Legal
Privacy notice
This notice is the record of how Third Shift Group LLC handles information. It covers the public site, mail you send us, the invited portal, storefront purchases, and work we do under a written engagement.
Effective 16 September 2026
Third Shift Group LLC is a North Carolina limited liability company. We publish the marketing site at https://thirdshift.group, run the invited operations portal at portal.thirdshift.group, and sell advisory and delivery work under our own name. Questions about this notice go to info@thirdshift.group.
A signed engagement letter, statement of work, business associate agreement, or board appointment can add duties we do not repeat here. Where that writing is stricter, it controls for that engagement. The terms of use cover browsing, acceptable use, and how these pages sit next to a contract.
Contents
- What this notice covers
- The public marketing site
- Email, forms, and the first meeting
- The invited portal
- Storefront purchases
- Work inside a client's tenant
- Board appointments
- Categories we handle
- How we use information
- Who we share it with
- How long we keep it
- Security
- Sensitive and regulated material
- Your choices and rights
- Children
- Where processing happens
- Changes
- How to reach us
What this notice covers
It applies when you load pages on https://thirdshift.group, open a mail draft from the contact page, write to info@thirdshift.group, attend a conversation we schedule, sign in at portal.thirdshift.group after we create an account, buy a subscription through the marketplace, or hire us for the work described on services and how we work.
It does not make us the operator of your Microsoft tenant, your help desk, or the dashboard that runs on your Azure subscription. Those systems stay on infrastructure you control. Vendor privacy statements (Microsoft, and any distributor or publisher behind a license) apply to products they supply. We do not republish those statements.
Public pages, llms.txt, and the sitemap are meant to be read by people and by crawlers. Publishing them is not a collection of your private data.
The public marketing site
thirdshift.group is a static site on Microsoft Azure Static Web Apps. It does not create visitor accounts. It does not set a cookie of our own. It does not load an advertising pixel, a tag manager, or a product-analytics script. The content-security policy on the host is written so the pages cannot call out to a tracker we did not put there.
Azure may still write hosting logs: time, path, status code, referring host, and a network address. Those logs exist so the host can operate, debug, and absorb abuse. We do not use them to build a marketing profile, and we do not sell them.
The site does not watch “do not track” or global privacy-control signals because there is no advertising or cross-context sharing on this host to turn off. The default is already off.
Email, forms, and the first meeting
The form on the contact page never posts a record to our servers. Your browser opens a draft in your own mail client, addressed to us, with the fields you typed. Until you send that message, we have nothing from the form.
If you send the message — or write us directly — we receive whatever you included: name, address you send from, company, a short status of AI use at your company, and the body. We keep that thread so we can reply, schedule the first conversation, and avoid asking you the same questions twice. There is no mailing list and no drip sequence. We do not add you to a newsletter because we do not run one.
Calendar holds, video-meeting links, and notes we take in a working session are kept as business records of that conversation. We do not record audio or video unless we say so before the session starts and you agree. If a session is recorded, the file is treated as correspondence, not as marketing content.
If you send a résumé or a capability statement, we treat it as an application or a vendor introduction and keep it only as long as that discussion is live, unless a longer hold is required by law.
The invited portal
The portal at portal.thirdshift.group is a separate host. Sign-in is Microsoft Entra ID only. There is no password stored by us and no public registration. An administrator at Third Shift must create an active user row before a Microsoft identity can see any data. A random work account cannot open a login.
Microsoft’s identity service sets the cookies and tokens needed to keep that session alive. Those cookies live on the portal host, not on the marketing site. Microsoft’s own notices apply to the sign-in event itself.
Once you are in, the portal holds the operating record of an engagement: organization and contact names, engagement status, tickets and comments, versions of an AI Use Policy, findings and inventories we produced, files you or we attach, billing references (not a card vault), and an audit trail of who changed a row. Staff see what they need to run the work. Invited clients see their own organization.
