Skip to content
Jadex Strategic Group logo featuring a teal hexagon cube symbol with modern blue-green branding for technology, cybersecurity, and compliance services
  • Home
  • AssessmentsExpand
    • AI & Data Governance
    • Compliance & Regulatory
    • Microsoft 365 Optimization
    • Security & Protection
  • PlatformsExpand
    • Praesidium
    • AuditAble
    • Academy
    • Cyber Watchtower
    • View All Platforms
  • Training
  • CapabilitiesExpand
    • CybersecurityExpand
      • Identity Security
      • Device Security
      • Data Security
      • Security Operations
    • Compliance & GRC
    • Microsoft 365 Transformation
    • Documentation & Audit Support
    • Information & Content Management
    • Communications & Collaboration
    • Business Communications
  • IndustriesExpand
    • Defense Industrial Base
    • Manufacturing
    • Financial Services
    • Government & Public Sector
    • Healthcare
    • Education
  • ResourcesExpand
    • Assessments
    • Case Studies
    • Guides & Playbooks
    • Insights
    • Partnerships & Referrals
    • Training & Enablement
  • CompanyExpand
    • Leadership
Facebook Instagram Linkedin YouTube
Jadex Strategic Group logo featuring a teal hexagon cube symbol with modern blue-green branding for technology, cybersecurity, and compliance services
Legal · Jadex Strategic Group

Meetings & Events Privacy and Security Policy

A guide for organizers and participants of online meetings, webinars, and town halls hosted by Jadex Strategic Group within Microsoft Teams.

Last Updated: June 30, 2026 | Effective: June 30, 2026 | Applies To: Microsoft Teams — Commercial, GCC, GCC High
In this Document
  1. Introduction & Scope
  2. Definitions
  3. Roles: Controller, Processor, Participant
  4. Personal Data We Collect
  5. How We Use Personal Data
  6. Recording, Transcription & AI Notice
  7. Data Retention Schedule
  8. Data Sharing & Sub-Processors
  9. Environments & Data Boundaries
  10. Security Measures
  11. CUI, ITAR & Export Control Restrictions
  12. Your Rights
  13. Best Practices for Organizers
  14. Best Practices for Participants
  15. Incident Reporting
  16. Governing Law & Contact
  17. Changes to This Policy
Plain-Language Summary

When you join a Microsoft Teams meeting, webinar, or town hall hosted by Jadex Strategic Group, we collect limited personal data needed to run the session — such as your name, email, and any content you share. Meetings may be recorded, transcribed, or summarized using AI (including Microsoft 365 Copilot). We will tell you when this happens. Certain conversations involving Controlled Unclassified Information (CUI) are hosted only inside our GCC High enclave. By joining, you agree to follow this policy and our Terms of Use.

01

Introduction & Scope

Microsoft Teams is Jadex Strategic Group’s primary unified communications platform for collaboration, live events, webinars, and town halls. Teams enables chat, calls, meetings, file sharing, and the participation of external guests such as customers, partners, vendors, subcontractors, and prospective clients.

Hosting and joining meetings and events introduces privacy, security, and regulatory obligations that must be understood and managed. This Policy explains how Jadex Strategic Group collects, uses, retains, and protects information related to meetings and events, and the responsibilities of organizers and participants.

Scope

This Policy applies to any online meeting, webinar, town hall, live event, one-to-one call, or recorded session hosted by Jadex Strategic Group within Microsoft Teams — whether in our Microsoft 365 Commercial, GCC, or GCC High environments — and to any participant who joins such a session, whether internal to Jadex or external.

This Policy is issued in addition to, and is incorporated by reference into, the Jadex Strategic Group Website Terms of Use and Website Privacy Policy.

02

Definitions

For purposes of this Policy:

  • Meeting — a scheduled or ad-hoc Teams session for two or more participants, typically internal or small-group collaboration.
  • Webinar — a Teams session with a registration workflow, structured presenter/attendee roles, and controlled interaction.
  • Town Hall — a broadcast-style Teams event supporting large audiences with limited attendee interaction.
  • Live Event — a legacy Teams broadcast format that Microsoft is transitioning to Town Halls; references in this Policy to Town Halls also apply to Live Events where still in use.
  • Organizer — the Jadex Strategic Group employee or authorized representative who schedules, hosts, or moderates a meeting or event.
  • Participant — any person who joins a meeting or event, including presenters, attendees, and guests.
  • External Participant / Guest — any participant who is not a Jadex Strategic Group employee.
  • CUI — Controlled Unclassified Information as defined by 32 C.F.R. Part 2002.
  • GCC / GCC High — Microsoft 365 Government Community Cloud environments designed for U.S. government and defense industrial base workloads.
  • AI Features — Microsoft 365 Copilot, Teams Premium intelligent recap, live translation, meeting summaries, speaker recognition, and similar generative or analytical AI capabilities.
03

Roles: Controller, Processor & Participant

Under applicable data protection laws, the parties involved in a Jadex-hosted meeting or event have distinct roles:

Jadex Strategic Group

Acts as the data controller for personal data collected in connection with meetings and events it organizes and hosts. Jadex determines the purposes and means of processing.

