Legal
Sayar Danışmanlık — Privacy Policy for Site Migrate
Last updated: 27 August 2026
Who we are
Site Migrate is a product of S2Stools, a brand of Sayar Danışmanlık.
Sayar Danışmanlık is the company behind that brand and the controller of the personal data in this notice — other than your SharePoint content, which we move on your instructions, as Our role explains below. Its address is Gümüşsuyu Mh. Kazancı Yokuşu Sk. No:11/2 Ada apt., 34437 Beyoğlu, İstanbul, Türkiye, and its contact address for anything here is contact@s2stools.com.
Our role
Your SharePoint content: we act on your instructions. You tell Site Migrate which site to copy and where to copy it. We move that content from your source to your target and we do not keep a copy.
Your account and usage records: we decide how they are handled, because we need them to run the service, bill it, and support you.
Payments: Lemon Squeezy. Purchases are processed by Lemon Squeezy as merchant of record. They collect and hold payment details under their own privacy policy. We never see or store your card details. We receive an order reference, a customer reference, the plan bought and the amount.
What we hold, and why
Your account — the object identifier Microsoft Entra ID gives us, your email address, your display name, your role in the workspace, when the account was created and when it was last used. This is what signs you in and attributes actions to a person.
Your migration setup — the source and target site addresses, the labels you give runs, and any schedules you configure.
Run records — for each migration we keep a report and a usage file. The report lists the libraries, lists, pages and files that were processed, counts, timings, and any warnings raised.
Warnings name people and the things they touched. When a user account on the source site has no matching account on the target, the warning that records it identifies the account that could not be matched — an email address, a SharePoint login name, or a display name. Warnings also name the files, list items and permission entries a step could not complete, and can carry the text of an error returned by SharePoint. This is how an administrator knows what to repair.
Usage and billing records — measured data volume, compute time and item counts per billing period, the allowance those consume, purchases and refunds, and an audit trail of changes to your plan.
Diagnostics — application logs. These record what the service was doing: site addresses, list names and item counts. Some entries also name a person. A failed step reports the error it received, and those errors can contain a login or an email address; entries recording who started a purchase, or who carried out a workspace erasure, name that person by design.
If you contact us through this website
If you use the contact form, we receive your name, email address, any company name you give, and your message. We use them to answer you. They are sent to our mailbox and are not stored in Site Migrate or in any database. We keep the correspondence for as long as we need it to deal with your enquiry and our records of it.
On what legal basis
Your account, migration setup, run records and usage history — because we need them to provide the service you have asked us to provide, and to bill it. That is performance of our contract with you.
Purchase and refund records — because tax and accounting law requires us to keep them.
What you send us through the contact form — because you asked us to reply, and because we have a legitimate interest in answering enquiries about the service. If your enquiry is about buying it, it is also a step taken at your request before a contract.
Diagnostics — because we have a legitimate interest in keeping the service working, diagnosing failures and protecting it from misuse. We keep them for 30 days and no longer.
Your SharePoint content — we do not process it on our own basis at all. We move it on your instruction, as your processor; the basis for moving it is yours, not ours, which is why starting a migration is your confirmation that you are entitled to move the content you have pointed us at.
What we do not keep
We do not retain a copy of your site content. Files, versions, list items, attachments and pages move directly from your source SharePoint to your target SharePoint. They exist in memory only for as long as the transfer takes — they are never written to our disks and never staged in our storage.
What remains after a run is the report, the usage record and the resume state: names, counts and timings, not documents.
Where it is held
All the data we hold is in the European Union — data and compute both in Azure West Europe.
Who else touches it
- Microsoft — hosting, storage, database and diagnostics (Azure), and the mailbox that receives what you send us through the contact form.
- Lemon Squeezy — payments, as merchant of record.
- Cloudflare — serves the public website, and runs the contact form's endpoint and its anti-spam check, so it processes what you type into that form and the address you send it from. It has no access to your migrations or to anything in Site Migrate.
How long we keep it
- Diagnostic logs: 30 days.
- Run records, account records and usage history: for the life of your workspace. Your migration history is part of what the service is for, so we keep it while your account exists rather than expiring it on a timer.
- Contact form enquiries: as long as we need them. They live in our mailbox as ordinary correspondence, not in the service, so they are kept and cleared like any other email rather than on the schedules above.
- When your workspace closes: tell us, and we erase what we hold for it. We do this on request rather than on a timer, and we confirm to you when it is done — see Your rights below.
Your rights
If you are in the EU or UK you may ask for a copy of your personal data, ask us to correct it, ask us to erase it, ask us to restrict or stop certain processing, and ask for it in a portable form. Email contact@s2stools.com. We act on your request and tell you what we did within one month.
Erasure is carried out by us on request rather than through a self-service control in the product. That describes how it works today; it is not a limit on the right. It covers the run records, account records and usage history we hold for you.
Two things survive an erasure.
The first is deliberate. We keep a short accountability record: the workspace identifier, the date, who carried the erasure out, and counts of how many records were removed. It holds nothing that describes you. We keep it because data protection law requires us to be able to show what we did with personal data, and an erasure we cannot evidence is one we cannot demonstrate we performed.
The second is a limitation we would rather state than gloss. Our application logs are not separated by customer, and there is no query that removes one customer's entries from them. An erasure does not reach them. What bounds them instead is the retention period above: every log entry is deleted 30 days after it was written, whether or not anyone asks.
You also have the right to complain to the data protection supervisory authority of the EU or UK country where you live, where you work, or where you think the problem occurred.
Keeping it safe
Sign-in is through Microsoft Entra ID — we never see your Microsoft password. Each workspace's data is separated from every other workspace's. Credentials and secrets are held in Azure Key Vault. Traffic is encrypted in transit.
Changes
We will post changes here and update the date above.