The portal database, file store, and application logs sit in Azure resources we operate. Azure keeps recovery copies of the database for a limited window. Files marked deleted can remain in a recycle period before they are gone. Application Insights and related logs record requests, failures, and security events so we can keep the host up and investigate abuse. That is operations, not advertising.
If someone leaves your company, tell us. We disable the user row. We do not watch your directory for joiners and leavers unless that watch is scoped as a service.
Storefront purchases
Azure, security, and Microsoft 365 subscriptions can be bought through the marketplace. Third Shift is the reseller you buy from. A distributor sits behind that purchase and sells to partners, not to you. The publisher of the license (usually Microsoft) still governs the product itself.
To place or provision an order we need business facts: legal name, domain, tenant identifiers, admin contacts, seat counts, and the skus you chose. Those facts are shared with the publisher and the distributor so the license can land in the tenant you own. How we invoice subscriptions and our own work is published on the services page; this notice does not change that model.
We do not take a card number on thirdshift.group. Payment details you give a vendor checkout, a bank, or an accounting link are handled by that provider. We retain the invoice, the sku, and enough of the payment history to answer a billing question and to feed the monthly license report the watch produces.
Work inside a client's tenant
Advisory and delivery work is done against systems you already run. The base dashboard is deployed in your own Microsoft cloud account, on your subscription, and you retain administrative control. If the engagement ends, that platform and its data stay with you. That rule is also on about and in the FAQ; it is a fact of the architecture, not a slogan.
To do the work we may be granted roles in Azure, Microsoft 365, or other systems you name in writing. We use that access to inventory, assess, design, remediate, connect, and report. We do not take over the help desk, device fleet, backups, or day-to-day administration of your systems. Microsoft 365 listings spell out the same boundary.
Production datasets are meant to stay in the tenant you own. What comes back into our portal or mail is the working product of the engagement: notes, inventories, gap lists, policy drafts, screenshots you asked us to keep, and reports. We do not copy a production warehouse into our subscription as a convenience. If a copy is required to finish a scoped task, we say so, limit it, and delete it when the task is done unless you ask us to keep it as a deliverable.
An assessment of shadow AI will often include staff names as tool owners, and it may describe data classes those tools can touch. That inventory is confidential to the engagement. It is not a public case study.
Board appointments
A technology-director seat is a personal appointment of the principal, paid as a board fee to the individual, never combined with Third Shift services at the same company. Information you give the director in that role is handled under the company’s board rules, counsel’s instructions, and any directors-and-officers arrangement — not under a Third Shift services file. See board seats.
Categories we handle
- Identity and contact: name, work email, title, phone if you give one, Microsoft object id for a portal user.
- Organization: legal name, sector, headcount band, website, Microsoft cloud account id, storefront customer references.
- Correspondence: mail, meeting notes, tickets, attachments.
- Engagement work product: policies, inventories, findings, connection decisions, reports.
- Commercial: quotes, invoices, sku and seat history, renewal dates.
- Technical: hosting logs, portal request logs, error traces, audit rows.
- Public site use: pages requested and the network facts Azure logs. No account. No cookie we set.
We do not collect government id numbers, payment-card primary account numbers, precise geolocation, biometric templates, or browsing profiles on the public site. We do not buy lists. We do not run consumer credit checks.
How we use information
- Reply, schedule, and run the first conversation and any later engagement.
- Create and version the AI Use Policy and the written assessment you own.
- Operate the portal, including access control and an audit trail.
- Provision and report on subscriptions you buy through us.
- Invoice, collect, and keep tax and accounting records.
- Defend a claim, meet a legal duty, or keep the hosts safe from abuse.
- Improve how we deliver the same method — in notes and playbooks, not by selling a dossier.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not put client files into a public model so that model can train. If staff use an internal drafting aid, client material stays under our instruction and is not offered as training data to a public service.
We do not take automated decisions that produce legal or similarly significant effects about a person. Ranking a governance gap inside a setup is professional judgment, not consumer scoring.
Who we share it with
We share information only as needed to do the work you asked for, or as the law requires:
- Microsoft, for Azure hosting, Entra sign-in, mail, and any license we provision.
