Last updated: 21 July 2026

Data Protection · Microsoft 365

Scoped access, not a copy of your mailbox.

How MailBroom for Business connects to Microsoft 365 mailboxes, what it can and can't see, and how that fits an organisation's GDPR obligations.

How access works

Scoped, revocable, per-user

No password ever seen

Sign-in goes through Microsoft Entra ID — the same login already used for Microsoft 365. MailBroom receives only a scoped Graph API access token, never the password itself.

Revocable at any time

An admin can revoke that access instantly from the organisation's own Microsoft admin settings — no need to contact MailBroom to cut off access.

Retention obligations

Works within holds, not around them

Smart Sweep and Storage Cleanup respect existing Exchange Online retention policies and litigation/in-place holds — items covered by a hold stay preserved regardless of what a user clears elsewhere in their own mailbox. This is the same requirement that applies to any bulk mailbox action, and matters specifically under GDPR where a retention or legal hold obligation overrides a general right to deletion.

Frequently asked questions

Does MailBroom store my Microsoft 365 password?

No. Sign-in happens via Microsoft Entra ID — the same login your company already uses for Microsoft 365. MailBroom never sees or stores the password itself; it only ever receives a scoped, revocable Microsoft Graph access token, used to read and act on the mailbox on the signed-in user's behalf.

Can an admin revoke MailBroom's access to company mailboxes?

Yes, at any time, via the organisation's own Microsoft admin settings — the same place any other Entra ID-connected app's access is managed. Revoking access there immediately invalidates MailBroom's Graph API token for that user.

Does mailbox cleanup respect existing data retention obligations under GDPR?

MailBroom's Smart Sweep and Storage Cleanup work within existing Exchange Online retention policies and legal/litigation holds, not around them — held or retained items stay preserved regardless of what a user clears elsewhere in their own mailbox. This matters for GDPR specifically where retention is a legal obligation (e.g. a litigation hold), not just a company preference.

What's the lawful basis for an MSP or company using MailBroom on client or employee mailboxes?

Each employee (or, for an MSP, each client's own employees) signs in with their own Microsoft account and acts on their own mailbox directly — the company or MSP running MailBroom isn't accessing mailbox contents on their behalf without their own authentication in the loop. The underlying data is the organisation's own business correspondence, held for its own operational purposes, which is the same basis the organisation already relies on for holding that mail in Microsoft 365 at all.

Does MailBroom retain a copy of mailbox content on its own servers?

MailBroom for Business connects to a mailbox via the Microsoft Graph API to act on it directly — it does not maintain its own separate copy of mailbox content as a matter of course. Some usage data (e.g. counts of storage freed, emails deleted) is retained at the account level to power the ROI/CO₂ dashboards; see the Privacy Policy for the full breakdown of exactly what's stored.

Read the full Privacy Policy.

Every data category MailBroom for Business stores, and exactly why — no summary, the actual policy.