Last updated: October 6, 2026
Zentriq Software (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use Zentriq Agent for Microsoft Dynamics 365 Business Central, Zentriq Connect (which links your own AI assistant, such as Claude or ChatGPT, to Business Central), Zentriq Capture and Zentriq Core (Business Central extensions that bring the vendor documents emailed to your company’s capture address into Business Central), the Zentriq web dashboard, and the Zentriq PunchOut Chrome extension (collectively, the “Services”).
We comply with the Swiss Federal Act on Data Protection (nFADP), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws.
The data controller is:
When you sign in via Microsoft Entra ID, we receive:
When you capture a cart, the Chrome extension sends the page content to our AI parsing service. This data is:
When you interact with the Zentriq Agent chat embedded in Business Central, the following data flows occur:
Sent to our backend (zentriqsoftware.com):
Sent to Anthropic (Claude):
What is NOT sent:
Storage and retention: Conversation history is stored in our PostgreSQL database (EU region) so you can resume past conversations. Conversations are retained until you delete them or close your account. You may request deletion at any time via privacy@zentriqsoftware.com.
Zentriq Connect lets you link your own AI assistant, such as Claude (Anthropic) or ChatGPT (OpenAI), to your Business Central through the Model Context Protocol (MCP), using Zentriq’s safe tools. This data flow differs from the Zentriq Agent (§3.3) in one important way, which we state plainly:
Where the reasoning happens. With the Zentriq Agent, AI inference runs on our own EU infrastructure (§5). With Zentriq Connect, the reasoning is performed by your AI assistant. Any Business Central data your assistant reads through Connect is therefore transmitted to your AI provider (Anthropic for Claude, OpenAI for ChatGPT) and processed under the agreement you have with that provider, not under Zentriq’s subprocessor agreements. We host and operate Connect in the EU, but we are not the data controller for, and do not control, the processing your AI provider performs on your instructions.
What Zentriq does on this path:
What we do NOT do on this path:
Your controls. The connection is scoped to the Business Central environment and company you choose when you authorize it, inherits exactly the permissions of the account that authorized it, and is revocable at any time from your dashboard (Connect page → Disconnect), which stops all connected assistants immediately.
Zentriq Capture reads the documents emailed to your company’s capture address (an address at in.zentriqsoftware.com), such as vendor invoices and credit memos, and places them in the Zentriq Document Journal in Business Central, where your users check and register them. It works with Zentriq Core, which Business Central installs with it. The following data flows occur:
Received by our backend (zentriqsoftware.com):
Read from the documents: the vendor’s name, VAT number and IBAN, the document type, number, dates and payment terms, the purchase order number, the currency, the totals and VAT, the lines (article code, description, quantity, unit, price, discount and VAT), and the payment data of a Swiss QR-bill (account, reference, amount, payee and message). Electronic invoices (UBL, CII, Factur-X) are read from their XML without an AI model. Other documents are read by an AI model from their text and, where needed, from images of their pages.
Read from your Business Central to match each document, through the connection an owner or admin of your organization made from the Zentriq dashboard:
Of this data, our backend keeps only what was matched to each document (the vendor, the items or accounts, and the purchase order figures of its lines), in the record described under Storage and retention below.
Written to your Business Central: each document as an entry in the Zentriq Document Journal, with the data read and matched and a link from which your Business Central downloads the file, and the capture address of each inbox.
What stays in your Business Central: Register creates the purchase invoice or credit memo in your Business Central and attaches the file to it. These documents, and what Zentriq Capture learns from your choices (line translations, vendor names, vendor profiles), are stored in your Business Central and remain under your control. Our backend does not receive the documents created at Register.
Usage records: for each document read we record the date, the number of pages, the document type, the file name and the vendor name read. They count documents and pages against your organization’s credits and monthly page allowance, and Zentriq Core shows the monthly totals in Business Central.
Purposes: we use this data to read each document and place it, matched to your Business Central data, in your journal; to recognize the Business Central company that installed Zentriq Core, so that we can approve it and allocate its capture address; to count documents and pages for billing; and to retry and investigate documents that could not be processed. When a document cannot be processed, an error entry is written in your journal and Zentriq staff receive a notice with the sender, subject and file name.
