Skip to content

Who we are and what this covers

Humoniq provides an API that helps companies respond to their customers. This policy explains what we do with personal data when you visit our website, when you ask us for access, and when a company sends us customer interactions through the API.

Two different relationships are covered here and the difference matters. For information about you as a visitor or a prospective customer, we are the controller: we decide what happens with it and this policy tells you what that is. For interaction content our customers send through the API, we are a processor acting on their instructions, which is explained in its own section below.

Information you give us

When you complete the access form on our home page, we collect exactly what the form asks for and nothing hidden alongside it.

  • Your name.
  • Your work email address.
  • The company you are with.
  • The use cases you selected: sales, service or support.
  • Anything else you choose to tell us, if you email us instead of using the form.

We use these details to reply to you, to work out whether Humoniq is a fit, and to set you up if it is. We do not add you to a marketing list, we do not enrich your record from third-party data brokers, and we do not pass your details to anyone else for their own use.

Information we collect automatically

This website is deliberately light. There are no advertising trackers, no profiling of visitors and no data sold to brokers.

We keep privacy-friendly, cookieless usage counts so we can see how many people visited a page and roughly where in the world they were. These are aggregated, they do not identify you, and they are not linked to anything else we hold.

Our hosting infrastructure keeps standard server logs containing IP addresses, timestamps, requested paths and user-agent strings. We use them to keep the site available, to investigate errors and to spot abuse.

Interaction content sent through the API

When a customer integrates Humoniq, their systems send us the content of interactions with their own customers. That content often contains personal data: names, email addresses, order and account details, and whatever the person happened to write in their message.

We process that content for one purpose, which is to produce the response and the optional next actions we return. We do not use it to train models shared across customers. Refinement based on outcome signals happens inside that customer's own account.

We never contact a customer's customers, we do not sell or share interaction content, and we do not use it to build any profile of the people in it beyond what is needed to answer their message.

How we use information

We use the personal data described above for the following purposes, and not for others.

  • Replying to your access request and setting up your account if Humoniq is a fit.
  • Providing, operating, securing and improving the Service.
  • Sending service messages about incidents, breaking changes and changes to our terms. These are not marketing and you cannot be opted out of them while you hold an account.
  • Meeting our legal, accounting and tax obligations.
  • Detecting, investigating and preventing abuse, fraud and security incidents.

We do not sell personal data. We do not share it with advertisers. We do not carry out automated decision-making that produces legal effects for you or similarly significantly affects you.

When we process on behalf of a customer

For interaction content, our customer is the controller and we are their processor. We act on their documented instructions, we do not decide what the content is used for, and we enter into a written data processing agreement with every customer before any of it flows.

If you are an individual whose message was handled through Humoniq by a company you deal with, that company holds your data and is the right first contact for access, correction or deletion. They know who you are and we do not. Ask them, and we will support whatever they need from us.

If you write to us directly instead, we will not ignore you. We will point you to the right company and help where we properly can without going behind our customer's back.

Sharing and sub-processors

We share personal data with a small number of service providers who make the Service work: cloud hosting and compute, model inference providers, email delivery and error monitoring. Each one is bound by a written agreement that limits them to processing on our instructions and requires appropriate security.

We also disclose data where the law requires it, and where it is necessary to establish, exercise or defend legal claims. If we are ever part of a merger, acquisition or sale of assets, data may transfer as part of that, and we will tell customers before it happens rather than after.

A current list of our sub-processors is available to customers on request, and we give notice before adding a new one so there is time to object.

International transfers

Our providers may process data outside the country you are in. Where personal data leaves the United Kingdom or the European Economic Area, we rely on an adequacy decision where one exists, and on Standard Contractual Clauses with the UK Addendum where one does not, together with any additional safeguards a transfer risk assessment calls for.

If you have regional processing requirements, raise them before you integrate. We can often accommodate them, and it is far easier to arrange at the start than to unpick later.

How long we keep information

Access requests are kept for two years from your last contact with us, so that we can pick a conversation back up where it left off, and are then deleted.

Interaction content is retained for the period agreed with the customer who sent it. Where nothing is agreed, it is kept only as long as needed to return the response and investigate any error, and is then deleted.

Server logs are kept on a short rolling window. Records we are required to keep for tax and accounting purposes are kept for as long as the law says, and no longer.

Security

Data is encrypted in transit using TLS and encrypted at rest. Access to production systems is limited to the people who need it, protected by multi-factor authentication and logged. API keys are stored hashed, never in plain text. We review access regularly and keep dependencies patched.

No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes the law sets, and we will tell you what we actually know rather than what sounds best.

Your rights

Depending on where you live, you may have some or all of the following rights over the personal data we hold about you as a controller.

  • Get a copy of it, along with information about how we use it.
  • Have it corrected if it is wrong or incomplete.
  • Have it deleted, where there is no overriding reason for us to keep it.
  • Restrict or object to how we use it, including any use based on legitimate interests.
  • Receive it in a portable, machine-readable format, or have it sent to someone else.
  • Complain to a data protection authority.

To exercise any of these, email our privacy address below. We will respond within one month, we will not charge you, and we will not make it deliberately difficult. We may need to confirm who you are first, so that we do not hand your data to somebody else. If you are in the United Kingdom or the European Economic Area you can complain to your local supervisory authority, though we would rather you came to us first so we get a chance to put it right.

Cookies

We do not use advertising cookies, tracking cookies or third-party marketing pixels. Our usage counts are cookieless, which is why you are not being asked to dismiss a consent banner to read this page.

If we ever introduce anything that does require consent, we will ask for it properly before setting it, and update this section to say what it is and why.

Children

The Service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

Changes to this policy

We will update this page whenever what we do changes. The effective date at the top tells you when the current version took effect, and we keep the substance of changes in plain language rather than burying them.

For material changes affecting customers, we will email you rather than rely on you noticing.

Contact us

Privacy questions and rights requests go to our privacy address below. General questions about access go to our access address, or use the form on the home page.

Both reach a person on our team, and we would genuinely rather answer a question early than have you guess.

Reach us

Privacy and rights
privacy@humoniq.com
Access and technical
access@humoniq.com
Legal and contracts
legal@humoniq.com

Humoniq is an early-stage company and these pages describe how we actually work today. If something here is unclear or does not fit how your organisation needs to operate, write to us and we will talk it through before you commit to anything.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now