Privacy Policy
Last updated: July 2026
Business Dynamics Pro Inc. (“we”, “us”, or “our”) operates extensions and applications for Microsoft Dynamics 365 Business Central available through Microsoft AppSource. This policy explains what our extensions do with your data. Where one extension's data handling differs from the rest, we name it and describe it specifically rather than hiding it inside a general statement.
Information We Collect
Most of our Business Central extensions operate entirely within your Dynamics 365 Business Central environment: they read and write standard and extension-specific tables in your own Business Central database and do not transmit your business data outside your tenant.
BDP SmartFlow APS and BDP SmartFlow Projects are the exceptions. Each has cloud scheduling features, and each keeps a record to operate your free trial and subscription, that involve data leaving your Business Central tenant. The full disclosure for each is in its own named section below — “BDP SmartFlow APS — data handling” and “BDP SmartFlow Projects — data handling” — and nothing about either extension is described in this section.
Data Processing
Except where the BDP SmartFlow APS and BDP SmartFlow Projects sections below say otherwise, our extensions process data locally within your Business Central environment to provide the functionality described in each extension's documentation. That data is not sent to our servers or to any third party.
Data Storage
Data generated by our extensions inside Business Central is stored within your Dynamics 365 Business Central database and is subject to Microsoft's data handling policies for Business Central. BDP SmartFlow APS and BDP SmartFlow Projects each additionally maintain one small record per customer tenant outside Business Central — see each extension's own section below for what it contains and why.
Sub-processors and Third Parties
We do not sell your data, and we do not share it with third parties for their own purposes. Where an extension's functionality requires sending data to a service we operate — today, that is BDP SmartFlow APS's optional cloud scheduling and BDP SmartFlow Projects' scheduling service, together with each extension's trial/subscription record, all described below — that service runs entirely on Microsoft Azure. Business Dynamics Pro Inc. is the sole processor of that data; Microsoft Azure is our only sub-processor, the same Microsoft cloud your Business Central environment already runs on. We do not use any third-party cloud provider.
BDP SmartFlow APS — data handling
What we send to our servers
When you run Sequence Optimization in cloud mode, or run Finite-Capacity Scheduling where it
is available in your installed version, the extension sends the SmartFlow Scheduling Service
(hosted by us at smartflow.dynamicspro.ca, on Microsoft Azure) the scheduling
data for the work centers, orders, and date range you selected — production order numbers,
item numbers, operation numbers, routing sequence, setup and run times, quantities, due
dates, work-center and machine-center identifiers, and changeover constraints — together with
your Business Central Azure Active Directory tenant identifier (a GUID). The request is
authenticated with a function key issued to this extension and that tenant identifier, which
the service uses to verify your tenant is entitled to use the feature. This scheduling data
is processed in memory to compute a result and is written to no datastore of ours; our
operational logs record only that a request occurred — the tenant identifier, the time taken,
and whether it succeeded — never the scheduling data itself. The built-in local Sequence
Optimizer sends nothing outside your Business Central environment; it is always available as
an alternative to the cloud optimizer.
What we store about your tenant, and where
When an administrator in your organization clicks Activate Extension, we create one record for your tenant in Microsoft Azure Table Storage, in Business Dynamics Pro Inc.'s own Azure subscription — that is, outside your Business Central environment and outside your Azure tenant. That record contains:
| Field | Stored as | Purpose |
|---|---|---|
| Business Central tenant identifier (Azure AD GUID) | Plaintext (record key) | Identify your tenant on every entitlement check |
| Activation date, trial/subscription status, Microsoft subscription identifier | Plaintext | Operate the trial and subscription lifecycle |
| Country | Plaintext (2-letter code) | Regional reporting |
| Administrator email address | Encrypted (AES-256-GCM) | Contact you about your trial or subscription |
| Company name, contact name, phone (where provided) | Encrypted (AES-256-GCM) | Contact you about your trial or subscription |
The administrator's email address is read from that user's Business Central user record, or from Company Information if the user record has none, at the moment Activate Extension is clicked.
