Security, by design.
Your data and your network's data are hosted in the European Union, encrypted in transit, and stay under your control. Here is exactly how, without any certification badge we don't actually hold.
Hosted in the EU · GDPR · Outbound only to your CRM
European hosting and GDPR
Data in the EU
bloo.Cards is developed and hosted in the European Union, and your data is stored there. A few technical providers are based outside the Union (sign-in with Google, Apple or LinkedIn, e-mail delivery, AI reading of the cards you scan): these transfers are covered by GDPR safeguards and described in the privacy policy.
Controller and processor
MOLDEREZ-CONSULT SRL (Brussels) is the controller for your account, and the processor for the contact data you collect. Data processing agreement: annex to the Terms of Use; signable version: privacy@blcrds.com.
Your rights
Access, rectification, export and erasure from your account, at any time. Deleting your account erases your data according to our retention policy.
Encryption at every layer
In transit
All traffic runs over HTTPS (TLS). No page, no API call in the clear.
Passwords & tokens
Passwords are hashed with Argon2id, never stored in the clear. Session tokens are hashed with SHA-256.
CRM credentials encrypted at rest Available
A connected CRM's credentials are encrypted at rest (XChaCha20-Poly1305) with a key specific to your organisation, and are never shown again. Since 5 October 2026, your address book contacts (names, company, address, notes, email addresses and numbers) are also encrypted at rest, with a key specific to your account, as are exchange notes, reminder notes and the Wallet history.
An outbound-only architecture
bloo.Cards sends new entries to your systems. It never reads or modifies your CRM data. This principle keeps everything simpler: fewer accesses, fewer risks.
Keys under your control
Read-only bloo.Cards API key
The keys you generate (bc_live_…) let your tools read your new bloo.Cards contacts. They grant no write access.
Signed webhooks
Every outbound notification is signed (HMAC-SHA256) with a secret only you know: your system can verify it really comes from bloo.Cards.
Revocable at any time
A key is revoked in one click; the cut-off is immediate. Keys are never shown twice or stored in the clear: only their hashed fingerprint is kept.
Access to your account
Two-factor authentication
Enable two-step verification (TOTP) on your account, with an authenticator app.
Sessions & rate limiting
Sessions regenerated at login, limits on the number of attempts, a log of logins and sensitive actions.
Distinct roles
Separate owner, administrator and member rights for team accounts: everyone sees and does exactly what concerns them.
What we never do
We don't resell your data or your contacts' data. We don't train any AI model on your contacts. We never access your CRM. And there is no advertising in bloo.Cards.
Built to recognised best practices
bloo.Cards follows OWASP best practices (access control, injection protection, data integrity) and undergoes regular internal audits. We claim no external certification we don't hold: we prefer to describe our measures precisely rather than display a logo.
Frequently asked questions
Where is my data hosted?
In the European Union. Development and hosting both take place in the EU.
Do you sign a data processing agreement (DPA)?
Yes. The data processing agreement is annexed to the Terms of Use and applies to all accounts; a signable version is available for CORPORATE accounts on request at privacy@blcrds.com.
Can bloo.Cards access my CRM?
No. The architecture is outbound only: bloo.Cards never has read or write access to your CRM.
How do I revoke an API key?
From the Developers section of your account, in one click. Revocation cuts off access immediately.
Are you ISO 27001 or SOC 2 certified?
We claim no certification we don't hold. We apply TLS, Argon2id, encryption at rest of CRM credentials and address book contacts (one key per account) and OWASP best practices, and we describe our measures openly.
What happens if I delete my account?
Your data is erased according to our retention policy; backups then expire on their own cycle.
Questions about security?
Data processing agreement: annex to the Terms of Use; signable version: privacy@blcrds.com. For the details of our technical measures or hosting: hello@bloo.cards. Contact us.
Your free card