Microsoft Corporation

Acts as a data processor and provider of the Microsoft Teams service, processing personal data on Jadex’s behalf under the terms of the Microsoft Products and Services Data Protection Addendum (DPA).

Participants

Are data subjects whose personal data may be collected during a meeting or event, and are responsible for the content they contribute (chat messages, shared files, spoken statements, video, and screen shares).

Client Engagements

When Jadex Strategic Group hosts meetings on behalf of a client (for example, as part of a managed service, assessment, or advisory engagement), roles may differ under the applicable engagement agreement or Business Associate Agreement (BAA). The engagement contract governs in the event of a conflict.

04

Personal Data We Collect

Jadex Strategic Group, through Microsoft Teams, may collect and process the following categories of personal data in connection with meetings and events:

Identity & Profile Data

  • Name, email address, organization, job title, and profile picture.
  • Phone number, if provided or used to dial into an event.
  • Authentication identifiers (Azure AD / Entra ID object IDs, guest account IDs).

Communications Content

  • Chat messages sent before, during, or after a meeting.
  • Audio and video streams contributed during a meeting.
  • Files, images, and links shared through the meeting or chat.
  • Recordings, transcripts, translations, and AI-generated summaries where features are enabled.
  • Whiteboard content, polls, Q&A submissions, reactions, and raised-hand events.

Operational & Diagnostic Data

  • Device information, operating system, and Teams client version.
  • Network information, connection quality metrics, and performance telemetry.
  • Attendance reports, join/leave times, and engagement data (for Webinars and Town Halls).
  • Feedback, ratings, and survey responses.
05

How We Use Personal Data

Jadex Strategic Group processes personal data collected through Teams meetings and events for the following purposes:

  • Delivering the meeting or event and supporting collaboration.
  • Verifying participant identity and controlling access (lobby, authentication, guest admission).
  • Producing recordings, transcripts, and AI-generated summaries where the feature is enabled and disclosed.
  • Fulfilling client engagements and delivery obligations under signed agreements.
  • Complying with regulatory obligations, including CMMC, NIST 800-171, and export control requirements where applicable.
  • Detecting, preventing, and responding to security incidents, abuse, or policy violations.
  • Improving service quality, reliability, and user experience.
  • Responding to legal process, subpoenas, or lawful government requests.

Legal Bases (GDPR)

Where the EU General Data Protection Regulation or UK GDPR applies, Jadex Strategic Group processes personal data on the following bases: (a) performance of a contract; (b) legitimate interests in operating the business, providing services, and securing our systems; (c) compliance with a legal obligation; and (d) consent, where required (for example, participation in a recorded session).

06

Recording, Transcription & AI Notice

Meetings, webinars, and town halls hosted by Jadex Strategic Group may be recorded, transcribed, translated, and summarized using Microsoft Teams and Microsoft 365 Copilot capabilities.

Notice & Consent

When recording or transcription is active, Microsoft Teams displays a visible indicator to all participants. By remaining in the session after that indicator appears, participants acknowledge and consent to the recording, transcription, and any associated AI processing. Participants who do not wish to be recorded should leave the session or notify the organizer before the meeting begins.

Multi-State & International Consent

Michigan is a one-party consent state for recording; however, participants may join from jurisdictions requiring two-party or all-party consent (including California, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, Washington, and various international jurisdictions). Jadex organizers will announce recording at the start of any recorded session, and Teams provides on-screen and audible notifications. Participants are responsible for ensuring they are permitted to be recorded under the laws of their own jurisdiction.

AI-Generated Content

Where Microsoft 365 Copilot, Teams Premium intelligent recap, live translation, speaker recognition, or similar AI Features are enabled, the resulting outputs — including summaries, action items, chapters, and translated text — are derived from the meeting transcript and audio. These outputs:

  • Are treated with the same confidentiality and retention controls as the underlying transcript.
  • May contain inaccuracies and should not be treated as verbatim records.
  • Are not used by Microsoft or Jadex Strategic Group to train foundation models.
  • Are governed by the Microsoft Products and Services DPA and Microsoft’s published Copilot data protection commitments.
07

Data Retention Schedule

Meeting-related content is retained in accordance with the following default schedule. Client engagements, legal holds, and regulatory requirements may extend or shorten these periods.

