Privacy Policy
Effective date: October 3, 2026
1. Who we are and scope
Liquid Trinity Productions LLC, a California limited liability company, does business as Liquid Trinity Technologies ("Liquid Trinity Technologies", "we", "us"). We are based in Santa Monica, California, USA.
This policy covers every product we offer and every website we run: liquidtrinitytechnologies.com, ddlexpander.com, and addin.ddlexpander.com, where the DDL Expander add-in and its sign-up and setup pages are served. Our current product is DDL Expander, an add-in for Microsoft Outlook. Section 15 describes each product in plain language. When we launch another product, we will add a section for it.
2. Our role
Processor / service provider. When our products read information from a customer's Microsoft 365 tenant, such as the members of a distribution list, we process it on that customer's behalf and under its instructions. The customer is the controller of that information.
Controller. We are the controller for account and billing information, support communications, website information, and our own diagnostic logs.
3. Information we collect
We collect only what we need to run our products. This is the full list.
Account and subscription
- Your organization's Microsoft 365 tenant ID.
- Your organization's initial
onmicrosoft.comdomain, which Microsoft assigns when an organization is created. - The billing admin's contact email address, and their Microsoft Entra object ID so we know who can manage billing.
- Stripe customer and subscription IDs, the subscription's status and dates (such as trial and billing period dates), the plan, and the number of seats.
- The date your organization's free trial was used.
Card and billing details that you enter at checkout, such as name, billing address, payment card, and tax ID, are held by Stripe, not by us. We never receive full card numbers.
Seat counting
To count how many seats are in use, we store the Microsoft Entra object ID of each person who uses a product, with the date they last used it. We keep each entry for 35 days after the person's last use. We do not store their name or email address for this purpose.
Sign-in
When someone signs in, Microsoft gives us a sign-in token. We read the tenant ID and the user's object ID from it, and the directory role identifiers that tell us whether the user can approve DDL Expander for their organization. The token also contains the user's name and sign-in email address. We use these only to recognize the person during the request, and we do not store them. The sign-up and setup pages on addin.ddlexpander.com keep sign-in state only for the life of the browser tab, in session storage. While Microsoft prepares a brand-new organization, the setup page also keeps a small marker in local storage, described in section 14.
Product data processed on your behalf
Our products read information from your Microsoft 365 tenant to do their job. For DDL Expander, this is the names of distribution lists and each member's display name, email address, and recipient type. We process this information in memory to answer a request. Member lists are held for up to 5 minutes, and the list of group names for up to 10 minutes. It is never stored in our database or written to disk. Section 15 has the details.
Support communications
If you email us, we receive your message, your email address, and anything you attach.
Website information
Our websites don't use analytics or advertising, and they don't set cookies. Our hosting provider processes standard request information, such as IP address and browser type, to deliver pages and protect the service. If you join a waitlist on ddlexpander.com, we store your email address and the time you signed up, and we send you a confirmation email.
Diagnostic logs
Our service records diagnostic logs to keep it running and to fix problems. Logs contain request times and results, your organization's tenant ID, Stripe object IDs, and error types and codes. They do not contain distribution list names or email addresses. Our logging provider masks client IP addresses. On access-denied and billing-admin events, a log entry may include a Microsoft Entra object ID, which is a random identifier and not a name or an email address. Logs are kept for 90 days.
4. How we use information
- To provide our products: signing users in, confirming that the organization has an active subscription, and doing what the user asks.
- To set up a product for an organization after an administrator approves it.
- To bill subscriptions, calculate tax, and manage seats.
- To send service, trial, and billing notices, and to answer support and privacy requests.
- To keep our services secure and reliable, and to diagnose problems.
- To notify waitlist subscribers when a plan becomes available.
- To meet legal, tax, and accounting obligations.
We don't use information for advertising, and we don't build profiles of individuals. We do not make decisions about individuals by automated means that have legal or similarly significant effects.
5. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases when we act as a controller:
- Contract: to provide the products your organization subscribes to and to bill for them.
- Legitimate interests: to secure and improve our services, diagnose problems, answer questions, and communicate with business customers.
- Legal obligation: to keep tax and accounting records and to respond to lawful requests.
- Consent: for waitlist emails. You can withdraw consent at any time.
When we act as a processor, the customer determines the legal basis.
