Security & privacy

Security, by design.

Your data and your network's data are hosted in the European Union, encrypted in transit, and stay under your control. Here is exactly how, without any certification badge we don't actually hold.

Hosted in the EU · GDPR · Outbound only to your CRM

European hosting and GDPR

Data in the EU

bloo.Cards is developed and hosted in the European Union, and your data is stored there. A few technical providers are based outside the Union (sign-in with Google, Apple or LinkedIn, e-mail delivery, AI reading of the cards you scan): these transfers are covered by GDPR safeguards and described in the privacy policy.

Controller and processor

MOLDEREZ-CONSULT SRL (Brussels) is the controller for your account, and the processor for the contact data you collect. Data processing agreement: annex to the Terms of Use; signable version: privacy@blcrds.com.

Your rights

Access, rectification, export and erasure from your account, at any time. Deleting your account erases your data according to our retention policy.

Encryption at every layer

In transit

All traffic runs over HTTPS (TLS). No page, no API call in the clear.

Passwords & tokens

Passwords are hashed with Argon2id, never stored in the clear. Session tokens are hashed with SHA-256.

CRM credentials encrypted at rest Available

A connected CRM's credentials are encrypted at rest (XChaCha20-Poly1305) with a key specific to your organisation, and are never shown again. Since 5 October 2026, your address book contacts (names, company, address, notes, email addresses and numbers) are also encrypted at rest, with a key specific to your account, as are exchange notes, reminder notes and the Wallet history.

An outbound-only architecture

bloo.Cards sends new entries to your systems. It never reads or modifies your CRM data. This principle keeps everything simpler: fewer accesses, fewer risks.

Keys under your control

Read-only bloo.Cards API key

The keys you generate (bc_live_…) let your tools read your new bloo.Cards contacts. They grant no write access.

Signed webhooks

Every outbound notification is signed (HMAC-SHA256) with a secret only you know: your system can verify it really comes from bloo.Cards.

Revocable at any time

A key is revoked in one click; the cut-off is immediate. Keys are never shown twice or stored in the clear: only their hashed fingerprint is kept.

Access to your account

Two-factor authentication

Enable two-step verification (TOTP) on your account, with an authenticator app.

Sessions & rate limiting

Sessions regenerated at login, limits on the number of attempts, a log of logins and sensitive actions.

Distinct roles

Separate owner, administrator and member rights for team accounts: everyone sees and does exactly what concerns them.

What we never do

We don't resell your data or your contacts' data. We don't train any AI model on your contacts. We never access your CRM. And there is no advertising in bloo.Cards.

Built to recognised best practices

bloo.Cards follows OWASP best practices (access control, injection protection, data integrity) and undergoes regular internal audits. We claim no external certification we don't hold: we prefer to describe our measures precisely rather than display a logo.

Frequently asked questions

Where is my data hosted?

In the European Union. Development and hosting both take place in the EU.

Do you sign a data processing agreement (DPA)?

Yes. The data processing agreement is annexed to the Terms of Use and applies to all accounts; a signable version is available for CORPORATE accounts on request at privacy@blcrds.com.

Can bloo.Cards access my CRM?

No. The architecture is outbound only: bloo.Cards never has read or write access to your CRM.

How do I revoke an API key?

From the Developers section of your account, in one click. Revocation cuts off access immediately.

Are you ISO 27001 or SOC 2 certified?

We claim no certification we don't hold. We apply TLS, Argon2id, encryption at rest of CRM credentials and address book contacts (one key per account) and OWASP best practices, and we describe our measures openly.

What happens if I delete my account?

Your data is erased according to our retention policy; backups then expire on their own cycle.

Questions about security?

Data processing agreement: annex to the Terms of Use; signable version: privacy@blcrds.com. For the details of our technical measures or hosting: hello@bloo.cards. Contact us.

Your free card