Default Retention Periods
  • Meeting recordings & transcripts: 60 days in OneDrive/SharePoint, unless downloaded, retained under a client engagement, or subject to a legal hold.
  • Chat messages: retained per the Jadex Microsoft Purview retention policy applicable to the tenant environment.
  • Whiteboard content: retained until explicitly deleted by the organizer or a participant with edit rights.
  • Attendance reports (Webinars & Town Halls): 90 days.
  • Registration data (Webinars): 12 months, or until deletion is requested.
  • Diagnostic and telemetry data: retained per Microsoft’s published retention schedule.
  • CUI-classified session data (GCC High): retained per the applicable client engagement, CMMC, and NIST 800-171 requirements.

Participants may request deletion of specific content in accordance with Section 12 (Your Rights).

08

Data Sharing & Sub-Processors

Jadex Strategic Group does not sell personal data. We share personal data collected through meetings and events only in the following circumstances:

  • Microsoft Corporation — as the processor providing the Teams service under the Microsoft Products and Services DPA.
  • Client engagements — where a client is a party to the meeting or where sharing is required by the engagement contract.
  • Service providers — bound by written agreements limiting use of data to the services provided to Jadex.
  • Legal & regulatory — in response to lawful process, subpoena, court order, or as required to protect the rights, safety, or property of Jadex, its clients, or others.
  • Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality obligations.

A current list of material sub-processors is available upon written request to privacy@jadexstrategic.com.

09

Environments & Data Boundaries

Jadex Strategic Group operates within multiple Microsoft 365 environments and routes meeting and event workloads to the environment appropriate for the sensitivity of the conversation and the compliance obligations of the participants.

Microsoft 365 Commercial

Used for general business meetings, marketing webinars, town halls, prospect conversations, and non-regulated collaboration. Data resides in Microsoft’s commercial datacenters within the applicable geographic region.

Microsoft 365 GCC

Used where required for engagements with U.S. state, local, tribal, and federal government customers subject to CJIS, IRS 1075, or similar controls. Data resides within U.S.-sovereign Microsoft government datacenters.

Microsoft 365 GCC High (Praesidium Enclave)

Used exclusively for meetings and collaboration involving Controlled Unclassified Information (CUI), covered defense information, ITAR-controlled technical data, and workloads subject to CMMC Level 2 or NIST 800-171 requirements. Data resides in Microsoft’s sovereign GCC High infrastructure with U.S.-persons access controls.

Environment Selection Is Not Optional

Participants may not migrate a conversation containing CUI or export-controlled data from a Commercial or GCC meeting into unauthorized channels. If CUI is inadvertently introduced into a non-authorized environment, participants must notify the organizer immediately and follow the incident procedures in Section 15.

10

Security Measures

Jadex Strategic Group and Microsoft apply layered technical, administrative, and physical controls to protect the confidentiality, integrity, and availability of meeting content and participant data.

Platform Controls (Microsoft)

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Optional end-to-end encryption (E2EE) for supported one-to-one calls.
  • Microsoft-managed identity, authentication, and threat protection infrastructure.
  • Continuous monitoring, threat detection, and incident response by Microsoft’s security operations.
  • Independently audited platform controls including SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, FedRAMP High (GCC High), and DoD Impact Level 4/5 (GCC High).

Tenant Controls (Jadex Strategic Group)

  • Enforced multi-factor authentication and conditional access policies.
  • Role-based access control, least-privilege administration, and audit logging via Microsoft Purview.
  • Sensitivity labels applied to meetings, files, and Teams channels.
  • Data loss prevention (DLP) policies aligned to CUI, PII, and regulated data categories.
  • Meeting policies restricting anonymous join, guest access, recording, and external file sharing based on sensitivity.
  • Watermarking, lobby enforcement, and end-to-end encryption enabled for eligible sensitive meetings under Teams Premium.
  • Continuous configuration monitoring, compliance reporting, and evidence collection for CMMC and NIST 800-171.
Compliance Attributions

Microsoft’s platform certifications apply to the Microsoft Teams service, not automatically to Jadex Strategic Group’s or a client’s use of it. Jadex configures Teams in alignment with these frameworks, but customer-specific compliance outcomes remain the responsibility of the customer and are established through the applicable engagement agreement.

