Privacy Policy
Last updated: 16 August 2026
Testgrity is operated by DYNAMICSDUO (ABN 93 257 340 580). This Privacy Policy explains how we collect, use, store, and disclose personal information when you visit our website or use the Testgrity test automation service (the “Service”).
1. Information we collect
Account and identity information
When you sign in, we may receive your name, email address, unique account identifier, company name, job title, and basic profile information from Microsoft Entra External ID. If profile editing is enabled, the Service may use Microsoft Graph to read or update the profile fields you choose.
During the private beta, we also process your beta approval status, relevant security-group membership, and the delivery status of access notifications. Registration creates an account but does not itself grant access to the Testgrity workspace.
Workspace and test information
We store information you create or provide through the Service, including projects, environments, application URLs, test suites, cases, steps, recordings, run history, results, and workspace membership information.
Connection and authentication information
To run tests, the Service may store an encrypted reusable browser session for a connected Dynamics 365 or Power Apps environment. The saved session may include authentication cookies and limited browser storage needed to access that environment. For interactive browser sign-in, you enter your Dynamics credentials directly into the Microsoft sign-in page; Testgrity does not collect your password. The browser extension sends a sanitised snapshot of the resulting session to the Service, where it is encrypted for Background execution and authenticated Dataverse operations until Microsoft requires authentication again. Browser execution uses the signed-in session in your current browser profile. Passwords used for unattended connection are used to establish an encrypted reusable session and are not retained by the Service.
Test artifacts and support information
Depending on workspace settings, test runs may create screenshots, video, Playwright traces, error details, and reports. These artifacts can contain information visible in the application being tested. If you submit an issue report or feedback, we collect the submission type, title, description, your name and email address, workspace ID, current page URL, browser information, portal version, submission time, and any screenshots you choose to attach. The Service creates a GitHub issue containing this information. Attached screenshots are stored by Testgrity and linked from that GitHub issue.
Testgrity Recorder browser extension
The Testgrity Recorder extension for Google Chrome and Microsoft Edge has the single purpose of connecting Testgrity with Microsoft Dynamics 365 and Power Apps so that you can authenticate a connection, record test steps, and run browser-based tests. Its content scripts run only on the Testgrity application and supported Microsoft Dynamics 365 domains.
When you initiate one of those features, the extension may process the relevant page URL and content, your clicks and field interactions, generated test steps, and authentication cookies or limited browser storage for the connected Microsoft environment. If your workspace enables evidence capture, the extension may also capture the visible managed Dynamics 365 test tab as screenshots. Tab video is captured only after you select the Testgrity extension button to authorise it. The browser requires a broad host permission for automatic visible-tab screenshots, but Testgrity restricts that capture to a tab it opened and is actively managing for your requested test run.
Extension session state is held temporarily in browser session storage. Information sent to Testgrity is transmitted over HTTPS and is used as described in this Policy. The extension does not monitor unrelated browsing, inject content scripts into unrelated sites, or use browsing or test information for advertising.
Technical information
We may process browser and device information, IP address, request and error logs, timestamps, and security events to operate, protect, and troubleshoot the Service.
How we collect information
We collect information directly from you when you sign in, use the Service, configure a workspace, connect an environment, run tests, or contact us. We may also receive information from your workspace owner or administrator, Microsoft Entra External ID, connected Dynamics 365 or Power Apps environments, and optional integrations enabled by your organisation.
2. How we use information
We use information to:
- provide, authenticate, maintain, and secure the Service;
- review and manage beta access and send account-approval notifications;
- create and manage workspaces, connections, tests, and reports;
- execute tests and retain the evidence selected by your workspace;
- respond to support requests, issue reports, and feedback, and investigate errors or misuse;
- improve reliability, performance, and user experience; and
- meet legal obligations and enforce our agreements.
We do not sell personal information or use customer test data for third-party advertising.
Browser extension limited use
Information obtained through the Testgrity Recorder is used or transferred only to provide or improve its user-facing test automation features, maintain security, prevent abuse, comply with applicable law, or complete a permitted business transfer with appropriate safeguards. We do not use or transfer this information for personalised advertising, creditworthiness, lending, or any purpose unrelated to Testgrity's disclosed functionality. Human access is limited to circumstances in which you have given permission, it is necessary for security or abuse investigation, it is required by law, or the information has been aggregated and de-identified for internal operations.
3. Cookies
The Service uses strictly necessary cookies for sign-in, session security, and authentication flows. These cookies are HTTP-only where appropriate and are not used for advertising. Disabling them may prevent you from signing in or using authenticated features.
