Skip to content
discover HiloIntelligence

Privacy Policy · HiloArchive

Last updated: 2026-08-20

The short version

HiloArchive is a service of Hilo Tech Inc. that archives dormant SharePoint files to archive storage hosted by HiloTech in Canada. Your files are kept in a container dedicated to your organization, on Canadian cloud infrastructure replicated across two datacenters (GRS). No file is removed from SharePoint until a copy has been verified byte for byte (SHA-256 checksum), and a clickable shortcut is left in its place. Archiving to your organization's own Azure storage (dedicated tier) remains available.

What the application can do in your Microsoft 365 environment

The HiloArchive application uses permissions granted explicitly by your global administrator, revocable at any time in Microsoft Entra ID:

  • Read SharePoint sites (Sites.Read.All): inventory libraries and identify dormant files from their metadata (name, path, size, dates).
  • Read and write site content (Sites.ReadWrite.All): copy files being archived to the archive storage, place the HTML shortcut where each file was, and restore files on request.
  • Full control of site collections (Sites.FullControl.All): used solely to remove already-archived, verified items from the site recycle bin so your quota frees immediately. Without this permission everything else still works, and quota frees when the recycle bin expires on its own.
  • Azure Service Management (delegated permission "user_impersonation"): used only if your organization chooses the dedicated tier (archives in your own Azure subscription), during the initial one-click setup, to create the storage account in your subscription. The standard Hilo-hosted offering does not use this permission.

The exact permission list is always visible on the Microsoft consent screen and, after consent, in Microsoft Entra ID under "Enterprise applications".

What the service keeps

The HiloArchive portal keeps the minimum needed to operate the service:

  • Portal accounts (name, work email, role) for the people your organization authorizes to access it.
  • The connection configuration for Microsoft 365 and the archive storage; secrets and private keys are encrypted at rest and never returned by the API.
  • The archive index: names, paths, sizes, dates, and checksums of archived files (the catalog, never the file content).
  • Archiving job history and a timestamped audit log of administrative actions.

Each client organization has its own database, isolated from every other client's.

Where your files live

Standard offering: archived copies reside in a storage account operated by HiloTech on Microsoft Azure infrastructure, in datacenters located in Canada, with geo-redundant replication (GRS). Each client organization has its own container, isolated from other clients', and application access uses a credential scoped to that single container. Dedicated tier: copies reside in a storage account owned by your organization, in your Azure subscription and the region of your choice; you then keep ownership and control at all times.

Security

  • All communications are encrypted (TLS); connection secrets are encrypted at rest.
  • No deletion without verification: a file is removed from SharePoint only after its copy has been fully re-read from the archive storage and its SHA-256 checksum confirmed.
  • A nightly integrity check continuously re-verifies a rotating sample of archived files.
  • Per-organization isolation: a separate database for each client.
  • An audit log of actions, with operational alerts sent to the contacts you designate.
  • Storage isolation: one dedicated container per client organization and an access credential scoped to that single container; soft delete (30 days) and versioning enabled on the hosted storage.

Retention and deletion

Portal data is kept for the duration of the service. When the contract ends, it is deleted on written request within 30 days, subject to legal retention obligations. For files archived on Hilo-hosted storage: at the end of the service they are restored to your SharePoint or handed over in a readable format, then deleted from our storage. On the dedicated tier, your archived files sit in your own Azure storage and do not depend on us.

Third parties

The service relies on Microsoft APIs (Microsoft Graph, SharePoint) and, for the standard offering, on Microsoft Azure infrastructure in Canada on which HiloTech operates the archive storage. No data is sold or passed to other third parties, and the portal contains no advertising and no third-party trackers.

Your rights

The rights of access, rectification, and deletion under Quebec's Law 25 and the GDPR, along with the contact details of our Privacy Officer, are described in the HiloTech privacy policy, which applies alongside this policy.

Contact

Questions about this policy or about how HiloArchive processes data: privacy@hilotech.ca.

Questions about your organization's archiving choices (which sites, which rules): your administrator.

Changes

We will update this page and the "Last updated" date when this policy changes; material changes will be noted in the portal's release notes.