Where it is processed:
Storage and retention: The files received are kept in our file storage until you ask us to delete them; they are not deleted automatically, including when your account or your organization’s account is deleted. The record of each document received (sender, subject, file name, processing status, and the data read and matched) and the usage records are kept while your account is active and are deleted with your organization’s account. The registration data sent by Zentriq Core is kept after a company disconnects, so that the same installation is recognized if it connects again, and is deleted on request. Data written to your Business Central stays there until you delete it. You may request deletion at any time via privacy@zentriqsoftware.com.
We collect anonymous usage metrics (page views, feature usage, error rates) to improve our services. No personal data is included in analytics.
We rely on the following subprocessors to deliver the Services. Each is bound by a data processing agreement and processes personal data only on our instructions.
| Subprocessor | Purpose | Used by | Region |
|---|---|---|---|
| Microsoft (Entra ID) | Sign-in & identity | Agent, PunchOut, Connect & Capture | EU / global (per Microsoft tenant) |
| Microsoft (Dynamics 365 Business Central) | ERP data source via delegated OAuth (never relocated) | Agent, PunchOut, Connect & Capture | Your BC tenant region |
| Amazon Web Services (Bedrock), running Anthropic’s Claude | AI inference; not used for training | Agent, PunchOut & Capture | EU (sent to Frankfurt, processed in EU regions) |
| Stripe | Payments & subscriptions | Agent, PunchOut & Capture | EU / US |
| Vercel | Application hosting | Agent, PunchOut, Connect & Capture | EU (Frankfurt + Paris) |
| Vercel Blob | Document / file storage (Zentriq Capture, Agent document uploads) | Agent & Capture | EU |
| Neon | PostgreSQL database (accounts, billing, conversation history, connector tokens, Capture processing and usage records) | Agent, PunchOut, Connect & Capture | EU (Frankfurt) |
| Resend | Transactional email; receiving the emails sent to Capture addresses | Agent, PunchOut, Connect & Capture | EU / US |
| Sentry | Error & performance monitoring | Agent, PunchOut, Connect & Capture | EU (Frankfurt) |
| FirstPromoter | Affiliate / referral tracking (marketing website only) | Website visitors | EU / US |
Zentriq Connect: your AI provider is not our subprocessor. When you use Zentriq Connect (§3.4), the AI provider that reasons over your data is the one you choose, Anthropic (Claude) or OpenAI (ChatGPT), acting under your own agreement with that provider. In that role they are a recipient determined by you, not a Zentriq subprocessor, and their data-residency and retention terms are those of your own account with them. The subprocessors listed above (Microsoft, Vercel, Neon) support Connect only for sign-in, tool execution against your Business Central, hashed-token storage, and activity metadata, all in the EU.
For a Data Processing Agreement (DPA) and the current subprocessor list, see our Data Processing Agreement.
We retain account data for the duration of your account. Cart data is processed in real-time and not retained. Usage logs are retained for 90 days. Zentriq Capture data, including its usage records, is kept as described in section 3.5. Zentriq Connect authorizations (hashed tokens) are retained until you revoke them or disconnect; expired tokens are purged automatically. You can request account deletion at any time, which also deletes your connector authorizations.
Under GDPR and nFADP, you have the right to:
To exercise your rights, email privacy@zentriqsoftware.com.
We use essential cookies required for authentication and session management. With your consent, our public marketing website also sets non-essential cookies: an affiliate-referral cookie (FirstPromoter's _fprom_tid, used to attribute sign-ups to partners) and anonymous usage analytics (Vercel Analytics). These non-essential cookies are only set after you accept them in our cookie banner, and you can withdraw consent at any time using the “Cookie settings” link in the footer. We do not use advertising cookies and do not sell your data.
We implement industry-standard security measures including TLS encryption in transit, encrypted storage at rest, regular security audits, and access controls.
We may update this policy periodically. Significant changes will be communicated via email or in-app notification. Continued use of our Services constitutes acceptance of the updated policy.
For privacy-related inquiries, contact us at privacy@zentriqsoftware.com.