Security, by design.
Your data and your network's data are hosted in the European Union, encrypted in transit, and stay under your control. Here is exactly how — without any certification badge we don't actually hold.
Hosted in the EU · GDPR · Outbound only to your CRM
European hosting and GDPR
Data in the EU
bloo.Cards is developed and hosted in the European Union. Your data and your contacts' data never leave it — unless you enable a non-EU integration yourself, in which case we warn you first.
Controller and processor
MOLDEREZ-CONSULT SRL (Brussels) is the controller for your account, and the processor for the contact data you collect. A data processing agreement (DPA) is available on request.
Your rights
Access, rectification, export and erasure from your account, at any time. Deleting your account erases your data according to our retention policy.
Encryption at every layer
In transit
All traffic runs over HTTPS (TLS). No page, no API call in the clear.
Passwords & tokens
Passwords are hashed with Argon2id, never stored in the clear. Session tokens are hashed with SHA-256.
CRM credentials at rest Soon
When you connect a CRM, its credentials will be encrypted at rest with a key specific to your organisation. Native connectors are rolling out gradually.
An outbound-only architecture
bloo.Cards sends new entries to your systems. It never reads or modifies your CRM data. This principle keeps everything simpler: fewer accesses, fewer risks.
Keys under your control
Read-only keys
The keys you generate (bc_live_…) let your tools read your new bloo.Cards contacts. They grant no write access.
Signed webhooks
Every outbound notification is signed (HMAC-SHA256) with a secret only you know: your system can verify it really comes from bloo.Cards.
Revocable at any time
A key is revoked in one click; the cut-off is immediate. Keys are never shown twice or stored in the clear — only their hashed fingerprint is kept.
Access to your account
Two-factor authentication
Enable two-step verification (TOTP) on your account, with an authenticator app.
Sessions & rate limiting
Sessions regenerated at login, limits on the number of attempts, a log of logins and sensitive actions.
Distinct roles
Separate owner, administrator and viewer rights for team accounts: everyone sees and does exactly what concerns them.
What we never do
We don't resell your data or your contacts' data. We don't train any AI model on your contacts. We never access your CRM. And there is no advertising in bloo.Cards.
Built to recognised best practices
bloo.Cards follows OWASP best practices (access control, injection protection, data integrity) and undergoes regular internal audits. We claim no external certification we don't hold: we prefer to describe our measures precisely rather than display a logo.
Frequently asked questions
Where is my data hosted?
In the European Union. Development and hosting both take place in the EU.
Do you sign a data processing agreement (DPA)?
Yes. A data processing agreement is available on request at hello@bloo.cards.
Can bloo.Cards access my CRM?
No. The architecture is outbound only: bloo.Cards never has read or write access to your CRM.
How do I revoke an API key?
From the Developers section of your account, in one click. Revocation cuts off access immediately.
Are you ISO 27001 or SOC 2 certified?
We claim no certification we don't hold. We apply TLS, Argon2id, encryption at rest for sensitive credentials and OWASP best practices, and we describe our measures openly.
What happens if I delete my account?
Your data is erased according to our retention policy; backups then expire on their own cycle.
Questions about security?
Write to us for a DPA, the details of our technical measures or hosting: hello@bloo.cards. Contact us.
Your free card