Authentication
Functions and synchronised data are accessible after authentication.
SECURITY AND DATA PROTECTION
Heumix protects access, separates organisations and keeps human authority over business data and decisions.
ACCESS AND ORGANISATIONS
Functions and synchronised data are accessible after authentication.
Access to business data is limited to the relevant organisation.
Agent, manager, administrator and owner views serve different responsibilities.
GOOGLE CONNECTIONS
A Google connection is initiated by an authenticated user and uses OAuth. Heumix only requests the Gmail read, Gmail send and Google Calendar events permissions required for the described functions.
OAuth tokens are encrypted at rest with AES-256-GCM. Encryption is bound to the organisation, provider and email address. Keys remain server-side and are not exposed to the browser.
Gmail read access does not allow Heumix to modify or delete email. An email is sent only when a user explicitly triggers it in the application.
PROVIDERS AND PROCESSING
Heumix uses Supabase for its application database and storage, Vercel/Nitro for application execution and hosting, and the OpenAI API server-side for certain AI functions explicitly requested by the user.
The contractual documents, product data protection policy and subprocessor list published by Heumix are the detailed applicable references.
DISCONNECTION AND DELETION
Disconnecting Gmail attempts to revoke the Google token, locally revokes the credential and stops future synchronisation. Disconnecting Calendar stops future synchronisation.
History already synchronised into the CRM is not automatically deleted on disconnection. It remains until deleted through the Heumix procedure.
YOUR FRAMEWORK, BEFORE ACTIVATION
The applicable scope is defined with your organisation before go-live.