11

CUI, ITAR & Export Control Restrictions

Meetings, chats, files, screen shares, and recordings involving Controlled Unclassified Information, ITAR-controlled technical data, or EAR-controlled information are subject to additional restrictions.

Authorized Environment

Such conversations may occur only within Jadex Strategic Group’s GCC High (Praesidium) enclave and only among participants who have been verified as authorized U.S. persons (or otherwise licensed under applicable export authorizations).

Participant Obligations

  • Do not share, discuss, display, or transmit CUI, ITAR-controlled, or EAR-controlled content in Commercial or GCC meetings.
  • Do not screen-share applications, documents, or windows containing controlled markings during unauthorized sessions.
  • Do not forward, download, or re-transmit recordings, transcripts, or chat content containing controlled data outside the authorized environment.
  • Do not invite unauthorized guests, foreign persons, or unverified attendees to sessions involving controlled data.
  • Immediately report suspected spillage to incident@jadexstrategic.com.
U.S. Government End Users

The Microsoft Teams service and Jadex configurations provided within GCC High are furnished as “Commercial Items” under 48 C.F.R. § 2.101, consistent with 48 C.F.R. §§ 12.212 and 227.7202, and are subject to the U.S. Export Administration Regulations (EAR) and, where applicable, the International Traffic in Arms Regulations (ITAR).

12

Your Rights & Choices

Subject to applicable law and the requirements of any active client engagement, participants may exercise the following rights with respect to personal data collected in Jadex-hosted meetings and events:

  • Access: Request a copy of personal data Jadex holds about you.
  • Correction: Request correction of inaccurate or incomplete personal data.
  • Deletion: Request deletion of personal data, subject to legal, regulatory, and contractual retention obligations.
  • Portability: Request a copy of your personal data in a structured, commonly used format where technically feasible.
  • Objection & Restriction: Object to or request restriction of certain processing activities.
  • Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.
  • Complaint: Lodge a complaint with the supervisory authority in your jurisdiction.
How to Exercise Your Rights

Submit requests in writing to privacy@jadexstrategic.com. We will respond within the time frame required by applicable law (generally 30–45 days). We may request additional information to verify your identity before fulfilling a request.

13

Best Practices for Organizers

Organizers hosting Jadex meetings and events are expected to follow these operational practices in addition to any client-specific requirements.

Before the Meeting

  • Select the correct environment (Commercial, GCC, or GCC High) based on the sensitivity of the conversation.
  • Apply the appropriate sensitivity label to the meeting invitation to enforce encryption, watermarking, lobby, and recording controls automatically.
  • Use meeting templates provisioned for common scenarios (external prospect, client delivery, CUI collaboration).
  • Verify the identity and legitimacy of external invitees; use registration workflows for webinars.
  • Configure meeting options: restrict who can bypass the lobby, who can present, who can record, and who can enable AI features.
  • Disable anonymous join for sessions involving client or regulated data.

During the Meeting

  • Announce recording, transcription, and AI-generated summaries at the start of the session.
  • Admit participants from the lobby only after verifying identity.
  • Use the “Only me and co-organizers” presenter option for sessions with unknown or large audiences.
  • Monitor chat and screen shares for accidental disclosure of sensitive information.
  • Remove participants who violate this Policy or the Jadex Terms of Use.

After the Meeting

  • Review the recording, transcript, and AI summary for accuracy and sensitivity before sharing.
  • Apply retention or deletion actions consistent with Section 7.
  • Store any downloaded content in the correct labeled location; never on unmanaged devices.
  • Report any suspected incident or spillage to incident@jadexstrategic.com.
14

Best Practices for Participants

All participants — whether internal or external — are expected to follow these practices to protect their own privacy and the privacy of others.

  • Join meetings from a supported, patched, and secured device.
  • Use a private, quiet location; be mindful of shoulder-surfing and background audio.
  • Blur or apply a background image to avoid disclosing sensitive information visible behind you.
  • Mute your microphone when not speaking.
  • Do not screen-share windows or documents containing information you are not authorized to disclose.
  • Do not record, screenshot, or transcribe a meeting using unauthorized third-party tools.
  • Do not forward invitations, recordings, transcripts, or chat content to unauthorized recipients.
  • Confirm you are permitted to participate in a recorded session under the laws of your jurisdiction.
  • Report any suspicious behavior, unauthorized access attempts, or spillage to the organizer immediately.
Acknowledgment

By joining a meeting or event hosted by Jadex Strategic Group, you acknowledge that you have received this Policy and agree to comply with it, along with the Jadex Website Terms of Use and https://jadexstrategic.com/privacy-policy/”>Website Privacy Policy.

