Document

Privacy Policy

Last updated: July 31, 2026

Source365 is operated by Nordic Valves Ab Oy in Finland. This policy explains what data the Outlook add-in processes, why it is needed, how long it is retained, and how you can exercise your rights.

1. Controller and Contact

Nordic Valves Ab Oy (Business ID 3341050-8), Mästasvägen 6, 68600 Pietarsaari, Finland, operates Source365 and is the controller for account, billing, support, and service-usage data processed through the service. Privacy and data-protection questions can be sent to hello@source365.io.

2. Information We Process

  • Microsoft account details such as your name, email address, and Microsoft account identifier.
  • Microsoft OAuth tokens needed to keep your authorized mailbox connection working.
  • Email content and attachments that you deliberately ask Source365 to analyse.
  • Extracted product requirements, supplier-search results, drafts, sending records, and reply-tracking metadata.
  • Your saved automation choices, including follow-up timing, maximum attempts, templates, and clarification auto-send status.
  • Subscription, invoicing, and payment-status information received from Stripe.
  • Security, reliability, and diagnostic events needed to operate and protect the service.

3. How and Why We Use Data

  • To authenticate users and maintain secure sessions.
  • To analyse procurement emails and attachments at the user’s request.
  • To discover, rank, and present potential suppliers.
  • To draft, send, and track initial outreach through Microsoft Graph after the user has reviewed the recipients and message.
  • To send follow-ups or eligible clarification replies only when the user has explicitly enabled the relevant automation setting. These settings can be disabled at any time.
  • To administer subscriptions, credits, billing, support, fraud prevention, and service security.
  • To comply with legal obligations and enforce the Terms of Service.

Processing is based primarily on performing the service requested by the user or customer, legitimate interests in operating and securing the service, and legal obligations. Where consent is required, it is requested separately.

4. Microsoft Mailbox Access

The Outlook add-in manifest uses the least-privilege ReadItem permission to work with the currently open message. Broader mailbox reading and email sending are performed through Microsoft Graph only after an explicit Microsoft OAuth consent flow. Source365 requests Mail.Read and Mail.Send for these features and does not request access to Microsoft mailbox settings. Users can sign out directly from the Outlook taskpane, revoke Source365 access from their Microsoft account, and disable email automations from Source365 settings.

5. Service Providers

  • Microsoft Entra ID and Microsoft Graph: Authentication, mailbox access, and email sending.
  • Supabase: EU-hosted PostgreSQL infrastructure.
  • Vercel: Application hosting and server-side execution.
  • OpenAI: AI-assisted email analysis, categorisation, drafting, and supplier-search workflows.
  • Mistral AI: OCR extraction from supported scanned documents when needed.
  • Serper: Web-search results used to discover potential suppliers.
  • Stripe: Subscription and payment processing.
  • Resend: Transactional service email delivery.
  • Upstash: Caching, rate limiting, and short-lived workflow state.
  • Inngest: Background workflow orchestration.
  • Sentry: Error and reliability monitoring with data minimisation.

Providers receive only the information needed for their role. Depending on provider location and configuration, data may be processed outside the European Economic Area subject to applicable contractual and technical safeguards.

6. Security

Traffic is encrypted in transit using TLS. Microsoft OAuth tokens are encrypted at rest using AES-256-GCM. Source365 application tables are accessed through a server-side PostgreSQL connection; direct anonymous or authenticated Supabase Data API access to those tables is disabled, and row level security is enabled as defense in depth. Access is restricted to personnel and systems that need it to operate the service.

7. Retention and Deletion

Search sessions and their related supplier results, attachments, drafts, sent-email records, and quote data are automatically deleted after 90 days. Processed Stripe webhook records are also deleted after 90 days. Account and subscription records are retained while the account remains active and for any additional period required for legal, accounting, fraud-prevention, or dispute purposes. Provider backups expire according to the relevant provider’s backup lifecycle.

8. Your Rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection regarding your personal data. You may also lodge a complaint with the Office of the Data Protection Ombudsman in Finland. Send requests to hello@source365.io. We may need to verify your identity before completing a request.

9. Changes to This Policy

We may update this policy when the service, providers, or legal requirements change. The current version and its update date are always published on this page.

10. Contact

Source365 / Nordic Valves Ab Oy, Mästasvägen 6, 68600 Pietarsaari, Finland — hello@source365.io.