SPOT Collector privacy policy
The SPOT Collector browser extension for Chrome, Microsoft Edge and Firefox
In short
- The extension lets the SPOT portal you are signed in to read SAP PO design-time metadata (interface definitions, not business messages) from an SAP PO system inside your network.
- It works only for portals you pair and PO systems you approve, and it can only read. Requests that would change anything in SAP PO are refused in code.
- It stores nothing except your pairings and approvals, in your browser. No passwords, no metadata, no browsing data.
- It has no analytics, no advertising and no tracking. Data is never sold.
1. Who we are
SPOT and the SPOT Collector extension are provided by Tarento (Tarento Group AB and its subsidiaries, "we"). This policy covers the extension and what happens to the data it handles once it reaches the SPOT portal. Tarento's company privacy policy covers everything else, such as our websites and business relationships.
2. What the extension does
SPOT assesses SAP Process Orchestration (PI/PO) estates for migration. The hosted SPOT portal cannot reach an SAP PO system inside a company network, so the extension does it from your browser. The SPOT page you are signed in to runs the extraction and hands each request to the extension. The extension checks that the request is a read-only query, sends it to the approved SAP PO system, and returns the answer to that page. The extension has no sign-in of its own.
3. Data the extension handles
| Data | Where it comes from | Where it goes | Kept by the extension? |
|---|---|---|---|
| SAP PO user name and password (authentication information) | The SPOT page, either saved with the estate by your organisation or typed by you for the run | Only to the SAP PO system you approved, as the request's Basic authorisation header | No. Held in memory for the request only |
| SAP PO design-time metadata (website content): names and namespaces of integration objects, communication components and channels, adapter types, endpoints and mapping references. Change records in it include SAP user IDs (personally identifiable information) | The approved SAP PO system | Only to the paired SPOT page that asked for it | No |
| Pairing settings: the SPOT portal addresses you paired and the SAP PO hosts you approved | You, on the extension's options page, or your organisation's IT through browser policy | Nowhere. They stay in your browser | Yes, in the browser's extension storage, until you remove them or the extension |
The extension does not:
- read your browsing history, or any page other than the SPOT portals you paired;
- read SAP PO business messages or their payloads. It reads design-time configuration only;
- use your browser's cookies or any SAP PO session you have open in another tab;
- change anything in SAP PO. Only query and read calls are ever sent;
- run code downloaded from anywhere. All of its code ships in the extension package;
- contain analytics, advertising or tracking of any kind.
4. Permissions and why they are needed
storage: keeps your paired portals and approved SAP PO hosts across browser restarts, and reads an organisation's pre-configured portal from browser policy.scripting: registers the extension's own message script on the portals you paired, and removes it when you unpair one. Until you pair a portal it runs on no website at all.offscreen(Chrome and Edge): an SAP PO query can take several minutes, longer than an extension's background worker may wait. The requests run in a hidden extension page, which also checks each one is read-only before sending it.- Optional site access: nothing is granted at install. When you pair a portal or approve an SAP PO host, your browser asks you for access to that one address, and you can revoke it at any time on the options page.
5. What happens in the SPOT portal
The metadata goes to the SPOT portal under your own signed-in session and is stored in your organisation's own space. Only members of your organisation can see it. SPOT uses it to build an inventory, rate each interface's migration difficulty and produce reports. The portal runs on SAP Business Technology Platform (Europe, Frankfurt), with its database in the same region and extracted files in Microsoft Azure Blob Storage. If your organisation saves an SAP PO password with an estate, it is stored encrypted. All traffic between your browser and the portal uses HTTPS.
6. Optional AI features
When a user in your organisation turns on AI assistance for an analysis, SPOT sends interface-level metadata to Anthropic to classify interfaces or draft a summary. That includes interface names, namespaces, sender and receiver component names, adapter types and quality of service. SAP PO passwords are never sent. If nobody turns AI assistance on, nothing is sent to Anthropic.
7. Sharing
We do not sell data, use it for advertising, or use it for any purpose other than the one described above. We do not use it to decide creditworthiness or for lending. Apart from the hosting and AI providers named in sections 5 and 6, we share it with nobody unless the law requires us to.
8. How long data is kept
- In the extension: your pairings and approvals stay until you remove them or remove the extension. Nothing else is kept.
- In the SPOT portal: extracted metadata is kept until your organisation deletes the estate (tenant) or the run it belongs to, or until your organisation asks us to delete it.
9. Your choices
- Unpair a portal or revoke an SAP PO host on the extension's options page (click the toolbar button).
- Remove the extension from your browser. That deletes everything it stored.
- To have data deleted from the SPOT portal, ask your organisation's SPOT administrator, or email gdpr@tarento.com. You can also use that address to exercise your other data-protection rights.
10. Changes to this policy
If the extension starts handling data in a new way, we will update this page and its effective date before releasing that version.