Hivsy legal
Privacy Policy
This Policy explains how Hivsy handles personal data when you visit our site, create or use an account, communicate with us, or interact with email processed through the Services.
Effective
1. Scope and our roles
This Policy applies to Hivsy websites, applications, support, account administration, and communications. It does not govern a customer’s own privacy practices or third-party sites and services.
Hivsy is a controller or business for account, billing, website, security, and service-relationship data. When a customer uses Hivsy to process recipient, contact, or message data for its own purposes, Hivsy generally acts as a processor or service provider under the Data Processing Addendum. Customers are responsible for their own notices, lawful bases, consent, and responses to their data subjects.
2. Personal data we collect
- Account data: name, email address, password hash, avatar, team membership, role, preferences, security settings, and account timestamps.
- Authentication data: session and refresh-token records, security and audit events, multi-factor authentication settings, and optional Google or GitHub identity identifiers and verified profile information. Hivsy does not store your OAuth provider password.
- Billing data: plan, entitlements, usage, purchase history, transaction references, and limited payment status. Payment-card details are handled by the payment processor rather than stored by Hivsy.
- Customer Data: sender and recipient addresses, contact lists, templates, message content and attachments, inbound messages, notes, rules, suppressions, domains and DNS status, webhooks, automations, and related metadata.
- Delivery and engagement data: message IDs, timestamps, routing and delivery status, bounces, complaints, unsubscribe events, and, when enabled by the sender, open and link events and associated request information.
- Technical and usage data: IP address, browser and device information, request and security logs, feature interactions, API activity, error details, and approximate location inferred from an IP address when available.
- Communications: support requests, abuse reports, feedback, and other correspondence with Hivsy.
3. Where the data comes from
- Directly from you when you register, configure the Services, make a purchase, or contact us.
- From your organization’s account owner or administrators when they invite or manage you.
- From Google or GitHub when you choose social sign-in and authorize the requested profile information.
- From Hivsy customers and their systems when they upload contacts, send or receive messages, configure webhooks, or use the API.
- Automatically from browsers, APIs, mail systems, DNS, security tooling, and recipient interactions with messages.
4. Why we use personal data
- Provide, authenticate, operate, maintain, and support the Services.
- Route and deliver outbound and inbound email, process webhooks, maintain suppressions, and show delivery and engagement information.
- Create accounts, manage teams, process payments, allocate credits, and communicate about transactions or service changes.
- Secure the Services, prevent fraud and spam, investigate abuse, enforce policies, and protect recipients, customers, Hivsy, and the public.
- Diagnose reliability issues, measure service performance, develop features, and improve usability.
- Comply with legal obligations, preserve evidence, respond to lawful requests, and establish or defend legal claims.
- Send product or marketing communications where permitted. You can opt out of marketing messages without affecting required service communications.
5. Legal bases
Where a legal basis is required, Hivsy relies on performance of a contract to provide account and paid services; legitimate interests in operating, securing, improving, and responsibly promoting the Services; compliance with legal obligations; and consent where required. You may withdraw consent at any time, without affecting earlier lawful processing. Hivsy balances legitimate interests against the rights and expectations of affected individuals.
6. How we disclose personal data
- Service providers that host infrastructure, process payments, support authentication, deliver communications, monitor security, or provide technical support, under appropriate contractual restrictions.
- Recipient mail systems, domain and DNS operators, webhook destinations, and other networks or services you direct Hivsy to interact with.
- Your organization’s account owner, administrators, and authorized team members according to their roles and the shared workspace configuration.
- Professional advisers, auditors, insurers, regulators, courts, or law enforcement when reasonably necessary or legally required.
- A successor or participant in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
- Other parties when you direct us to disclose data or give valid consent.
Hivsy does not sell personal data for money and does not use personal data for cross-context behavioral advertising. Hivsy may publish aggregated or de-identified information that cannot reasonably identify a person.
7. Email tracking and recipient choices
A Hivsy customer may enable open or link tracking in messages. Open tracking generally uses a small remote image; link tracking routes a clicked link through a Hivsy endpoint before redirecting to the destination. These events may reveal timestamps, IP-derived information, device or client details, and the message or link involved. The customer is responsible for telling recipients about this processing and obtaining consent where required.
Recipients can often block remote images in their email client and can use the unsubscribe mechanism in a marketing message. Privacy or deletion requests about a customer’s mailing list or message should normally be directed to that customer; Hivsy will assist the customer as required by the Data Processing Addendum.
8. Retention
Hivsy retains personal data for the period needed to provide the Services and for legitimate operational, security, backup, dispute, and legal-compliance purposes. The period depends on the type of data, account status, customer configuration, legal obligations, sensitivity, and risk. Customer Data is ordinarily retained while the account or relevant feature remains active and is deleted or de-identified after it is no longer needed, subject to backup cycles, legal holds, fraud prevention, and records Hivsy must retain.
Authentication, security, billing, suppression, complaint, and audit records may be retained longer when needed to protect accounts, honor recipient choices, document transactions, prevent repeat abuse, or comply with law.
9. Security
Hivsy uses administrative, technical, and organizational safeguards designed for the nature and risk of the data, including encrypted network transport, access controls, credential hashing, secret protection, tenant scoping, logging, abuse controls, and backup and recovery practices. No internet service is completely secure, and Hivsy cannot guarantee absolute security.
If you believe your account or data is at risk, contact support@hivsy.com immediately. Do not send passwords, API keys, recovery codes, or sensitive message content by email.
10. International transfers
Hivsy and its service providers may process data in countries different from where you live. Where required, Hivsy uses an approved transfer mechanism, contractual protections, and supplementary safeguards appropriate to the transfer. Customers that need processor terms for international transfers should review the Data Processing Addendum and contact privacy@hivsy.com before sending regulated data.
11. Your privacy rights
Depending on your location and relationship with Hivsy, you may have rights to know or access personal data; correct, delete, or receive a portable copy; restrict or object to processing; withdraw consent; opt out of certain disclosures or marketing; and appeal a denied request. You may also complain to your local data-protection authority. Hivsy will not discriminate against you for exercising a privacy right.
Submit a request to privacy@hivsy.com. Hivsy may need to verify your identity and authority before acting. If Hivsy holds the data only for a customer, we may direct the request to that customer. Authorized agents may submit requests where permitted by law, subject to verification.
12. Children
The Services are intended for business users aged 18 or older and are not directed to children. Do not create an account or intentionally use Hivsy to collect children’s personal data without a lawful basis, appropriate notices and consent, and a written agreement covering that use. Contact privacy@hivsy.com if you believe a child provided account data directly to Hivsy.
13. Changes to this Policy
Hivsy may update this Policy as the Services or legal requirements change. The effective date will be updated. Material changes will be communicated through the Services, by email, or another reasonable method when required.
14. Contact
Hivsy is the operator responsible for the account and service-relationship processing described above. Privacy questions and rights requests may be sent to privacy@hivsy.com. Legal notices may be sent to legal@hivsy.com.
Questions about this document? Email privacy@hivsy.com.