- The distributor and publisher behind a storefront purchase, so the sku can be fulfilled.
- Your own staff, MSP, or counsel when you ask us to work with them.
- Insurers, accountants, and lawyers who support our practice, under their duties of confidence.
- A successor, if the company is sold or combined, and only for the same kinds of use.
- A court, regulator, or law-enforcement body when we are required to produce records.
We do not list a public subprocessor catalog that pretends to be complete on every day of the year. The classes above are the classes. If a new class appears, this notice will say so when we next revise it.
How long we keep it
Mail about a conversation that does not become a client is kept long enough to finish that thread and to show, if asked, that we answered. Engagement files are kept for the life of the work and then for a period we need for professional, tax, and legal defense — typically years, not weeks. Portal rows follow the engagement; we can export or disable them on request. Hosting logs rotate on Azure’s default windows. Recovery copies expire when their window closes.
When we delete a record, residual copies can remain in backups until those backups age out. We do not resurrect a deleted file to use it again.
Security
The portal requires Entra sign-in and an active user row. Database access is parameterized and granted to the application identity, not to a shared password in the repo. Files sit in private storage. The marketing host sends security headers, including a content-security policy. We do not claim a named certification (SOC, ISO, or similar) on this page, because we have not published one.
No host is immune. If we confirm a breach that requires notice under applicable law, we will notify the people and the regulators that law names, and we will say what we know at the time we are required to speak.
You are responsible for the accounts and roles you grant us in your tenant, and for telling us when those accounts should end.
Sensitive and regulated material
We work with firms that hold client files, patient records, claim files, or donor data. We are not your compliance officer, your counsel, or your attest firm. Industry pages and the FAQ say that in writing. A policy we draft is an internal rule for your team to own, not legal advice.
We do not become a HIPAA business associate, a qualified professional, or a similar statutory role unless a separate writing says so. Until that writing exists, do not send us a production extract of regulated records. Describe the class of data, not the record.
If regulated material appears in a screenshot, a ticket, or a mailbox by accident, tell us. We will treat it as confidential, limit access, and delete or return it once the immediate task no longer needs it.
Your choices and rights
You can write to us, refuse a meeting, decline a portal invite, or ask us to disable an account. You can buy licenses through another partner; the storefront is not a lock-in. You can take the written assessment we produce to another firm.
Depending on where you live, United States state law may also give you the right to know what we hold, to receive a copy, to correct it, to delete it, to appeal a refusal, and to use an authorized agent. We will not deny services, charge a different price, or reduce quality because you exercised a privacy right, except as the law allows for a request that is truly excessive.
Some records we must keep (invoices, engagement letters, audit rows required to show who changed a policy). Some records are yours already, because they live in your tenant. We will say which is which when you ask.
We honor a verifiable request from the person, the company administrator, or an agent with proof of authority. We may need to confirm the email or the tenant relationship before we act.
Children
The site, the portal, and the work are for businesses and their adult staff. We do not knowingly collect information from children under 16. If you believe a child sent us personal information, write to info@thirdshift.group and we will delete it.
Where processing happens
We are based in North Carolina, US. Hosts, mail, and the portal run on Microsoft Azure and Microsoft 365 in the United States. If you contact us from elsewhere, you send information to the United States. We do not operate an EU or UK representative, because we have not established that kind of establishment. Service areas named on this site (North Carolina and South Carolina) are places we work, not extra offices and not a claim that a page is a local shop.
Changes
We will change this notice when the facts change — a new host, a new class of vendor, a measurement tag we do not have today. The date at the top is the date the posted text became current. Material changes belong on this page; we do not hide them in a changelog no one reads. Continued use of the public site after a posted change means the new notice applies to that use. Engagements already under contract keep the duties in their letter unless both sides agree otherwise.
How to reach us
Privacy requests: info@thirdshift.group. Name the company, the email you used, and what you want us to do. We reply from the same domain.
You may also complain to a state attorney general or another authority that has jurisdiction over us or over you. We would rather fix the record first.
Related pages: terms of use, contact, client login, marketplace.