Security & privacy

Security, by design.

Your data and your network's data are hosted in the European Union, encrypted in transit, and stay under your control. Here is exactly how — without any certification badge we don't actually hold.

Hosted in the EU · GDPR · Outbound only to your CRM

European hosting and GDPR

Data in the EU

bloo.Cards is developed and hosted in the European Union. Your data and your contacts' data never leave it — unless you enable a non-EU integration yourself, in which case we warn you first.

Controller and processor

MOLDEREZ-CONSULT SRL (Brussels) is the controller for your account, and the processor for the contact data you collect. A data processing agreement (DPA) is available on request.

Your rights

Access, rectification, export and erasure from your account, at any time. Deleting your account erases your data according to our retention policy.

Encryption at every layer

In transit

All traffic runs over HTTPS (TLS). No page, no API call in the clear.

Passwords & tokens

Passwords are hashed with Argon2id, never stored in the clear. Session tokens are hashed with SHA-256.

CRM credentials at rest Soon

When you connect a CRM, its credentials will be encrypted at rest with a key specific to your organisation. Native connectors are rolling out gradually.

An outbound-only architecture

bloo.Cards sends new entries to your systems. It never reads or modifies your CRM data. This principle keeps everything simpler: fewer accesses, fewer risks.

Keys under your control

Read-only keys

The keys you generate (bc_live_…) let your tools read your new bloo.Cards contacts. They grant no write access.

Signed webhooks

Every outbound notification is signed (HMAC-SHA256) with a secret only you know: your system can verify it really comes from bloo.Cards.

Revocable at any time

A key is revoked in one click; the cut-off is immediate. Keys are never shown twice or stored in the clear — only their hashed fingerprint is kept.

Access to your account

Two-factor authentication

Enable two-step verification (TOTP) on your account, with an authenticator app.

Sessions & rate limiting

Sessions regenerated at login, limits on the number of attempts, a log of logins and sensitive actions.

Distinct roles

Separate owner, administrator and viewer rights for team accounts: everyone sees and does exactly what concerns them.

What we never do

We don't resell your data or your contacts' data. We don't train any AI model on your contacts. We never access your CRM. And there is no advertising in bloo.Cards.

Built to recognised best practices

bloo.Cards follows OWASP best practices (access control, injection protection, data integrity) and undergoes regular internal audits. We claim no external certification we don't hold: we prefer to describe our measures precisely rather than display a logo.

Frequently asked questions

Where is my data hosted?

In the European Union. Development and hosting both take place in the EU.

Do you sign a data processing agreement (DPA)?

Yes. A data processing agreement is available on request at hello@bloo.cards.

Can bloo.Cards access my CRM?

No. The architecture is outbound only: bloo.Cards never has read or write access to your CRM.

How do I revoke an API key?

From the Developers section of your account, in one click. Revocation cuts off access immediately.

Are you ISO 27001 or SOC 2 certified?

We claim no certification we don't hold. We apply TLS, Argon2id, encryption at rest for sensitive credentials and OWASP best practices, and we describe our measures openly.

What happens if I delete my account?

Your data is erased according to our retention policy; backups then expire on their own cycle.

Questions about security?

Write to us for a DPA, the details of our technical measures or hosting: hello@bloo.cards. Contact us.

Your free card