Privacy Policy and Data Processing Agreement
Data Processing Agreement (DPA) 1. Definitions 2. Scope and Roles 3. Subject Matter and Duration 4. Nature and Purpose of Processing 5. Categories of Data 6. Processor Obligations 7. Security Measures 8. Sub-processors (DPA) 9. International Transfers 10. Assistance to the Controller 11. Data Subject Rights 12. Data Breach Notification 13. Data Retention and Deletion 14. Audit Rights 15. Customer Responsibilities 16. Liability 17. Governing Law 18. Order of Precedence 19. Contact
Annex I Annex II Annex III
1. Introduction
De BI Controller B.V. (“we”, “us”, or “our”) operates Dexterity (the “Services”), a Software-as-a-Service solution for replicating data from Microsoft Dynamics 365 Business Central to Azure SQL Database or Microsoft Fabric SQL Database.
We are committed to protecting your personal data and respecting your privacy in accordance with applicable laws, including the General Data Protection Regulation (GDPR) and other global privacy laws.
If you have questions, visit the contact form.
2. Scope of this Policy
This Privacy Policy applies to:
- use of Dexterity software and APIs;
- customer relationships and support interactions;
- our website and communications.
“Customer” refers to business users of the Services.
3. Information We Collect
3.1 Information Provided by You
We may collect:
- name, email address, phone number;
- company name, job title;
- billing and contract information;
- account credentials and authentication data;
- support communications.
3.2 Data Processed via the Service
Dexterity processes data from your Business Central environment, which may include:
- business data (financial, operational, transactional);
- potential personal data contained within your systems.
We process this data strictly on your behalf.
3.3 Automatically Collected Data
We may collect:
- IP address;
- device and browser information;
- usage and log data;
- API usage metrics;
- error and diagnostic data.
4. How We Use Your Information
We process personal data based on:
- contract performance (providing the Services);
- legitimate interests (security, improvements);
- legal obligations;
- consent, where applicable.
We use data to:
- provide and operate Dexterity;
- enable data replication and API functionality;
- manage accounts and billing;
- provide customer support;
- improve performance and security;
- communicate service updates;
- comply with legal obligations.
5. Data Sharing
We do not sell personal data.
We may share data with:
- cloud infrastructure providers, for example Microsoft Azure;
- sub-processors necessary to deliver the Services;
- professional advisors, such as legal or financial advisors;
- authorities where required by law.
All processing is governed by appropriate agreements and safeguards.
6. International Data Transfers
Data may be processed in countries outside the European Economic Area (EEA).
Where applicable, we ensure safeguards such as:
- Standard Contractual Clauses (SCCs);
- adequacy decisions;
- equivalent legal protections.
7. Data Retention
We retain personal data:
- for the duration of the customer relationship;
- as required to provide the Services;
- as required by law, for example for tax or accounting purposes.
After termination:
- data is retained for up to 30 days unless otherwise agreed;
- data is then securely deleted or anonymized.
8. Data Security
We implement appropriate technical and organizational measures, including:
- encryption in transit and at rest, where applicable;
- access controls;
- monitoring and logging;
- secure cloud infrastructure.
However, no system is completely secure.
9. Customer Responsibilities
As a Customer, you are responsible for:
- ensuring lawful processing of your data;
- providing necessary notices and consents;
- configuring access controls within your own systems;
- compliance with GDPR and other applicable laws.
10. Cookies and Tracking
We may use cookies and similar technologies for:
- authentication;
- analytics;
- performance monitoring.
You can control cookies through your browser settings.
11. Your Privacy Rights
Depending on your jurisdiction, for example the EU/EEA, the UK, or the US, you may have rights to:
- access your personal data;
- correct inaccurate data;
- delete your data;
- restrict or object to processing;
- data portability;
- withdraw consent.
To exercise your rights, visit the contact form.
You also have the right to lodge a complaint with a supervisory authority.
12. Data Subject Requests
We will:
- respond within legally required timeframes;
- verify identity before processing requests;
- retain minimal data necessary for compliance.
Customers controlling the data, as controllers, are primarily responsible for responding to end-user requests.
13. Third-Party Services
Dexterity integrates with third-party platforms, for example Microsoft Azure and related APIs.
We are not responsible for:
- third-party privacy practices;
- external systems outside our control.
Customers should review third-party policies.
14. Children’s Privacy
Dexterity is a business product and is not intended for individuals under 18.
We do not knowingly collect data from minors.
15. Legal Disclosures
We may disclose data:
- to comply with legal obligations;
- to enforce agreements;
- to protect rights, safety, or property.
We will notify you where legally permitted.
16. Updates to this Policy
We may update this Privacy Policy from time to time.
Changes become effective upon publication or upon notification. We encourage periodic review.
17. Contact Information
For privacy-related inquiries, contact De BI Controller B.V. via the contact form.
18. Additional Regional Rights (Summary)
EU/EEA
Full GDPR rights apply, including the right to lodge a complaint with your local supervisory authority.
United States
Rights may include access, deletion, and opt-out, depending on state law.
We will comply with applicable laws based on your location.
19. Subprocessors
We may use subprocessors, for example cloud providers, to deliver the Services.
