But where they specifically went wrong? Well one of them was absolutely the way the "point of contact" reached out. If my professional email was shared with you as part of a professional agreement, adding it to a mailing list to sell me on the paid version of what I used for free makes sense. Sending some of those specific details to my personal account, which by the way you aren't sure is actually me, is way over the line. The salesperson personally screwed up big time there for sure.
The other thing is the granularity of the data, and that's also over the line. I read that agreement and think sure - they'll know our company has used their company. But specific actions taken by specific developers? There are users that avoid certain providers like the plague because in some way they're competitive, and even if they trust them not to directly compromise security measures, interfere and steal data - they still don't want a competitive company having insight into their costs, development, traffic, etc. This kills the trust you may have in Microsoft from that standpoint.
In Canonical's statement they never regretted using the information to contact the user. The part they regretted was TELLING the user that they are monitoring the installs and linking those installs to personal contact details.
Canonical promised to improve training to avoid those "poor choice of words", NOT to stop the practice. Basically they will train their staff to make it feel more serendipitous when they just so happen to reach out about selling an enterprise license moments after you install the VM on Azure. Canonical doesn't regret this sales practice and plans to keep using it. That's the scary part in this story.
I mean, is it even possible to buy an Oracle license without Oracle knowing who you are?