PRIVACY · LAST UPDATED 28 SEPTEMBER 2026
Privacy Notice
This notice explains how D365ext handles personal data when you use the website, account portal and Chrome extension.
1. Controller and contact
D365ext is operated by Totoescu Dan-Paul, based in Romania (trading as “D365ext”). We are the data controller for account, licensing, support and website data described here. For privacy requests, email support@d365ext.com. Paddle is the Merchant of Record for purchases and handles payment information under its own privacy terms.
2. Data, purposes and legal bases
- Account and licensing: email address, name if provided, account identifier, password authentication data managed by our authentication provider, license key, trial dates and subscription status. We use these to create your account, provide the 7-day trial, verify your license and manage access. Legal basis: performance of our contract.
- Support: messages and any details you send us, used to respond to requests and resolve issues. Legal basis: contract performance or our legitimate interest in providing support.
- Technical and security data: IP address, device/browser information, access and error logs where collected by our website or hosting providers. We use these to deliver the site, prevent abuse and diagnose failures. Legal basis: legitimate interests in reliability and security.
- Purchase status: Paddle customer and subscription identifiers, plan and renewal status shared with us to activate access and maintain records. Legal basis: contract performance and, where applicable, legal obligations. Paddle collects and processes card details directly; we do not receive full payment card numbers.
The extension is designed to send data you choose to capture directly from your browser to your organization’s Dynamics 365 instance. D365ext does not intentionally store those CRM records in its account database. Your organization may independently control the data in its Dynamics 365 instance.
Anonymous usage statistics: the extension may send anonymous counts of actions, limited to the standard record type (for example “contact”; custom types are reported only as “custom”), where the action started (such as form or grid) and the result (such as success or error). These are combined into daily totals. They contain no CRM content, record IDs, URLs, organization names, license keys, account identifiers or IP addresses, and cannot be linked to you. We use them to understand reliability and improve the extension. You can turn this off in the extension settings.
3. Sharing
We share data only as needed with hosting, authentication, security and support service providers; Paddle as Merchant of Record for sales, subscription management, payments, tax and invoices; professional advisers such as accountants or legal counsel; and authorities when required by law. These recipients receive only data relevant to their role.
4. Retention and security
We keep account and license information while your account is active and afterwards only as needed for legal, accounting, dispute or security purposes. Support messages and technical logs are kept only as long as reasonably needed for those purposes, then deleted or anonymized. We use appropriate technical and organizational safeguards, including encrypted connections and access controls. No online system can guarantee absolute security.
5. International transfers
Our providers may process information outside Romania or the EEA. Where required, we rely on an adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses. Contact us for information about safeguards applicable to your data.
6. Your rights
Under the GDPR, you can request access, correction, deletion, restriction, portability or object to processing where applicable. If processing relies on consent, you may withdraw it at any time without affecting earlier processing. Email support@d365ext.com to make a request. We normally respond within one month; certain requests may be subject to legal exceptions. You may also complain to the Romanian supervisory authority (ANSPDCP) or your local EEA data protection authority.
7. Cookies and local storage
The website uses essential session cookies or browser storage to keep you signed in and remember settings. Paddle checkout may use its own essential cookies for payment and fraud prevention; see Paddle’s privacy information at checkout. We do not currently describe optional analytics or marketing cookies as part of the D365ext site. You can manage or clear cookies in your browser settings, though blocking essential storage may prevent sign-in. If we introduce non-essential cookies, we will update this notice and request consent where required.