of your personal data.
- Right to data portability: You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transfer it to another controller.
- Right to object: You may object to the processing of your personal data where it is based on a legitimate interest.
- Right to withdraw consent: Where the processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of the processing carried out until withdrawal.
- You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.
Competent supervisory authority in Austria:
Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42
1030 Vienna
Phone: +43 1 52 152-0
E-mail: dsb@dsb.gv.at
Website: www.dsb.gv.at
To exercise your rights, you can contact us at any time: contact@chaos.ms
9. Data security
We take extensive technical and organisational measures pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons.
Our security measures include, among others:
- Encryption of data transmission (SSL/TLS)
- Access control systems and authorisation concepts
- Regular security updates
- Logging of system access
- Regular data backups
- Confidentiality obligations of all employees
Our security measures are continuously improved in line with technological developments.
9a. DORA (financial and insurance undertakings only)
Where the customer is a financial entity or insurance undertaking within the meaning of Regulation (EU) 2022/2554 (DORA), or DORA otherwise applies, the DORA addendum applies in addition (accepted by confirming AGB, privacy policy and DPA — no separate signature). For other customers, the DORA addendum does not apply. GDPR Arts. 33/34 remain unaffected.
10. Changes to this privacy policy
We reserve the right to amend this privacy policy where necessary, in particular to adapt it to legal requirements or changes to our services. The current version of the privacy policy is available on our website.