Last updated: September 19, 2026
Privacy tools in CustomerGate 365
CustomerGate 365 handles personal data of your website visitors and customers inside your own Business Central environment, with your company as the controller. This page covers the tools the app gives you for that: the retention period and the cleanup job, and export and erasure per e-mail address.
What is stored
- Quote requests and their lines: name, company, e-mail, phone, addresses, VAT number, customer reference, free text and an IP hash.
- Account requests: the same, plus the job title and the stated customer number.
- Portal users: e-mail address, name and last sign-in.
- Sign-in codes and portal sessions: e-mail address and IP hash. Codes and tokens are stored only as hashes.
- Quote acceptances: the e-mail address and IP hash of the person who accepted.
The IP hash is made by the website with a secret key. It is pseudonymized personal data, not anonymous data. The app registers all these fields as personal data in Business Central's data classification.
Retention and cleanup
Retention Period (Days) on CustomerGate Setup sets how long personal data is kept, counted from the day a request was received. Every night at 02:00, the cleanup job then anonymizes:
- Quote requests in every status, including the text copied to the sales quote at conversion. Number, status, dates, country and the quote number stay, so the link to the sales document is kept. A request that is still New or In Progress becomes Rejected.
- Account requests in every status.
- Quote acceptances: the e-mail address and the IP hash. The acceptance itself stays, because it records a commercial commitment.
- Portal users that have been deactivated for longer than the retention period. An active portal user is never erased.
Expired sign-in codes are deleted a day after they expire, and expired sessions after thirty days. Each item is cleaned on its own, so one that fails does not stop the rest; failed steps are retried the next night and shown on CustomerGate Setup. Posted documents cannot be changed: when request text has reached one, the request records that with Cleanup Incomplete.
Keeping the cleanup running
- The cleanup job is installed on hold. Turn it on with Turn On Both Jobs once the retention period is right.
- Awaiting Cleanup on CustomerGate Setup and the retention cues on the Role Center count requests past the retention period that still hold personal data. They should be zero.
- Cleanup Disabled stops all erasure. Use it only briefly, for a test.
- Clean Up Personal Data Now runs a round straight away.
Export per e-mail address (GDPR articles 15 and 20)
Export Personal Data, on Web Requests, Account Requests and Portal Users, creates one JSON file with every row the app holds for the e-mail address: quote requests with their lines, account requests, portal users, sign-in codes, portal sessions and quote acceptances. The hashes and salts of codes and tokens are left out.
Erasure per e-mail address (GDPR article 17)
Erase Personal Data erases everything for one e-mail address: its quote requests and their text on sales quotes, account requests, portal users, sign-in codes, sessions and quote acceptances. Numbers, dates, the chosen customer and who reviewed stay, and an acceptance keeps its quote and date. It refuses while the address still has an active portal user, so deactivate first. It runs only from the Business Central client, after a confirmation.
Copies of sent e-mails
Business Central keeps every sent message in Sent Email, including request details and sign-in codes, and the cleanup does not reach it. Set a retention policy for Sent Email on the Retention Policies page, equal to the CustomerGate retention period (the minimum there is seven days); Business Central then cleans up the messages itself.
Telemetry
Once telemetry is enabled, the app sends Van Oosten Software technical telemetry: which feature ran and with what outcome, with counts and kinds only. It never contains e-mail addresses, names, customer numbers, document numbers or error texts. The privacy statement for the app has the details.
Related help
- CustomerGate Setup
Every setting and status line on the setup page.
- Portal Users
Who may see which customer's data, and revoking that access.
- Privacy statement for the app
What the app does with personal data, and who is responsible for it.