Legal

Privacy Policy

Last updated: 20 July 2026

Testgrity is operated by DYNAMICSDUO (ABN 93 257 340 580). This Privacy Policy explains how we collect, use, store, and disclose personal information when you visit our website or use the Testgrity test automation service (the “Service”).

1. Information we collect

Account and identity information

When you sign in, we may receive your name, email address, unique account identifier, and basic profile information from Microsoft Entra External ID. If profile editing is enabled, the Service may use Microsoft Graph to read or update the profile fields you choose.

Workspace and test information

We store information you create or provide through the Service, including projects, environments, application URLs, test suites, cases, steps, recordings, run history, results, and workspace membership information.

Connection and authentication information

To run tests, the Service may store an encrypted reusable browser session for a connected Dynamics 365 or Power Apps environment. Passwords used for unattended connection are used to establish the connection and are not retained by the Service. Interactive browser connections keep Dynamics credentials and cookies in your browser.

Test artifacts and support information

Depending on workspace settings, test runs may create screenshots, video, Playwright traces, error details, and reports. These artifacts can contain information visible in the application being tested. If you submit an issue report, we collect the description, diagnostic details, and any screenshots you choose to attach.

Technical information

We may process browser and device information, IP address, request and error logs, timestamps, and security events to operate, protect, and troubleshoot the Service.

How we collect information

We collect information directly from you when you sign in, use the Service, configure a workspace, connect an environment, run tests, or contact us. We may also receive information from your workspace owner or administrator, Microsoft Entra External ID, connected Dynamics 365 or Power Apps environments, and optional integrations enabled by your organisation.

2. How we use information

We use information to:

  • provide, authenticate, maintain, and secure the Service;
  • create and manage workspaces, connections, tests, and reports;
  • execute tests and retain the evidence selected by your workspace;
  • respond to support requests and investigate errors or misuse;
  • improve reliability, performance, and user experience; and
  • meet legal obligations and enforce our agreements.

We do not sell personal information or use customer test data for third-party advertising.

3. Cookies

The Service uses strictly necessary cookies for sign-in, session security, and authentication flows. These cookies are HTTP-only where appropriate and are not used for advertising. Disabling them may prevent you from signing in or using authenticated features.

4. When we disclose information

We may disclose information:

  • to hosting, database, storage, security, and other service providers that process it on our behalf;
  • to Microsoft when you use Microsoft Entra External ID, Microsoft Graph, Azure-hosted services, Dynamics 365, or Power Apps;
  • to GitHub when you choose to submit an issue through an enabled GitHub issue-reporting integration;
  • to your workspace owners or administrators, according to their access and responsibilities;
  • when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service; or
  • as part of a merger, financing, acquisition, or transfer of business assets, subject to appropriate safeguards.

5. Data retention

We retain information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Workspace owners can configure screenshot and video retention to 1, 7, 14, or 30 days. Other test records and artifacts may remain until they are deleted, the workspace is closed, or they are no longer required. Security logs and backups may be retained for a limited additional period.

6. Azure hosting, compliance, and data security

Azure hosting

The Testgrity cloud service is hosted on Microsoft Azure. Our primary application resources are currently configured in the Australia East Azure region. Microsoft Azure provides the underlying cloud infrastructure and platform security used to operate the Service.

Technical safeguards

We use technical and organisational safeguards designed to protect information against unauthorised access, loss, misuse, alteration, or disclosure. These safeguards include encryption in transit and at rest, secure authentication, access controls, workspace-level data separation, controlled access to test artifacts, service monitoring, and retention controls.

Azure compliance and shared responsibility

Microsoft maintains independent certifications, attestations, and audit reports for Azure services that are within the scope of its compliance programs. These programs include standards and frameworks such as ISO/IEC 27001, ISO/IEC 27018, ISO/IEC 27701, SOC, and Australia IRAP, although the services covered differ between programs. Current details and audit scope are available in the Microsoft Azure compliance documentation.

Azure's compliance certifications apply to Microsoft's in-scope cloud infrastructure and services; they do not automatically certify Testgrity or any customer workload. Under the cloud shared-responsibility model, Microsoft is responsible for the security of the underlying Azure platform. Testgrity remains responsible for its application code, configuration, access controls, data handling, and operational processes. Customers remain responsible for the data they place in the Service, their users, connected environments, and workspace settings.

Test artifacts may contain sensitive tenant data. You are responsible for choosing appropriate capture and retention settings, limiting access to your workspace, and avoiding unnecessary personal or confidential information in test data. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

Data breaches

If we become aware of a data breach, we will assess it and take reasonable steps to contain and address it. We will notify affected organisations, individuals, and regulators where required by applicable law.

7. International data transfers

Although Testgrity's primary application resources are configured in Australia East, Microsoft and optional third-party services may process some information outside Australia, including in the United States and other countries where those providers operate. The countries involved depend on the services and optional integrations your organisation enables. Where required, we use appropriate contractual or other safeguards for international transfers.

8. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, or to object to certain processing. You may also have the right to complain to a privacy regulator.

You can update certain account and workspace information within the Service. For other requests, contact your Testgrity workspace owner or use the Testgrity support contact provided to your organisation. We may need to verify your identity before completing a request.

9. Third-party services

The Service may link to or interoperate with third-party services. Their handling of personal information is governed by their own terms and privacy policies. Your organisation controls which environments and optional integrations it connects to Testgrity.

10. Changes to this policy

We may update this Privacy Policy as the Service or applicable laws change. We will post the revised policy here and update the date at the top. We will provide additional notice when required by law.

11. Contact us

For privacy questions, access or correction requests, or complaints, contact:

DYNAMICSDUOABN 93 257 340 580contact@dynamicsduo.com.au

Please submit privacy complaints in writing and include enough information for us to understand your concern and the outcome you are seeking. We will acknowledge your complaint and aim to respond within 30 calendar days. We may contact you for further information and may need to verify your identity.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner. If your organisation manages your Testgrity workspace, you may also contact its workspace owner or administrator.