7. Microsoft 365 permissions
DDL Expander asks for these Microsoft permissions:
| Permission | Type | Why |
|---|---|---|
Read/write the current item (ReadWriteItem) | Outlook add-in permission | Read the To, Cc, and Bcc recipients already on the message you're writing, add the members you choose, or clear a recipient line when you ask. This happens inside Outlook; the recipients are not sent to us. The add-in does not read the subject, body, or attachments. |
openid, profile, User.Read (Microsoft Graph), and DDL Expander's access_as_user | Delegated | Sign you in to the add-in and the setup pages, and read your organization's initial domain during sign-up. |
Exchange.ManageAsApp (Office 365 Exchange Online) | Application, requires admin consent | Lets our service connect to your Exchange Online without a user, so it can read distribution lists. |
| Exchange role View-Only Recipients | Exchange role assignment | Read-only access to recipient objects in your organization. The role covers all recipients, not only distribution list members. DDL Expander reads only distribution lists and their members' display name, email address, and recipient type. |
Exchange.Manage (Office 365 Exchange Online) | Delegated, used once by an administrator | During setup, your administrator's Exchange sign-in is used once to register DDL Expander with Exchange and assign it the View-Only Recipients role. We don't store or log that sign-in. On a brand-new Microsoft 365 organization, setup may also turn on Exchange organization customization, which Microsoft requires before any role can be assigned. Microsoft does not allow that setting to be turned off again. |
Admin consent. A Global Administrator, or an administrator who can grant consent to applications and is also an Exchange Administrator, approves DDL Expander for the whole organization. Users can't grant the application permission themselves.
How to revoke access.
- Remove the add-in: Microsoft 365 admin center → Settings → Integrated apps → DDL Expander → Remove app.
- Remove the enterprise application: Microsoft Entra admin center → Enterprise applications → the DDL Expander application → Delete.
- Optionally, remove the Exchange role assignment and service principal in Exchange Online PowerShell (
Remove-ManagementRoleAssignment,Remove-ServicePrincipal).
Removing the add-in does not cancel a subscription. See our Terms of Service.
8. Data retention
| Information | How long we keep it |
|---|---|
| Tenant ID, initial domain, billing admin contact, Stripe IDs, and subscription records | While the subscription is active. Deleted or anonymized within 90 days after the subscription ends. Deleted within 30 days of a verified request (section 11). |
| Entra object IDs used for seat counting | 35 days after the person's last use. |
| Distribution list members and lists | Not stored. Held in memory for up to 5 minutes (10 minutes for the list of group names), as described in section 15. |
| Diagnostic logs | 90 days, then deleted automatically. |
| Database backups | Up to 7 days. Backups are encrypted. |
| Waitlist emails | Until the waitlist closes. You can request removal at any time. |
| Billing and tax records, held by Stripe | 7 years, as required by tax and accounting law. |
| Sign-in state in your browser (sign-up and setup pages) | Only for the browser tab. It is cleared when you close the tab. |
| Setup marker in your browser's local storage (tenant ID and the time setup started) | Removed when setup finishes, or when the 2-hour wait for Microsoft ends. If you abandon setup, it stays until you clear your browser's site data or finish setup later. |
| Organizations that sign up but never subscribe | Deleted after 90 days without activity. |
After your data is deleted, we keep your organization's tenant ID and the date its free trial was used, to prevent repeat free trials. This is true whether the deletion was automatic or on request. We also keep a deletion record, which holds only the tenant ID, the date, and counts of what was deleted, as proof that a deletion was carried out.
Deleted data can remain in our encrypted backups for up to 7 days before it is overwritten.
9. Security
- Traffic to our websites and service uses HTTPS (TLS 1.2 or later).
- Our database and storage are encrypted at rest by Microsoft Azure.
- Keys and certificates are kept in Azure Key Vault.
- Our service connects to your Exchange Online with a certificate, not a password, and with read-only recipient access.
- Every request to our service must carry a valid Microsoft sign-in token, and each organization can reach only its own data.
- Access to our systems is limited to our personnel who need it.
No system is perfectly secure. If you find a vulnerability, please report it (section 17).
10. International transfers
We store and process information in the United States. If you are outside the United States, your information is transferred to the United States. For transfers from the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum), including those in our Data Processing Addendum and in our subprocessors' data protection terms.