4. When we disclose information
We may disclose information:
- to hosting, database, storage, security, and other service providers that process it on our behalf;
- to Microsoft when you use Microsoft Entra External ID, Microsoft Graph, Azure Communication Services, Azure-hosted services, Dynamics 365, or Power Apps;
- to GitHub when you choose to submit an issue report or feedback through the in-app reporting integration. The resulting GitHub issue may include your submission, identity and workspace context, technical details, and links to screenshots. Access depends on the configured repository's visibility and permissions;
- to your workspace owners or administrators, according to their access and responsibilities;
- when required by law or reasonably necessary to protect rights, safety, security, and the integrity of the Service; or
- as part of a merger, financing, acquisition, or transfer of business assets, subject to appropriate safeguards.
5. Data retention
We retain information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Workspace owners can configure screenshot, video, and Playwright trace retention to 1, 7, 14, or 30 days. Native Playwright reports containing those artifacts are deleted when an included artifact expires. Other test records may remain until they are deleted, the workspace is closed, or they are no longer required. Security logs and backups may be retained for a limited additional period. As of this policy update, production operational logs are normally retained for 30 days and automated PostgreSQL backups for 7 days. These operational periods may change as our recovery requirements evolve.
Issue and feedback submissions created in GitHub are retained under the configured repository's policies and GitHub's applicable terms. Screenshots uploaded with those submissions are stored separately by Testgrity and are not governed by the workspace's 1, 7, 14, or 30-day test-artifact settings. They may remain while the related GitHub issue exists or for as long as reasonably needed for support, security, dispute resolution, or legal obligations. Account deletion does not automatically remove an external GitHub issue or its linked submission screenshots. You may contact us to request deletion, subject to any legal, security, or operational need to retain them.
6. Azure hosting, compliance, and data security
Azure hosting
The Testgrity cloud service is hosted on Microsoft Azure. Our primary application resources are currently configured in the Australia East Azure region. Microsoft Azure provides the underlying cloud infrastructure and platform security used to operate the Service.
Technical safeguards
We use technical and organisational safeguards designed to protect information against unauthorised access, loss, misuse, alteration, or disclosure. These safeguards include encryption in transit and at rest, secure authentication, access controls, workspace-level data separation, controlled access to test artifacts, service monitoring, and retention controls.
Azure compliance and shared responsibility
Microsoft maintains independent certifications, attestations, and audit reports for Azure services that are within the scope of its compliance programs. These programs include standards and frameworks such as ISO/IEC 27001, ISO/IEC 27018, ISO/IEC 27701, SOC, and Australia IRAP, although the services covered differ between programs. Current details and audit scope are available in the Microsoft Azure compliance documentation.
Azure's compliance certifications apply to Microsoft's in-scope cloud infrastructure and services; they do not automatically certify Testgrity or any customer workload. Under the cloud shared-responsibility model, Microsoft is responsible for the security of the underlying Azure platform. Testgrity remains responsible for its application code, configuration, access controls, data handling, and operational processes. Customers remain responsible for the data they place in the Service, their users, connected environments, and workspace settings.
Test artifacts may contain sensitive tenant data. You are responsible for choosing appropriate capture and retention settings, limiting access to your workspace, and avoiding unnecessary personal or confidential information in test data. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Data breaches
If we become aware of a data breach, we will assess it and take reasonable steps to contain and address it. Where the Australian Notifiable Data Breaches scheme applies and a breach is eligible, we will notify affected individuals and the Office of the Australian Information Commissioner as required. We will also notify affected organisations, individuals, and regulators where otherwise required by applicable law.
7. International data transfers
Although Testgrity's primary application resources are configured in Australia East, Microsoft identity, Graph, communications, and support services may process information in Australia, the United States, or the locations associated with your organisation's Microsoft tenant. GitHub may process issue and feedback submissions in the United States and other locations where it operates. Other countries may be involved when your organisation enables optional integrations. Where required, we use appropriate contractual or other safeguards for international transfers. Contact us if you need the current information available to us about a particular provider or integration.
8. Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, or to object to certain processing. You may also have the right to complain to a privacy regulator.
You can update certain account and workspace information or delete your Testgrity account within the Service. Account deletion also deletes the Microsoft Entra External ID identity used for the Service, but does not automatically delete content already submitted to an external integration or screenshots attached to an issue or feedback submission. For other requests, including a request to remove submitted screenshots, contact your Testgrity workspace owner or use the Testgrity support contact provided to your organisation. We may need to verify your identity before completing a request.
9. Third-party services
The Service may link to or interoperate with third-party services. Their handling of personal information is governed by their own terms and privacy policies. Your organisation controls which environments and optional integrations it connects to Testgrity.
10. Changes to this policy
We may update this Privacy Policy as the Service or applicable laws change. We will post the revised policy here and update the date at the top. We will provide additional notice when required by law.
11. Contact us
For privacy questions, access or correction requests, or complaints, contact:
DYNAMICSDUOABN 93 257 340 580contact@dynamicsduo.com.auPlease submit privacy complaints in writing and include enough information for us to understand your concern and the outcome you are seeking. We will acknowledge your complaint and aim to respond within 30 calendar days. We may contact you for further information and may need to verify your identity.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner. If your organisation manages your Testgrity workspace, you may also contact its workspace owner or administrator.