SPOT Collector privacy policy

The SPOT Collector browser extension for Chrome, Microsoft Edge and Firefox

Effective 22 September 2026 · Extension version 1.0.1 and later

In short

1. Who we are

SPOT and the SPOT Collector extension are provided by Tarento (Tarento Group AB and its subsidiaries, "we"). This policy covers the extension and what happens to the data it handles once it reaches the SPOT portal. Tarento's company privacy policy covers everything else, such as our websites and business relationships.

2. What the extension does

SPOT assesses SAP Process Orchestration (PI/PO) estates for migration. The hosted SPOT portal cannot reach an SAP PO system inside a company network, so the extension does it from your browser. The SPOT page you are signed in to runs the extraction and hands each request to the extension. The extension checks that the request is a read-only query, sends it to the approved SAP PO system, and returns the answer to that page. The extension has no sign-in of its own.

3. Data the extension handles

DataWhere it comes fromWhere it goesKept by the extension?
SAP PO user name and password (authentication information) The SPOT page, either saved with the estate by your organisation or typed by you for the run Only to the SAP PO system you approved, as the request's Basic authorisation header No. Held in memory for the request only
SAP PO design-time metadata (website content): names and namespaces of integration objects, communication components and channels, adapter types, endpoints and mapping references. Change records in it include SAP user IDs (personally identifiable information) The approved SAP PO system Only to the paired SPOT page that asked for it No
Pairing settings: the SPOT portal addresses you paired and the SAP PO hosts you approved You, on the extension's options page, or your organisation's IT through browser policy Nowhere. They stay in your browser Yes, in the browser's extension storage, until you remove them or the extension

The extension does not:

4. Permissions and why they are needed

5. What happens in the SPOT portal

The metadata goes to the SPOT portal under your own signed-in session and is stored in your organisation's own space. Only members of your organisation can see it. SPOT uses it to build an inventory, rate each interface's migration difficulty and produce reports. The portal runs on SAP Business Technology Platform (Europe, Frankfurt), with its database in the same region and extracted files in Microsoft Azure Blob Storage. If your organisation saves an SAP PO password with an estate, it is stored encrypted. All traffic between your browser and the portal uses HTTPS.

6. Optional AI features

When a user in your organisation turns on AI assistance for an analysis, SPOT sends interface-level metadata to Anthropic to classify interfaces or draft a summary. That includes interface names, namespaces, sender and receiver component names, adapter types and quality of service. SAP PO passwords are never sent. If nobody turns AI assistance on, nothing is sent to Anthropic.

7. Sharing

We do not sell data, use it for advertising, or use it for any purpose other than the one described above. We do not use it to decide creditworthiness or for lending. Apart from the hosting and AI providers named in sections 5 and 6, we share it with nobody unless the law requires us to.

8. How long data is kept

9. Your choices

10. Changes to this policy

If the extension starts handling data in a new way, we will update this page and its effective date before releasing that version.