This policy explains what data Schedrix™ Production Sequencing for Microsoft Dynamics 365 Business Central (the app) and the Schedrix service behind it collect, why, where the data is kept and for how long. Capability Systems Ltd publishes the app and runs the service.
Who we are
Capability Systems Ltd, a company registered in England and Wales (company number 03060219), 128 City Road, London EC1V 2NX.
For anything about this policy or your data, email privacy@capability-systems.com.
What the app sends to the Schedrix service
The app runs inside your Business Central tenant. It sends data to the Schedrix service only after an administrator has agreed to the Schedrix privacy notice in Business Central, and only when a user chooses an action that needs the service.
With every call, the app sends your Business Central tenant's ID and the name of the environment, and, once you have one, your tenant key.
To work out a sequence, it sends the production data the sequence needs:
- the item numbers of the orders in the planning window, with each item's allergens and changeover family;
- each order's run time, current line, current position and due date;
- the lines' numbers, their working minutes per day and the item each line last ran;
- the changeover times between items, worked out from your confirmed rules.
To read a changeover rule written in plain English, it sends the rule's text, with the allergens and families your items use. To work out the changeover times, it sends your confirmed rules as structured settings, with no rule text, and each item's number with its allergens and changeover family.
To read a disruption you report in plain English, it sends the sentence you write, the current time, and the numbers and names of the lines in the resource pool.
To register for a tenant key, it sends the email address and company name entered in the Set up Schedrix wizard.
The app doesn't send customer names, vendor names, prices, costs or personal data about your staff, other than the email address of the person who registers, and anything a user types into a rule or a disruption report.
What the service keeps, and for how long
Everything the service keeps is stored in Microsoft Azure in the UK South region, encrypted at rest.
- The data for a sequence is stored while the sequence is worked out, and the sequence is stored until Business Central collects it. Both are deleted by the time it is collected, and in any case within about two days.
- Rules and disruption reports are processed in memory and not stored.
- The tenant key record holds your tenant ID as a one-way digest, a digest of the key, the company name entered when registering, and a digest of the administrator's email address. It is replaced when you register again, and kept until you ask us to delete it. Uninstalling the app doesn't delete it: email privacy@capability-systems.com.
- A registration in progress holds the same digests, the company name, a digest of the emailed code and how many codes were sent. It is deleted within about two days.
- Service logs hold the time of each request, a shortened digest of the tenant ID, counts, timings and outcomes. They hold no product data, rule text or email addresses. They are kept for 90 days.
Your IP address is used, in memory only, to limit how often a registration can be tried. It may also appear in the service's request logs, which are kept for 90 days.
Who else processes the data
- Microsoft Azure hosts the service and its storage, in the UK South region.
- Anthropic provides the AI model (Claude) that reads rules and disruption reports written in plain English. For a rule, it receives the rule's text, the list of the 14 UK allergens, and the allergen and family names of yours that appear in the text. For a disruption, it receives the sentence, the current time and the numbers and names of the pool's lines. Anthropic doesn't use data sent through its API to train its models, and deletes it within 30 days, unless its safety systems flag it, in which case it may keep it for up to two years. Anthropic processes the data in the United States.
- Resend sends the email with the registration code. It receives the email address, the code and your tenant ID. The email is sent from Ireland; Resend keeps its records of it in the United States.
- Sentry receives error reports from the service, and a performance record of each request. They hold the address of the request, the environment name, timings and technical details, but not the content of the request, your tenant ID or your tenant key. They are stored in Sentry's EU region, in Frankfurt, and kept for up to 90 days.
Where data leaves the UK, it is protected by the safeguards UK data protection law requires, such as the UK International Data Transfer Addendum.
We don't sell data, and we don't use your production data for anything other than giving you the sequence or the answer you asked for.
Our role and the legal basis
For the production data, rules and disruption reports your users send, Capability Systems processes the data on your behalf, to provide the service. For the registration email address and company name, Capability Systems decides how they are used, to issue and secure your tenant key, on the basis of the contract with you and our legitimate interest in preventing misuse of the service.
Your rights
Under UK data protection law you can ask for a copy of personal data we hold about you, and ask us to correct or delete it. Email privacy@capability-systems.com. If you aren't satisfied with our answer, you can complain to the Information Commissioner's Office (ico.org.uk).
Turning it off
An administrator can stop the app sending data at any time: disagree to the Schedrix privacy notice on the Privacy Notices page in Business Central, or uninstall the app. Sequence data the service already holds is deleted as described above. To have the tenant key record deleted too, email privacy@capability-systems.com.
Changes to this policy
When this policy changes, we update the date at the top of this page. If a change affects what data the app sends or how long the service keeps it, we say so in the app's release notes.