AutoFlow Logo
Solutions Use cases Connectors Pricing Partner
Login Get started
Deutsch English
Login Get started
AutoFlow Graphical editor Click triggers, steps and branches instead of programming them. External systems Call any API over HTTP and carry the response straight into the next step. Traceable runs Every step is in the log, with the values the decisions were made on. See all features
Solutions
AutoFlow Receive Turn inbound documents into Business Central records automatically AutoFlow Dispatch E-invoices in any format, through any channel ITscope2Dynamics Product data, prices and availability CreditSolution2Dynamics Credit reports on German business data SkyMinder2Dynamics Credit reports on international business data ElectronicSales2Dynamics Shop orders as documents, stock back into the shop Praxedo2DYCE Field service and ERP in one process
See all solutions
Use cases
Incomplete item master data Unbilled subscriptions Reordering at the reorder point File invoices to SharePoint automatically Service orders from your ticketing system
See all use cases
Connectors
Outlook SharePoint ITscope CRIF SkyMinder ElectronicSales
See all connectors
Not listed? Any system with an API AutoFlow talks to any system with an API — over an HTTP call, with nothing for us to build first.
Partner programme
BC partner For Microsoft partners with their own Business Central practice Set AutoFlow up in every project. After that the answer to the next small request is a flow rather than a PTE. Delivered faster, and with no maintenance debt waiting for you at the next upgrade. Automation expert For consultants who work with the people using BC Become a certified AutoFlow expert, build automations for Business Central users and earn from it, as an affiliate or as a listed reseller. No development team required.
Not sure yet? Both paths side by side The programmes are not mutually exclusive. The overview shows what they share and where they differ.

Privacy policy

This page describes what happens to your data on autoflow365.app — and nothing else. Everything beyond that is covered by the privacy policy of mse Software GmbH.

Last updated: 13 September 2026

The short version

This website sets no cookies of its own. Personal data arises essentially where every web server processes it: in the access logs. A single service goes beyond that — the LinkedIn Insight Tag — and it loads only if you agree in the cookie notice.

Without your agreement, data is transmitted to third parties in only two cases: when you start an embedded video (YouTube), and when you follow a link to another service. Both are described below.

What this policy covers

This policy applies to the website autoflow365.app. It does not apply to the AutoFlow portal (portal.autoflow365.app), the documentation, the apps obtained through Microsoft AppSource, our support channels, or www.mse365.de.

All of that — and the processing of your data in our business relationship generally — is covered by the privacy policy of mse Software GmbH. The controller is the same in both cases; the details are repeated here so that this page can be read on its own.

Controller

The controller for data processing on this website is:

Martin Wollenweber mse Software GmbH Rheinpromenade 13 40789 Monheim am Rhein, Germany Phone: +49 2173-99300-0 Email: privacy@mse365.de

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses or similar).

Data protection officer

We have appointed a data protection officer.

Marcel Felgenhauer Mprotect365 GmbH Nordstraße 17–21 04105 Leipzig, Germany Web: mprotect365.de Phone: +49 2173 99300-0 Email: privacy@mse365.de

What this website does not do

For completeness, because the absence of these services would otherwise be documented nowhere. autoflow365.app does not run:

  • Google Analytics, Google Tag Manager or any other analytics tool that sets cookies or recognises visitors
  • fonts, icons or scripts from third-party servers — everything is served from this domain
  • a contact form; getting in touch runs through email links
  • chat widgets, captchas or social media plugins

This is enforced technically by a content security policy that blocks connections to other servers. Exactly three are exempt: the video player, which loads only on a click, and the two LinkedIn addresses, which are not contacted at all before consent.

Hosting

This website is hosted as a static site on Microsoft Azure (Azure Static Web Apps) in the “West Europe” region (Netherlands). The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.

The host processes the data arising when these pages are retrieved — principally IP addresses and access logs — solely in order to deliver the site and on our instructions. The legal basis is our legitimate interest in the secure, fast and efficient provision of our online offering by a professional provider (Art. 6(1)(f) GDPR). A data processing agreement under Art. 28 GDPR is in place with the provider.

