Privacy policy
How BC Toolkit, operated by CLOUD DATA PROCESSING LLC, handles personal data and customer data.
Last updated 6 October 2026. BC Toolkit is currently free of charge; this policy will be updated before any paid plan is introduced.
Who we are
CLOUD DATA PROCESSING LLC ("we", "us") operates the BC Toolkit service at bctoolkit.clouddata.vc. Contact: bctoolkit@clouddata.vc. Registered office: Suite 305, Griffith Corporate Centre, Beachmont, Kingstown, St. Vincent and the Grenadines. Company number 3404 LLC 2024.
Roles
For the data inside your Business Central environments, your organisation is the controller and we act as a processor on your instructions. For your account data (who signed in, when, and what jobs were run), we are the controller.
What we process
| Data | Source | Purpose | Retained |
|---|---|---|---|
| Name, email address, Microsoft account and tenant identifiers | Microsoft Entra ID sign-in | Creating your account, showing who did what, support | Until your organisation's consent is revoked or the account is deleted, plus 30 days |
| Access and refresh tokens for Business Central | Microsoft Entra ID | Calling Business Central as you | Encrypted; deleted on sign-out, consent revocation or expiry |
| Business Central records you browse | Your Business Central environment | Displaying them to you | Not stored; held in memory only while the page is served |
| Job definitions, plans and run reports | Created by you in BC Toolkit | Review, apply, audit and undo of bulk corrections | Until deleted by you, or 12 months after the last run |
| Service logs (request metadata, errors, timing) | The service | Operation, security, troubleshooting | 30 days |
Plans and run reports contain the field values that a job changes. Depending on the entity, those can include personal data of your customers, vendors or employees. You decide which entities and fields a job touches.
What we do not do
- We do not keep a copy of your Business Central database.
- We do not use your data to train models or for any purpose other than providing the service to you.
- We do not sell or share your data with advertisers.
- Service logs never contain access tokens.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Microsoft | Identity (Entra ID) and Business Central itself | Your Microsoft tenant's region |
| Cloudflare | DNS, TLS termination and content delivery for this site and the service | Global edge network |
| Hetzner Online GmbH | Application and database hosting (dedicated server) | Nuremberg, Germany (EU) |
| Purelymail | Support and service email | United States |
Where data is stored
Account data, tokens, jobs and reports are stored on servers in Germany, within the European Union. Business Central data stays in your Microsoft tenant's region and is only read on demand.
Security
All traffic uses HTTPS. Tokens are stored encrypted at rest. Access to production systems is limited to named staff with multi-factor authentication. Business Central permissions are enforced by Business Central on every call, using the signed-in user's own identity; BC Toolkit cannot do anything the user could not do in Business Central directly.
Your rights and how to exercise them
Depending on where you are, you may have rights to access, correct, delete, restrict or export your personal data, and to complain to a supervisory authority. Email bctoolkit@clouddata.vc. Requests about data inside Business Central should go to your organisation, which controls that data; we will assist them.
Revoking access
Your organisation's administrator can revoke BC Toolkit's access at any time in Microsoft Entra ID (Enterprise applications). Revocation stops all access immediately; stored account data, jobs and reports are deleted within 30 days unless you ask us to keep them.
Changes
We will post changes to this policy on this page and, for material changes, notify signed-in users or the administrator who granted consent.