Skip to content
Van Oosten Advies B.V.

Last updated: September 19, 2026

CustomerGate 365: privacy statement

This statement is about the CustomerGate 365 app in Microsoft Dynamics 365 Business Central, published by Van Oosten Software. It is written for the Business Central customer that uses the app. This website has its own separate privacy statement, linked at the bottom of every page.

The short version

The app processes personal data of your website visitors and customers, inside your own Business Central environment. You are the controller for that data. Van Oosten Software has no access to your environment and receives no copy of the data, only technical telemetry that contains no personal data.

What personal data the app processes

Of the visitors and customers who use your website, the app stores:

  1. Name, company name, e-mail address, phone number, address and VAT number.
  2. The content of quote requests and account requests, including the requested lines and comments.
  3. Which quote a customer accepted through the portal, and when.
  4. A pseudonymized hash of the IP address, made by the website, and never the address itself.
  5. Sign-in and session timestamps for the customer portal.

Who is responsible

You, the Business Central customer, are the controller for this data: you decide what your website asks for, why, and how long it is kept, and you inform your visitors in the privacy statement on your own website. Van Oosten Software supplies the app but does not process this data on your behalf through it. If Van Oosten Software also builds or hosts your website, that is covered by a separate agreement, including a data processing agreement, and not by this statement.

Where the data stays

In your own Business Central environment, at Microsoft, under the terms and the geography you agreed with Microsoft. E-mails go out through your own Business Central e-mail accounts. Van Oosten Software has no access to your environment and receives no copy of your data.

How the app protects it

  1. Every field carries a data classification.
  2. Sign-in codes and session tokens are stored only as hashes.
  3. IP addresses are stored only as a pseudonymized hash.
  4. The website connects through Microsoft Entra application registrations with narrow permission sets, execute-only where possible and without D365 BASIC.
  5. Portal sessions expire when unused and have a maximum age, and revoking access works immediately.

Telemetry

Once telemetry is enabled for CustomerGate 365, Van Oosten Software receives technical telemetry through Azure Application Insights, stored in the European Union. It records which feature ran and with what outcome: requests received, documents created, e-mail sent or not, cleanup runs, sign-ins that succeeded or failed, quote acceptances, permission repairs and a completed setup, with counts and kinds only. It never contains e-mail addresses, names, customer numbers, document numbers or error texts.

Sub-processors

For the telemetry: Microsoft, as the provider of Business Central and of Azure Application Insights. Nobody else.

How long data is kept

You decide. The retention period is set on the CustomerGate Setup page, and once it has passed the cleanup job anonymizes the request. Telemetry is kept for at most 90 days.

Rights of the people involved

Your website visitors and customers exercise their rights with you, as the controller. The app helps you answer them: Export Personal Data creates one file with all personal data the app holds for an e-mail address (GDPR articles 15 and 20), and Erase Personal Data erases it. Questions about the app itself can be sent to info@van-oosten.nl.

Who we are

Van Oosten Software, a trade name of Van Oosten Advies B.V., Wilgestraat 40, 4431 CH 's-Gravenpolder, the Netherlands. Chamber of Commerce 42077708, VAT number NL869603504B01. Email info@van-oosten.nl.