Why this record lives outside Business Central, and how long we keep it
The free trial is time-limited. If the trial record lived only inside your Business Central environment, uninstalling and reinstalling the extension would reset it, and the trial could be renewed indefinitely. The record therefore persists after uninstall — that is its purpose, not an oversight. We retain the tenant identifier, subscription status, and a non-personal flag recording whether this tenant has already used its trial for the life of the entitlement relationship — indefinitely — because preventing indefinite trial resets is the entire reason this record exists outside Business Central. The personal information in this record (administrator email, company name, contact name, phone number) is retained only while your tenant is within its free trial period or holds an active subscription, and is automatically deleted within 12 months after your subscription is cancelled or your trial expires. You may request earlier deletion at any time — see “Your rights,” below.
Availability without the cloud service
Sequence Optimization includes a scheduling algorithm that runs entirely inside Business Central and continues to work if the cloud service is unavailable. Finite-Capacity Scheduling, where available in your installed version, has no offline equivalent and requires the cloud service; if it is unreachable, the finite scheduler reports an error and makes no change to your data.
BDP SmartFlow Projects — data handling
What we send to our servers
When you click Generate Schedule, the extension sends a scheduling service we operate on Microsoft Azure the scheduling data for the projects and date range you selected — project and task numbers and descriptions, scheduled dates, durations and effort hours, dependency links and their lag values, resource assignments and allocation percentages, resource capacity and working calendars, and your scheduling weights — together with your Business Central Azure Active Directory tenant identifier (a GUID). The request is authenticated with a key issued to this extension and that tenant identifier, which the service uses to verify your tenant is entitled to use the feature.
Resources are identified by their Business Central resource code only. Resource names, email addresses and other personal details are never placed on that request. The scheduling data is processed in memory to compute a result and is written to no datastore of ours; our operational logs record only that a request occurred — the tenant identifier, the time taken, and whether it succeeded — never the scheduling data itself.
What we store about your tenant, and where
When an administrator in your organization activates the extension, we create one record for your tenant in Microsoft Azure Table Storage, in Business Dynamics Pro Inc.'s own Azure subscription — that is, outside your Business Central environment and outside your Azure tenant. That record contains:
| Field | Stored as | Purpose |
|---|---|---|
| Business Central tenant identifier (Azure AD GUID) | Plaintext (record key) | Identify your tenant on every entitlement check |
| Activation date, trial/subscription status, Microsoft subscription identifier | Plaintext | Operate the trial and subscription lifecycle |
| Administrator email address | Encrypted (AES-256-GCM) | Contact you about your trial or subscription |
That is the whole record. BDP SmartFlow Projects does not send or store your company name, contact name, phone number or country — the activation request carries only the tenant identifier and the administrator's email address. The email address is read from that user's Business Central user record at the moment the extension is activated.
Why this record lives outside Business Central, and how long we keep it
The free trial is time-limited. If the trial record lived only inside your Business Central environment, uninstalling and reinstalling the extension would reset it, and the trial could be renewed indefinitely. The record therefore persists after uninstall — that is its purpose, not an oversight. We retain the tenant identifier, subscription status, and a non-personal flag recording whether this tenant has already used its trial for the life of the entitlement relationship — indefinitely — because preventing indefinite trial resets is the entire reason this record exists outside Business Central. The administrator email address is deleted on request at any time; see “Your rights,” below.
Availability of the scheduling service
Generating a schedule requires the scheduling service and has no offline equivalent. If the service is unreachable, the extension reports an error and makes no change to your data. Everything else in the extension — the board, the table view, dependencies, templates, the capacity heatmap and the Excel export — runs entirely inside Business Central and continues to work without it. Nothing is ever written back to your Business Central data except when you explicitly accept a proposed schedule.
Your rights
You may request a copy of, a correction to, or earlier deletion of the personal information described above (administrator email, company name, contact name, phone number) at any time by contacting privacy@dynamicspro.ca, rather than waiting for the automatic 12-month purge. Deleting your personal information does not reset your tenant's trial-eligibility history — the non-personal trial-used flag persists indefinitely, because that is what the record's anti-reset purpose depends on.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page.
Contact Us
If you have questions about this privacy policy, please contact us at:
Business Dynamics Pro Inc.
Email: privacy@dynamicspro.ca
Phone: 416-843-6575
Address: 248 Farrell Rd, Vaughan, Ontario, L6A 4W5, Canada