SECURITY AND DATA PROTECTION

Trust starts with clear boundaries.

Heumix protects access, separates organisations and keeps human authority over business data and decisions.

ACCESS AND ORGANISATIONS

Every user operates within an authorised scope.

01

Authentication

Functions and synchronised data are accessible after authentication.

02

Organisation scope

Access to business data is limited to the relevant organisation.

03

Roles

Agent, manager, administrator and owner views serve different responsibilities.

GOOGLE CONNECTIONS

OAuth, limited scope and server-side keys.

A Google connection is initiated by an authenticated user and uses OAuth. Heumix only requests the Gmail read, Gmail send and Google Calendar events permissions required for the described functions.

OAuth tokens are encrypted at rest with AES-256-GCM. Encryption is bound to the organisation, provider and email address. Keys remain server-side and are not exposed to the browser.

Gmail read access does not allow Heumix to modify or delete email. An email is sent only when a user explicitly triggers it in the application.

PROVIDERS AND PROCESSING

Roles and dependencies remain documented.

Heumix uses Supabase for its application database and storage, Vercel/Nitro for application execution and hosting, and the OpenAI API server-side for certain AI functions explicitly requested by the user.

The contractual documents, product data protection policy and subprocessor list published by Heumix are the detailed applicable references.

DISCONNECTION AND DELETION

Stopping a connection and deleting imported history are separate actions.

Disconnecting Gmail attempts to revoke the Google token, locally revokes the credential and stops future synchronisation. Disconnecting Calendar stops future synchronisation.

History already synchronised into the CRM is not automatically deleted on disconnection. It remains until deleted through the Heumix procedure.

Review the trust references

IntegrationsWhat is Heumix?Reality EngineHeumix FranceHeumix UAE

YOUR FRAMEWORK, BEFORE ACTIVATION

Let’s discuss your security and processing requirements.

The applicable scope is defined with your organisation before go-live.