Microsoft Corporation is certified under the EU-US Data Privacy Framework. See the Microsoft privacy statement for details.

Server log files

The host automatically collects and stores information in server log files, which your browser transmits automatically. These are:

  • browser type and version
  • operating system used
  • referrer URL
  • host name of the accessing computer
  • time of the server request
  • IP address

This data is not merged with other sources. It is collected on the basis of Art. 6(1)(f) GDPR: we have a legitimate interest in the technically correct presentation and the security of this website.

Browser storage instead of cookies

This website sets no cookies of its own. It remembers three things in your browser's local storage so that it behaves on your next visit the way you left it:

  • af-lang — the language you chose (German or English)
  • af-nl — that you have already dismissed the newsletter prompt, so it does not reappear
  • af-consent — your answer to the cookie notice, so it does not reappear on every visit and so that we can demonstrate consent

These entries stay on your device, are never transmitted to us, and contain no identifier by which you could be recognised. They are strictly necessary for functions you requested within the meaning of § 25(2) no. 2 TDDDG (formerly TTDSG), so no consent is required. You can delete them at any time through your browser settings.

Contacting us by email or phone

This website has no contact form. If you contact us via one of the email links or by phone, your enquiry including all personal data arising from it (name, enquiry) is stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary for pre-contractual measures. In all other cases the processing rests on our legitimate interest in effectively handling enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) where this was requested; consent can be withdrawn at any time.

The data remains with us until you ask us to delete it, withdraw your consent, or the purpose for storing it no longer applies. Mandatory statutory provisions — in particular retention periods — remain unaffected.

Newsletter

If you would like to receive the newsletter, we require an email address from you plus information allowing us to verify that you are the owner of the address given and consent to receiving it. No further data is collected, or only on a voluntary basis.

We use Brevo for sending. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. The data entered for the purpose of subscribing is stored on servers in Germany. Brevo allows newsletter campaigns to be analysed — for example whether a message was opened and which links were clicked. If you do not want this, you have to unsubscribe; every message contains an unsubscribe link.

The signup form transmits your entry directly to Brevo, with no intermediate step on our servers. Your IP address is disclosed to Sendinblue GmbH in the process. Subscribing runs as a double opt-in: after submitting you receive an email with a confirmation link, and only when you click it do we add you to the list. If you do not click, nothing happens.

Processing takes place on the basis of your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time; the lawfulness of processing already carried out is unaffected. Your data is stored until you unsubscribe and deleted afterwards; the email address may remain on a suppression list where necessary to prevent future mailings. A data processing agreement is in place with the provider.

Applications and enquiries submitted through forms

If you apply or make an enquiry through a form on this website, we process the details you give: first name, last name, email address, phone number and company, along with your answers to the questions that follow. We use them to deal with your request and to get in touch with you.

Your details are transmitted as soon as you complete the first step of the form. The answers to the questions that follow are added to the record already created. If you leave the form after that, the details transmitted up to that point remain stored.

Along with your details we store which page you opened the form from and which campaign parameters were in the address at the time. This tells us which content leads to an enquiry.

The legal basis is Art. 6(1)(b) GDPR where your enquiry is aimed at entering into or performing a contract. In all other cases processing rests on our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). The data remains with us until you ask us to delete it or the purpose for storing it no longer applies. Mandatory statutory provisions, in particular retention periods, remain unaffected.

Orders placed through the order form

If you order through the order form, we process the details of both companies named, that is company name, address, VAT ID, website, and the name, email address and phone number of the respective contacts, along with the items ordered, the totals, and the details of the person signing: first name, last name, position and place. We use them to fulfil the order, to invoice it and to get in touch with you.

The details are transmitted only when you submit the order. They pass through an interface we operate on Microsoft Azure (Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) and from there into our ERP system. We send the confirmation of your order through Brevo, provider Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany; delivering that single message is the only purpose, and it does not add you to any mailing list.

