Privacy policy

How BC Toolkit, operated by CLOUD DATA PROCESSING LLC, handles personal data and customer data.

Last updated 6 October 2026. BC Toolkit is currently free of charge; this policy will be updated before any paid plan is introduced.

Who we are

CLOUD DATA PROCESSING LLC ("we", "us") operates the BC Toolkit service at bctoolkit.clouddata.vc. Contact: bctoolkit@clouddata.vc. Registered office: Suite 305, Griffith Corporate Centre, Beachmont, Kingstown, St. Vincent and the Grenadines. Company number 3404 LLC 2024.

Roles

For the data inside your Business Central environments, your organisation is the controller and we act as a processor on your instructions. For your account data (who signed in, when, and what jobs were run), we are the controller.

What we process

DataSourcePurposeRetained
Name, email address, Microsoft account and tenant identifiersMicrosoft Entra ID sign-inCreating your account, showing who did what, supportUntil your organisation's consent is revoked or the account is deleted, plus 30 days
Access and refresh tokens for Business CentralMicrosoft Entra IDCalling Business Central as youEncrypted; deleted on sign-out, consent revocation or expiry
Business Central records you browseYour Business Central environmentDisplaying them to youNot stored; held in memory only while the page is served
Job definitions, plans and run reportsCreated by you in BC ToolkitReview, apply, audit and undo of bulk correctionsUntil deleted by you, or 12 months after the last run
Service logs (request metadata, errors, timing)The serviceOperation, security, troubleshooting30 days

Plans and run reports contain the field values that a job changes. Depending on the entity, those can include personal data of your customers, vendors or employees. You decide which entities and fields a job touches.

What we do not do

Sub-processors

ProviderPurposeLocation
MicrosoftIdentity (Entra ID) and Business Central itselfYour Microsoft tenant's region
CloudflareDNS, TLS termination and content delivery for this site and the serviceGlobal edge network
Hetzner Online GmbHApplication and database hosting (dedicated server)Nuremberg, Germany (EU)
PurelymailSupport and service emailUnited States

Where data is stored

Account data, tokens, jobs and reports are stored on servers in Germany, within the European Union. Business Central data stays in your Microsoft tenant's region and is only read on demand.

Security

All traffic uses HTTPS. Tokens are stored encrypted at rest. Access to production systems is limited to named staff with multi-factor authentication. Business Central permissions are enforced by Business Central on every call, using the signed-in user's own identity; BC Toolkit cannot do anything the user could not do in Business Central directly.

Your rights and how to exercise them

Depending on where you are, you may have rights to access, correct, delete, restrict or export your personal data, and to complain to a supervisory authority. Email bctoolkit@clouddata.vc. Requests about data inside Business Central should go to your organisation, which controls that data; we will assist them.

Revoking access

Your organisation's administrator can revoke BC Toolkit's access at any time in Microsoft Entra ID (Enterprise applications). Revocation stops all access immediately; stored account data, jobs and reports are deleted within 30 days unless you ask us to keep them.

Changes

We will post changes to this policy on this page and, for material changes, notify signed-in users or the administrator who granted consent.