LEGAL · DYNAMICS CRM ASSISTANT
Privacy Statement
Dynamics CRM Assistant, an AI assistant skill published by Breathe IT AS.
Last updated: 27 August 2026
The short version: Breathe IT does not collect, store, host or process your data. Nothing flows to or through Breathe IT’s systems or tenant. Your data moves directly between your AI client and your own Dynamics 365 / Dataverse environment. We are only the publisher of the application identity that lets you sign in.
1.Scope
This statement explains how data is handled when you use the Dynamics CRM Assistant skill (the “Skill”) published by Breathe IT AS, Stavern, Norway. It covers the Skill only; the third-party services it connects to have their own privacy terms (see section 6).
2.What Breathe IT does not do
- We do not receive, collect or store your Dynamics 365 / Dataverse data.
- We do not route your data through any Breathe IT server, service or Microsoft tenant.
- We do not store your credentials, access tokens or sign-in details.
- We do not track your usage of the Skill, and we run no analytics, telemetry or profiling on it.
3.How authentication works
The Skill uses Microsoft Entra ID with the OAuth 2.0 device code flow and delegated permissions. When you sign in:
- You authenticate directly with Microsoft Entra ID using your own work or school account.
- Microsoft issues an access token directly to the AI client running on your side. The token is scoped to your own Dynamics 365 environment.
- The token is cached locally on the machine running the client (by default under
~/.d365-copilot/) so you do not have to sign in repeatedly. It is not transmitted to Breathe IT. - The Skill can only act with the same permissions you already have in Dynamics 365, your security roles, field-level security and business-unit scope.
4.How your data flows
When you ask the Skill to read or write records, the request goes directly from the AI client to your Dynamics 365 / Dataverse Web API over HTTPS, authenticated with the token described above. Breathe IT is never part of that path and never sees the content of your requests or your data.
5.Breathe IT’s role
Breathe IT publishes a single multi-tenant application registration in Microsoft Entra ID. When your administrator grants consent, Microsoft creates a service principal inside your own tenant, no application or data is created on Breathe IT’s side. Our role is limited to being the identity publisher of the Skill. We are not a processor of your data.
6.Third-party services
The Skill connects services operated by third parties. Their handling of data is governed by their own terms:
| Provider | Role | Their terms |
|---|---|---|
| Microsoft | Entra ID (sign-in) and Dynamics 365 / Dataverse (your data resides here). | microsoft.com/privacy |
| Anthropic | Provides the Claude AI assistant that processes your prompts. | anthropic.com/legal/privacy |
Prompts and content you send to the AI assistant are processed by Anthropic under its data-processing terms and, per those terms, are not used to train its models. Please review the third-party terms above; Breathe IT does not control these services.
7.Revoking access
You can revoke the Skill’s access at any time, with immediate effect, from the
Microsoft Entra admin centre: Enterprise applications → Dynamics CRM Assistant →
Delete (or remove the user assignment). You can also clear the locally cached
token by deleting the ~/.d365-copilot/ folder on your machine.
8.Changes to this statement
We may update this statement from time to time. The version published at this URL is the current one. Material changes will be reflected in the “Last updated” date above.
9.Contact
Breathe IT AS, Stavern, Norway
Email: contact@breathe.no
Web: breathe.no