The legal basis is Art. 6(1)(b) GDPR, since the processing is necessary to enter into and perform the contract. Order and invoice data is subject to the commercial and tax retention periods of §§ 257 HGB and 147 AO and is kept for their duration. Data processing agreements are in place with the providers used.

Consent and the cookie notice

On your first visit a notice appears with two buttons of the same size, each taking a single click: “Accept all” or “Necessary only”. Until you choose one of them, nothing that would require consent is loaded; the script in question is not on the page at all. Nothing is pre-selected, and “Necessary only” is exactly as reachable as “Accept all”.

We store your answer under af-consent in local storage, so the notice does not reappear on every visit and so that we can demonstrate consent. You can change your decision at any time via “Cookie settings” in the footer of any page. The cookie policy lists which services are affected.

LinkedIn Insight Tag

If you have agreed, we load the LinkedIn Insight Tag. The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. We use it to measure which of our LinkedIn ads lead to visits and signups, and to build audiences for further ads.

In doing so LinkedIn processes, among other things, your IP address, device and browser data and the page you visited, and sets cookies of its own. If you are signed in to LinkedIn, it can associate the visit with your member account. We ourselves receive only aggregated reports from LinkedIn, no information about individuals.

The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which can be withdrawn at any time. Transfer to the USA cannot be ruled out; LinkedIn is certified under the EU-US Data Privacy Framework. See the LinkedIn privacy policy for details; as a LinkedIn member you can additionally object to the use of your data for advertising in your LinkedIn settings.

Audience measurement (Plausible)

We would like to know how often which page is read and what people are looking for on this website. For that we use Plausible Analytics. The provider is Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia; the data is processed in Germany and does not leave the EU.

Plausible works without cookies and without any identifier on your device. What is recorded is the page visited, the referring page, any campaign parameters, approximate origin at country level, and device type, browser and operating system. Your IP address is not stored: in order to group repeat requests within a day into one visit, Plausible computes a server-side hash from the IP address and browser identification together with a random value that changes daily and is then discarded. The hash cannot be reversed, and by the next day the association can no longer be made.

Because nothing is stored on or read from your device, § 25 TDDDG does not apply and no consent is required. The legal basis is our legitimate interest in a data-minimising assessment of how our offering is used (Art. 6(1)(f) GDPR). A data processing agreement is in place with the provider. The data collected cannot be combined into a personal profile; we cannot identify individuals in it.

Where a visit came from

We would like to know whether a visit comes from a search engine, from an ad, or directly — and to still know it after you have looked at a few pages and then move on to the AutoFlow portal or a form.

Nothing is stored on your device for this. Instead the information is appended as a parameter to the address of the next page and passed along that way within the visit; when you move to one of our other addresses, it travels with you. If the visit carries no campaign parameters, all we carry for this purpose is the hostname of the referring page — “google.com”, say — not the full address. Close the tab and it is gone.

Because nothing is stored on or read from your device in the process, § 25 TDDDG does not apply and no consent is required. The legal basis is our legitimate interest in being able to judge the effect of our publications and ads (Art. 6(1)(f) GDPR).

YouTube videos

On some pages we embed videos from YouTube. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The videos are not embedded directly in the page; they are loaded only once you click them. Until then no connection to Google is established and no data is transmitted. We also use the extended privacy mode (youtube-nocookie.com), in which, according to YouTube, no recognition cookies are set as long as you do not play a video.

As soon as you start a video, a connection to YouTube's servers is established. YouTube then learns which of our pages you visited and may process your IP address and further device data. If you are simultaneously signed in to your YouTube account, YouTube can associate the playback with your profile; you can prevent this by signing out.

Because the video is loaded only in response to your action, processing takes place on the basis of your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); beyond that there is a legitimate interest in an appealing presentation of our offering (Art. 6(1)(f) GDPR). Google is certified under the EU-US Data Privacy Framework. Further information in the Google privacy policy.

Links to other services

This website links to, among others, the AutoFlow portal (portal.autoflow365.app), the documentation (docs.autoflow365.app), www.mse365.de, Microsoft AppSource, LinkedIn and YouTube. The offerings of mse Software GmbH are covered by their privacy policy, third-party offerings by their own. Merely displaying a link transmits no data to the destination.