11. Your rights
EEA and UK (GDPR and UK GDPR)
You can ask to access, correct, delete, or export your personal information, to restrict or object to our processing, and to withdraw consent. You can also complain to your local data protection authority.
California (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request access to the specific personal information we hold about you; to request that we delete it or correct it; and to be free from discrimination for exercising these rights. We will not deny you our products, charge you a different price, or provide a different level of service because you exercised a right. You may use an authorized agent to make a request on your behalf, and we may ask for proof of the agent's authority.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA, so there is nothing for you to limit.
In the past 12 months we have collected the following categories of personal information, from our customers and from Microsoft sign-in, for the business purposes described in section 4, and disclosed them only to the service providers listed in section 6:
- Identifiers: Microsoft Entra object IDs, tenant IDs, and the billing admin's email address.
- Commercial information: subscription status, plan, seat count, and dates.
- Internet or other electronic network activity: diagnostic logs and the date a person last used a product.
- Professional or employment-related information: the name of the organization (its tenant ID and initial domain).
- Information in the course of support: the contents of emails that you send to us.
We keep each category only for the periods in section 8. Our websites do not track visitors across other sites, so we do not respond differently to a "Do Not Track" or Global Privacy Control signal.
How to make a request
Email support@liquidtrinitytechnologies.com with the subject "Privacy request". Tell us which product and organization your request is about. We will verify your identity, usually by confirming control of the email address or Microsoft 365 account involved. For organization-wide requests, we will ask that the request come from an administrator of the Microsoft 365 tenant. We respond within the time required by law, such as one month under the GDPR and 45 days under the CCPA.
Deletion requests
A tenant administrator or billing admin of your organization can ask us to delete the organization's account data at any time by emailing support@liquidtrinitytechnologies.com. We complete the deletion within 30 days after verifying the requester. Deleting account data ends access to the product for that organization. We keep only the organization's tenant ID and the date its free trial was used (section 8).
If your organization uses our products: for information that we process on your organization's behalf, please contact your organization's administrator. We will help them respond.
12. Data Processing Addendum
Our Data Processing Addendum sets out how we process personal data for our customers. It incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
13. Children
Our products and websites are for businesses and are not directed to anyone under 16. We do not knowingly collect information from children.
15. Product details: DDL Expander
DDL Expander is an add-in for Microsoft Outlook (Windows and Outlook on the web). It shows the individual members of Exchange Online dynamic distribution groups so you can add them to a message.
What it reads from Exchange Online
The list of dynamic distribution groups in your organization, and, when you expand one, each member's display name, email address, and recipient type. It reads these with read-only access, using the permissions in section 7.
What it returns
The members are shown to the user who asked, inside Outlook. If the user chooses, the add-in adds them to the message they're writing. It checks the message's existing recipients inside Outlook to avoid duplicates; those recipients are not sent to us.
What it stores
- Your organization's tenant ID and initial domain, the billing admin's contact email and object ID, and Stripe customer and subscription IDs, status, and dates.
- The Entra object ID of each user and the date they last used the product, for seat counting. We keep each entry for 35 days after the last use.
- The date your organization's free trial was used.
- Diagnostic logs, kept for 90 days. They contain request times and results, tenant IDs, and error types, but no distribution list names or email addresses. On access-denied and billing-admin events they may include a Microsoft Entra object ID, which is a random identifier and not a name or an email address.
What it doesn't store
- Distribution list members. They are never written to our database, logs, or disk. To speed up repeated lookups, results are cached in our service's memory. A cached result is no longer used after 5 minutes (10 minutes for the list of groups) and is removed from memory when it is replaced, swept on a later request, or the service restarts.
- User names and email addresses. We read them from the sign-in token to recognize the person during a request, but we don't store them.
- Mail content. We don't read or store the subject, body, or attachments of your messages.
- Passwords. Microsoft handles sign-in. We never see your Microsoft 365 password.
- Payment card numbers. Stripe holds them.
16. Changes to this policy
When we change this policy, we update the date at the top. If a change is material, we will also notify the billing administrators of affected customers by email before it takes effect.
17. Contact
Liquid Trinity Productions LLC, doing business as Liquid Trinity Technologies
Santa Monica, California, USA
support@liquidtrinitytechnologies.com
For help with a product, see our Support page.