A list of subprocessors is available upon request.
20. Data Processing Role
For data processed through Dexterity:
- Customer = Data Controller;
- Vendor = Data Processor.
This processing is set out in more detail in the Data Processing Agreement (DPA) below.
Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions (“Agreement”) between:
De BI Controller B.V. (“Processor”, “Vendor”, “we”, “us”),
and
Customer (“Controller”, “you”).
This DPA applies whenever Vendor processes Personal Data on behalf of Customer in connection with the Dexterity Services.
1. Definitions
For the purposes of this DPA:
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on Personal Data (e.g. collection, storage, transfer).
- “Controller” is the entity that determines the purposes and means of the processing.
- “Processor” is the entity that processes Personal Data on behalf of the Controller.
- “GDPR” means Regulation (EU) 2016/679.
2. Scope and Roles
2.1 Customer acts as Controller.
2.2 De BI Controller B.V. acts as Processor.
2.3 This DPA applies to Personal Data processed via:
- data replication from Microsoft Dynamics 365 Business Central;
- API integrations;
- hosting environments (managed by Vendor or Customer).
3. Subject Matter and Duration
3.1 Subject Matter
Processing necessary to deliver the Dexterity Services, including data replication, storage, and synchronization.
3.2 Duration
Processing lasts for the duration of the Agreement and until Personal Data is deleted or returned.
4. Nature and Purpose of Processing
Processing includes:
- extraction of data from Business Central;
- transformation and replication to Azure SQL or Fabric SQL;
- storage and synchronization;
- system monitoring, logging, and support.
5. Categories of Data and Data Subjects
5.1 Categories of Data
May include:
- business data (financial, transactional);
- contact information (names, email addresses, job titles);
- any Personal Data contained within Customer’s systems.
5.2 Data Subjects
May include:
- Customer’s employees;
- end customers;
- suppliers and business contacts.
6. Processor Obligations
Vendor will:
- process Personal Data only on documented instructions from Customer;
- ensure staff are bound by confidentiality obligations;
- implement appropriate technical and organizational measures;
- not sell Personal Data or use it for its own purposes;
- assist Customer with GDPR compliance obligations.
7. Security Measures
Vendor implements appropriate security measures, including:
- encryption in transit (TLS);
- access control and authentication mechanisms;
- logging and monitoring;
- secure cloud infrastructure (Microsoft Azure);
- regular security updates and patches.
Customer acknowledges that no system is completely secure.
8. Sub-processors
8.1 Vendor may engage sub-processors to deliver the Services (e.g. cloud providers).
8.2 Vendor will:
- ensure sub-processors are bound by equivalent data protection obligations;
- remain liable for the performance of sub-processors.
8.3 A list of sub-processors is available upon request.
9. International Transfers
Where Personal Data is transferred outside the EEA, Vendor ensures appropriate safeguards, including:
- Standard Contractual Clauses (SCCs);
- adequacy decisions;
- other lawful transfer mechanisms.
10. Assistance to the Controller
Vendor will assist Customer with:
- responding to data subject requests;
- carrying out data protection impact assessments (DPIAs);
- consulting supervisory authorities where required.
To the extent reasonably possible and proportionate.
11. Data Subject Rights
Vendor will:
- notify Customer of any request received directly;
- not respond without Customer’s consent, unless legally required.
Customer remains responsible for handling such requests.
12. Data Breach Notification
Vendor will:
- notify Customer without undue delay after becoming aware of a Personal Data breach;
- provide relevant information to help Customer meet its legal obligations.
13. Data Retention and Deletion
Following termination of the Agreement:
- Personal Data is deleted or returned at Customer’s request;
- data may be retained where legally required;
- backup data is deleted in accordance with standard retention cycles.
14. Audit Rights
Customer may request information demonstrating compliance.
Formal audits:
- must be reasonable and must not disrupt business operations;
- are limited to once per year at most;
- may be subject to confidentiality obligations.
15. Customer Responsibilities
Customer ensures that it:
- has a lawful basis for processing Personal Data;
- provides the necessary notices and obtains consents;
- configures systems and access appropriately;
- does not process unlawful or sensitive data without appropriate safeguards.
16. Liability
Liability under this DPA is subject to the limitations set out in the main agreement (Terms and Conditions).
17. Governing Law
This DPA is governed by the law of the Netherlands.
18. Order of Precedence
In the event of a conflict, the following order of precedence applies:
- This Data Processing Agreement (DPA)
- The Terms and Conditions (EULA)
19. Contact
Annex I — Processing Details
Overview of processing activities
- Subject matter: Data replication and integration services
- Duration: Duration of the Agreement
- Nature: Collection, storage, transfer, synchronization
- Purpose: Delivery of Dexterity Services
Annex II — Technical and Organizational Measures
Security measures implemented
- Role-based access control (RBAC)
- Encryption (in transit and at rest where applicable)
- Secure cloud hosting (Azure)
- Logging and monitoring systems
- Incident response procedures
- Regular software updates
Annex III — Sub-processors
Current sub-processors
- Microsoft Azure (cloud infrastructure)
The full list is available upon request.