Legal bases for processing

Where you have consented to processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. Where you have consented to the storage of cookies or to access to information on your device, processing additionally rests on § 25(1) TDDDG. Consent can be withdrawn at any time. Where your data is required for the performance of a contract or for pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. Where processing is necessary to comply with a legal obligation, it rests on Art. 6(1)(c) GDPR. Processing may further rest on our legitimate interest under Art. 6(1)(f) GDPR. The sections above state the legal basis applicable in each case.

Storage period

Unless a more specific storage period is stated within this privacy policy, your personal data remains with us until the purpose for processing it ceases to apply. If you assert a justified request for erasure or withdraw consent, your data will be deleted unless we have other legally permissible grounds for storing it (e.g. retention periods under tax or commercial law); in the latter case erasure follows once those grounds cease to apply.

Recipients of personal data

We pass personal data to external parties only where this is necessary for the performance of a contract, where we are legally obliged to, where we have a legitimate interest in doing so under Art. 6(1)(f) GDPR, or where another legal basis permits it. Where processors are used, we pass on data only on the basis of a valid data processing agreement.

Transfers to third countries

The services used on this website — Microsoft (hosting) and Google (YouTube) — are provided through their Irish entities. Processing in the USA cannot be ruled out. Both parent companies are certified under the EU-US Data Privacy Framework, which means the USA counts as a safe third country for certified recipients.

Your rights

Within the applicable statutory provisions you have the right at any time to free information about your stored personal data, its origin and recipients, and the purpose of processing, and where applicable a right to rectification or erasure of that data.

  • Withdrawal of consent. Many processing operations are possible only with your express consent. You may withdraw consent at any time; the lawfulness of processing carried out up to that point is unaffected.
  • Objection (Art. 21 GDPR). Where processing rests on Art. 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. Where your data is processed for direct marketing, you have the right to object at any time without giving reasons.
  • Restriction of processing. You have the right to request restriction of processing — for instance while we verify data whose accuracy you contest, in place of erasure where processing was unlawful, where you need the data to defend legal claims, or while an objection under Art. 21(1) GDPR is being weighed.
  • Data portability. You have the right to receive data we process automatically on the basis of your consent or in performance of a contract in a common, machine-readable format, or — where technically feasible — to have it transmitted to a third party.
  • Complaint to a supervisory authority. In the event of breaches of the GDPR you have a right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.

For all of these matters you can reach us at privacy@mse365.de or via the contact details given above.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the browser address bar starting with “https://” and showing a padlock symbol. When encryption is active, the data you transmit to us cannot be read by third parties.

Objection to advertising emails

We hereby object to the use of contact data published under the imprint obligation for sending advertising and information material that has not been expressly requested. We expressly reserve the right to take legal action in the event of unsolicited advertising being sent.

Newsletter

Never miss a product update

New features, new connectors, new videos and the next webinar dates. We write to you whenever there is something new.

By subscribing you consent to receiving the AutoFlow newsletter by email. Withdraw at any time via the unsubscribe link in every email. More in the privacy policy.

AutoFlow

The graphical process platform for Microsoft Dynamics 365 Business Central. Click your workflows instead of coding them.

Follow us

  • LinkedIn
  • YouTube

Solutions

  • AutoFlow
  • AutoFlow Receive
  • AutoFlow Dispatch
  • ITscope2Dynamics
  • CreditSolution2Dynamics
  • SkyMinder2Dynamics
  • ElectronicSales2Dynamics
  • Praxedo2DYCE
  • All solutions

Use cases

  • Incomplete item master data
  • Unbilled subscriptions
  • Reordering at the reorder point
  • File invoices to SharePoint automatically
  • Service orders from your ticketing system
  • All use cases

Resources

  • AutoFlow portal
  • Template gallery
  • Documentation
  • Release notes

Legal

  • Imprint
  • Privacy policy
  • Licence agreement
  • Terms & conditions
© AutoFlow – a product by mse Software GmbH Click your workflows instead of coding them.