15

Incident Reporting

If you observe or suspect a privacy or security incident related to a Jadex-hosted meeting or event — including unauthorized access, unauthorized recording, spillage of CUI or export-controlled data, malware, phishing, harassment, or credential compromise — report it immediately.

How to Report

Email: incident@jadexstrategic.com
Backup: security@jadexstrategic.com
Response target: Acknowledgment within one (1) business day.

When reporting, include: (a) the meeting or event name and date; (b) the nature of the incident; (c) the participants involved; (d) any evidence (screenshots, links) available; and (e) your contact information.

CUI Spillage

Suspected spillage of Controlled Unclassified Information, ITAR-controlled data, or classified information into an unauthorized environment must be reported immediately. Do not attempt to delete, forward, or remediate the affected content on your own — preservation is required for incident investigation and, where applicable, DoD reporting under DFARS 252.204-7012.

16

Governing Law & Contact

This Policy is governed by and construed in accordance with the laws of the State of Michigan, without regard to its conflict of laws principles. Any dispute arising from this Policy is subject to the exclusive jurisdiction and venue provisions set forth in the Jadex Website Terms of Use.

Contact

Jadex Strategic Group
Attn: Privacy & Compliance
Spring Lake, Michigan, USA

Privacy: privacy@jadexstrategic.com
Security: security@jadexstrategic.com
Incidents: incident@jadexstrategic.com
Legal: legal@jadexstrategic.com
Website: https://jadexstrategic.com

Additional Resources

  • Microsoft Privacy Statement: privacy.microsoft.com/privacystatement
  • Microsoft Teams security and compliance overview: learn.microsoft.com/microsoftteams/security-compliance-overview
  • Microsoft Products and Services DPA: Microsoft DPA
17

Changes to This Policy

Jadex Strategic Group may update this Policy from time to time to reflect changes in our services, technology, legal requirements, or business practices. Updates will be posted on the Website with a revised “Last Updated” date.

Where changes are material, we will provide additional notice, such as a banner on the Website or a notice within a Jadex-hosted meeting or event invitation. Continued participation in Jadex-hosted meetings or events after the effective date of any update constitutes acceptance of the revised Policy.

Participants are encouraged to review this Policy periodically. Prior versions are available upon written request to legal@jadexstrategic.com.

“
Security in collaboration is not a feature — it is a discipline. Every meeting we host reflects the same standards we bring to the organizations we defend.
— Jadex Strategic Group Leadership
Need a Secure Collaboration Environment?

Talk to the Jadex Team

From Microsoft 365 Commercial to GCC High enclaves like Praesidium, Jadex Strategic Group designs collaboration environments that meet the real-world compliance obligations of the Defense Industrial Base and regulated industries.

Contact Our Team Explore Praesidium
Jadex Strategic Group logo featuring a teal hexagon cube symbol with modern blue-green branding for technology, cybersecurity, and compliance services
Company Details

DUNS Number: 078570307
Cage Code: 6TX26
NAICS Codes: 541690, 541990, 541611, 541618, 611420, 541370, 541519

Company Designations
Grand Rapids Chamber of Commerce Diverse Business Enterprise - Veteran Owned Business designation for Jadex Strategic Group.
Grand Rapids Chamber of Commerce Diverse Business Enterprise - Minotiry Owned Business designation for Jadex Strategic Group.
Business Information

Headquarters: Spring Lake, MI
Email: info@jadexstrategic.com
Phone: +1 (833) 568 - 3925

Platforms
Praesidium
AuditAble
Cyber Watchtower
AI Academy

Terms and Conditions

Privacy Policy

  • Home
  • Assessments
    • AI & Data Governance
    • Compliance & Regulatory
    • Microsoft 365 Optimization
    • Security & Protection
  • Platforms
    • Praesidium
    • AuditAble
    • Academy
    • Cyber Watchtower
    • View All Platforms
  • Training
  • Capabilities
    • Cybersecurity
      • Identity Security
      • Device Security
      • Data Security
      • Security Operations
    • Compliance & GRC
    • Microsoft 365 Transformation
    • Documentation & Audit Support
    • Information & Content Management
    • Communications & Collaboration
    • Business Communications
  • Industries
    • Defense Industrial Base
    • Manufacturing
    • Financial Services
    • Government & Public Sector
    • Healthcare
    • Education
  • Resources
    • Assessments
    • Case Studies
    • Guides & Playbooks
    • Insights
    • Partnerships & Referrals
    • Training & Enablement
  • Company
    • Leadership
Search