Skip to content
Documentation Portal →

Privacy

Draft — not yet reviewed

This describes what the support platform actually does, written from the code that does it. It has not been reviewed by anyone qualified to sign it off, and the points marked [decision] are ones nobody has made yet rather than ones we have left vague. Do not link to it from AppSource or the sign-up flow until both are fixed.

This explains what we do with your information when you use the bydynamics Portal. It is written to be read, not to be survived.

bydynamics B.V. is the controller for everything below. Ask us anything about it at support@bydynamics.com.

What we hold, and why

Your account

When you sign in, our identity service (Microsoft Entra) uses your organisation's existing Microsoft account where you have one, or verifies your email address with a one-time code where you do not. Either way, we never hold a password of yours.

We store, against an identifier derived from your sign-in rather than from anything you type:

What Why
Email address To tell you about your issues, and so your colleagues can recognise you
Display name To show who wrote a comment
Which organisation you belong to It decides which issues you can see, and it is the whole access model
Whether your access is approved, and who approved it So an administrator at your organisation can answer for who was let in

Your organisation is worked out from your email domain, or from your company's own identity provider if we have connected one. A colleague of yours approves your access, not us — and approving somebody gives them every issue your organisation has raised, including ones they did not write.

Your issues

An issue holds what you type: a summary, a description, and any comments. It may also hold a Business Central version and a tenant id if you give them.

Please do not put personal data in an issue. The form says so at the point you are about to, because a screenshot of a Business Central page usually contains a customer name, an address, and sometimes a bank account. We cannot un-see what is pasted, and an issue is visible to everyone at your organisation with portal access.

Files you attach

Attachments are stored separately and served only to people who can already see the issue they belong to. There is no shareable link — a copied URL is useless to anyone who is not signed in and entitled.

What we log

We keep an operational record of who did what: an action, a timestamp, an organisation, and the identifier for the person. It does not contain your email address, your name, or anything from an issue. It exists so we can answer "who read this and when", which is a question you are entitled to have answered.

The writing assistant

The issue form offers to rewrite your description and read the error text out of screenshots you paste. It is optional, and nothing happens unless you press it.

When you do:

  • What you typed, and up to two pasted screenshots, are sent to Azure OpenAI running in West Europe.
  • The result comes back to your browser for you to read and edit. It is not stored unless you go on to create the issue.
  • The model is instructed to take the error text out of a screenshot and to leave business data — names, addresses, bank details, amounts — alone. That is an instruction, not a guarantee, which is the other reason the form asks you not to paste personal data.
  • Your text is not used to train any model.

[decision] Azure OpenAI's default abuse monitoring can retain prompts for up to 30 days and expose flagged content to human review. Whether we have applied for the exemption, and what we tell you if we have not, has to be settled before this paragraph is true enough to publish.

Who else processes it

Processor What they hold Where
Microsoft Azure The portal, its API, attachments, logs West Europe
Microsoft Azure OpenAI Assistant requests, at the moment you press the button West Europe
Microsoft Entra ID Your sign-in identity European tenant
GitHub, Inc. Issue content and comments [decision] — see below

GitHub is the one that needs an answer. Issues are stored as issues in private repositories, which means the content of your issue sits with GitHub, whose processing is not confined to the EU. The transfer mechanism — Microsoft's Data Protection Addendum and the standard contractual clauses it incorporates — has to be recorded, and the record has to name GitHub as a sub-processor. Until somebody does that, this table is incomplete rather than reassuring.

How long we keep it

[decision] Nobody has set retention periods. What is true today:

  • Issues are kept indefinitely. A closed issue is often the answer to the next one, which is an argument for keeping them and not a policy.
  • Attachments are kept as long as the issue.
  • Account records are kept while your access exists.
  • Logs are kept for as long as the platform's telemetry retains them, which is a setting rather than a decision.

Each of those needs a number and a reason before this section says anything.

What you can ask for

You can ask us to show you what we hold, correct it, delete it, or hand it over in a portable form. Write to support@bydynamics.com and we will answer within a month.

Two honest caveats:

  • Deleting an issue deletes it for your colleagues too. An issue belongs to your organisation rather than to the person who filed it, so we will confirm with an administrator before removing one.
  • Your data spans two places — the issue in GitHub and the attachment in storage. A request has to reach both, and the tooling that does that is still being built rather than finished.

Cookies and storage

The portal keeps your sign-in session in your browser's own storage so you are not asked to sign in on every page. There is no advertising, no analytics that follows you, and nothing shared with a third party for either.

The documentation site loads its own fonts rather than fetching them from Google, so reading the documentation does not tell anyone else that you did.

Changes

We will date this page when it changes and say what changed. If a change matters to you — a new processor, a new purpose — we will tell you rather than rely on you noticing.


Last updated: 17 August 2026. Status: draft, unreviewed.