Document

Privacy Policy

Last updated: September 20, 2026

Source365 is operated by Module One in Finland. This policy explains what data the Outlook add-in processes, why it is needed, how long it is retained, and how you can exercise your rights.

1. Controller and Contact

Module One (Business ID 2670055-8), Killingholmsstråket 5, 68600 Pietarsaari, Finland, operates Source365 and is the controller for account, billing, support, and service-usage data processed through the service. Privacy and data-protection questions can be sent to hello@source365.io.

2. Information We Process

  • Microsoft account details such as your name, email address, and Microsoft account identifier.
  • Microsoft OAuth tokens needed to keep your authorized mailbox connection working.
  • Email content and attachments that you deliberately ask Source365 to analyse.
  • Extracted product requirements, supplier-search results, drafts, sending records, and reply-tracking metadata.
  • Your saved automation choices, including follow-up timing, maximum attempts, templates, and clarification auto-send status.
  • Subscription, invoicing, and payment-status information received from Stripe.
  • Security, reliability, and diagnostic events needed to operate and protect the service.

3. How and Why We Use Data

  • To authenticate users and maintain secure sessions.
  • To analyse procurement emails and attachments at the user’s request.
  • To discover, rank, and present potential suppliers.
  • To draft, send, and track initial outreach through Microsoft Graph after the user has reviewed the recipients and message.
  • To send follow-ups or eligible clarification replies only when the user has explicitly enabled the relevant automation setting. These settings can be disabled at any time.
  • To administer subscriptions, credits, billing, support, fraud prevention, and service security.
  • To comply with legal obligations and enforce the Terms of Service.

Processing is based primarily on performing the service requested by the user or customer, legitimate interests in operating and securing the service, and legal obligations. Where consent is required, it is requested separately.

4. Microsoft Mailbox Access

The Outlook add-in manifest uses the least-privilege ReadItem permission to work with the currently open message. Broader mailbox reading and email sending are performed through Microsoft Graph only after an explicit Microsoft OAuth consent flow. Source365 requests Mail.Read and Mail.Send for these features and does not request access to Microsoft mailbox settings. Users can sign out directly from the Outlook taskpane, revoke Source365 access from their Microsoft account, and disable email automations from Source365 settings.

5. Service Providers

  • Microsoft Entra ID and Microsoft Graph: Authentication, mailbox access, and email sending.
  • Supabase: EU-hosted PostgreSQL infrastructure.
  • Vercel: Application hosting and server-side execution.
  • OpenAI: AI-assisted email analysis, categorisation, drafting, and supplier-search workflows.
  • Mistral AI: OCR extraction from supported scanned documents when needed.
  • Serper: Web-search results used to discover potential suppliers.
  • Stripe: Subscription and payment processing.
  • Resend: Transactional service email delivery.
  • Upstash: Caching, rate limiting, and short-lived workflow state.
  • Inngest: Background workflow orchestration.
  • Sentry: Error and reliability monitoring with data minimisation.
  • Google Ads: Optional advertising measurement, only after you allow measurement cookies. Advertising personalization is disabled.
  • LinkedIn: Optional advertising measurement, website audience insights, and advertising, only after you allow measurement cookies.

Providers receive only the information needed for their role. Depending on provider location and configuration, data may be processed outside the European Economic Area subject to applicable contractual and technical safeguards.

6. Security

Traffic is encrypted in transit using TLS. Microsoft OAuth tokens are encrypted at rest using AES-256-GCM. Source365 application tables are accessed through a server-side PostgreSQL connection; direct anonymous or authenticated Supabase Data API access to those tables is disabled, and row level security is enabled as defense in depth. Access is restricted to personnel and systems that need it to operate the service.

7. Retention and Deletion

Search sessions and their related supplier results, attachments, drafts, sent-email records, and quote data are automatically deleted after 90 days. Processed Stripe webhook records are also deleted after 90 days. Account and subscription records are retained while the account remains active and for any additional period required for legal, accounting, fraud-prevention, or dispute purposes. Provider backups expire according to the relevant provider’s backup lifecycle.

8. Your Rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection regarding your personal data. You may also lodge a complaint with the Office of the Data Protection Ombudsman in Finland. Send requests to hello@source365.io. We may need to verify your identity before completing a request.

9. Optional Advertising Measurement

We ask before loading Google Ads or LinkedIn measurement on the website. If you allow it, these providers may process advertising click identifiers, page addresses, cookie identifiers, website actions, and technical information such as your IP address, browser, and visit time. A Marketplace link click indicates intent, not completed installation. The LinkedIn Insight Tag runs only on selected public pages; it does not run inside Outlook or on account, billing, admin, or onboarding pages. Separately configured conversion pixels may report a completed website registration or installation-link click using an opaque event identifier. We do not include mailbox content, attachments, supplier records, account names, or email addresses in these measurement events, and do not send email addresses for enhanced matching. Google advertising personalization is disabled. LinkedIn may use visit data for audience insights, ad relevance, and personalized advertising according to its policies and your LinkedIn settings.

Source365 also records consented first-party conversion steps, such as opening the preview, starting setup and completing the first analysis. The browser session ID expires after 24 hours; attribution records and cohort memberships expire within 35 days. New-account, add-in-opened and first-analysis milestones are confirmed by the server, not inferred from clicks. These events contain no RFQ text, supplier details or email addresses. Withdrawing permission removes the available session attribution.

Your choice is stored for up to 180 days. Google attribution cookies are configured for up to 90 days, and a registration receipt expires after 30 minutes. LinkedIn cookie lifetimes and retention are described in its Cookie Policy. You can withdraw consent using Privacy choices; this clears accessible advertising cookies on our domain and reloads the page to stop the tags. We cannot delete cookies on another provider’s domain. Rejecting optional cookies does not affect the service. See Google Business Data Responsibility and the LinkedIn Privacy Policy for provider processing details.

10. Changes to This Policy

We may update this policy when the service, providers, or legal requirements change. The current version and its update date are always published on this page.

11. Contact

Source365 / Module One, Killingholmsstråket 5, 68600 Pietarsaari, Finland — hello@source365.io.