D&T Device Management Privacy Notice

Effective date: July 23, 2026
Last updated: July 23, 2026

Purpose

D & T Contractors Inc. (“D&T”) uses Microsoft Intune and related Microsoft security services to manage company-owned devices, protect company information, provide technical support, and control access to company applications and resources.

This notice explains what device information D&T may collect or view, what D&T does not access through Intune, and what management actions D&T may perform. It applies to employees, contractors, and other authorized users who use a company-owned device or access D&T resources from a personal device.

Information D&T May Collect or View

The information available to D&T depends on whether a device is company-owned or personal, how the device is enrolled, and which management features are enabled. D&T may collect or view:

  • User name, company email address, and work-account identifiers.

  • Device ownership status, device name, manufacturer, model, serial number, and other device identifiers.

  • Operating system, operating-system version, enrollment status, and last check-in information.

  • Device compliance and security status, including encryption, BitLocker, Secure Boot, firewall, antivirus, antimalware, security intelligence, update, password, PIN, and screen-lock status.

  • Hardware, storage, network, and certificate information needed for security, inventory, and troubleshooting.

  • Managed application inventory on personal devices.

  • Installed application inventory and additional system information on company-owned devices.

  • Security events, administrative actions, sign-in information, and other audit records associated with company accounts, managed applications, and managed devices.

  • On company-owned Windows devices, authorized troubleshooting tools may retrieve technical information such as file names and paths, running processes, local users and groups, registry entries, and event-log information. This does not by itself give D&T the contents of personal documents.

Personal Devices and Protected Work Applications

When a personal phone or other personal device is used only with D&T-protected work applications, such as Microsoft Outlook, D&T manages the company account, company data, and protected work applications rather than the entire personal device.

D&T may verify basic device and security information, apply protections to company data, restrict how company data is copied or saved, require an application PIN, block access from an unsafe device, and remove D&T data from managed applications when access is revoked.

Information Intune Is Not Used to View

Microsoft Intune is not used by D&T to view:

  • Personal calling or web-browsing history.

  • Personal email or text-message content.

  • Personal contacts or calendars.

  • Passwords.

  • Personal photographs or camera-roll contents.

  • The contents of personal, user-created documents.

Company-owned devices are D&T business systems and should be used primarily for authorized business purposes. Other authorized security, monitoring, backup, legal-discovery, or support tools may process information as permitted by D&T policy, contractual requirements, or applicable law.

Device Management Actions

Depending on device ownership, enrollment type, and business need, D&T may:

  • Install, configure, update, restrict, or remove applications.

  • Apply security and compliance settings.

  • Require encryption, antivirus protection, firewall protection, software updates, passwords, PINs, and automatic screen locking.

  • Allow or block access to company resources based on device compliance or risk.

  • Synchronize, restart, lock, retire, or wipe a company-owned device.

  • Remove D&T accounts, applications, and company data from a personal device without intentionally deleting personal content.

  • Locate a lost company-owned mobile device where the platform supports that action.

  • Investigate security incidents and take reasonable protective or corrective action.

Remote Help

D&T may use Microsoft Remote Help to assist users with technical problems. D&T’s standard practice is to use attended support sessions with the user’s authorization. During an active session, authorized IT personnel may view or control the screen only to provide support, troubleshoot a problem, or complete an approved administrative task. The user can see when the session is active and can end the session. Microsoft Remote Help does not store a recording of the session in the service.

How Information Is Used

D&T uses device and account information only for legitimate business purposes, including:

  • Protecting D&T, customer, Federal Contract Information, and other sensitive information.

  • Administering devices, accounts, applications, and software licenses.

  • Evaluating compliance with company security requirements.

  • Detecting, investigating, and responding to cybersecurity incidents.

  • Providing technical support and maintaining business operations.

  • Meeting contractual, regulatory, legal, audit, and recordkeeping requirements.

Service Providers and Disclosure

D&T uses Microsoft and, where applicable, device-platform providers such as Apple and Google to provide device-management and security services. Information may also be disclosed to authorized service providers, customers, legal authorities, or other parties when reasonably necessary to provide services, investigate an incident, meet a contractual or legal obligation, or protect D&T and its users.

D&T does not sell employee device-management information.

Data Retention

D&T retains device-management, security, and audit information only as long as reasonably necessary for business, security, contractual, audit, and legal purposes. Records may remain in system logs, security records, backups, or compliance evidence after a device is retired or a user’s access ends, subject to applicable retention requirements.

User Responsibilities

Users must follow D&T acceptable-use, information-security, and device-management requirements; protect their credentials; promptly install required updates; and immediately report lost devices, suspected compromise, or unauthorized access. Users must not disable, bypass, or interfere with D&T security or management controls.

Questions or Privacy Requests

Questions about this notice, device management, or information associated with a managed device may be directed to:

John DeSalvo
IT and Compliance Administration
john.desalvo@dtci.net

Changes to This Notice

D&T may update this notice when its technology, security practices, legal obligations, or business requirements change. The current version and effective date will be posted on this page.