HUMINT

Privacy Policy

Last updated: 25 July 2026·Public policy URL: https://humint.digital/privacy

1. Who we are

This Privacy Policy explains how European Management Institute (“we”, “us”, “our”) collects, uses, and protects personal data when you use the HUMINT web application available at https://humint.digital and related APIs (the “Service”).

For the purposes of the EU General Data Protection Regulation (GDPR) and applicable data protection laws, the data controller is:

2. Scope

This policy applies to users of the Service (including administrators and authorised operators), visitors of public pages such as this Privacy Policy, and individuals whose information is lawfully processed through the Service on behalf of a customer organisation.

Where we process personal data on behalf of a customer under a separate agreement, that customer may act as an independent controller (or joint controller, where applicable). This policy describes our practices as provider of the Service.

3. Personal data we process

Depending on how the Service is used, we may process:

  • Account data: name, email address, authentication credentials (password hashes / biometric credentials), account settings, and role information.
  • Operational content: contacts, notes, documents, meeting recordings and transcriptions, calendar-related metadata, messages, tags, projects/tasks, and similar information that users upload or generate in the Service.
  • Technical / usage data: IP address, browser and device information, timestamps, security logs, and approximate product usage metrics needed to operate, secure, and improve the Service.
  • Support communications: information you send us by email or other support channels.

We do not intentionally collect special categories of personal data unless a user or customer chooses to include such information in content they store in the Service. Customers are responsible for ensuring they have a lawful basis to upload any such data.

4. Google user data

If you choose to connect a Google account, the Service may request access to selected Google APIs (for example Google Calendar and/or Gmail send functionality) solely to provide features you explicitly enable, such as syncing calendar events or sending email on your behalf.

Google API Services User Data Policy (Limited Use). Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • Google user data is used only to provide or improve user-facing features of the Service that are prominent in the interface.
  • We do not sell Google user data, and we do not use it for advertising, credit scoring, or unrelated profiling.
  • We do not transfer Google user data to third parties except as necessary to provide or improve the Service features you request, to comply with applicable law, or as part of a merger/acquisition with notice where required — and only under appropriate contractual protections.
  • Human access to Google user data is limited to cases such as user-requested support, security investigations, legal compliance, or with your explicit consent, and is subject to internal access controls.

You may revoke Google access at any time from your Google Account permissions (myaccount.google.com/permissions) and/or by disconnecting the integration inside the Service.

5. Purposes and legal bases (GDPR)

We process personal data for the following purposes and legal bases (Art. 6 GDPR):

  • Providing the Service (account creation, login, storage of operational content, AI-assisted features you trigger) — performance of a contract (Art. 6(1)(b)).
  • Optional integrations (e.g. Google Calendar / Gmail) — consent (Art. 6(1)(a)), which you may withdraw at any time without affecting prior lawful processing.
  • Security, abuse prevention, and service integrity legitimate interests (Art. 6(1)(f)), balanced against your rights.
  • Legal obligations (e.g. responding to lawful requests, accounting/tax where applicable) — Art. 6(1)(c).
  • Product improvement and diagnostics using aggregated or limited technical logs — legitimate interests (Art. 6(1)(f)).

6. How we use AI features

Some features may send content you provide (for example transcripts, notes, or prompts) to artificial intelligence / machine-learning providers to generate analyses, summaries, or similar outputs. Such processing is performed to deliver the feature you requested. We configure providers, where available, not to use your content to train public models for unrelated purposes. You should avoid submitting data that you are not authorised to process.

7. Sharing and processors

We use trusted service providers (processors) to host and operate the Service, which may include cloud hosting, databases, object storage, email delivery, authentication support, and AI inference providers. These providers process data only on our instructions and under appropriate data-processing agreements.

We do not sell personal data. We may disclose data if required by law, to protect rights and safety, or in connection with a corporate transaction subject to applicable safeguards.

8. International transfers

Personal data may be processed in the European Economic Area and, where necessary, in other countries by providers that offer an adequate level of protection or appropriate safeguards (such as Standard Contractual Clauses) in accordance with GDPR Chapter V.

9. Retention

We retain personal data only for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Account and operational content are generally retained until deleted by an authorised user or until the customer account is closed, subject to backup cycles and mandatory retention periods. Security logs are retained for a limited period consistent with security and operational needs.

Google OAuth tokens are stored only while the integration remains connected and are deleted or invalidated when you disconnect the integration or delete your account.

10. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), access controls, authentication, and least-privilege administrative access. No method of transmission or storage is completely secure; we work to continuously improve our safeguards.

11. Your rights

If GDPR or similar laws apply, you may have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase data (“right to be forgotten”), subject to legal exceptions;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with a supervisory authority in your country of residence or work.

To exercise these rights, contact tech@europeanmanagement.eu. We may need to verify your identity before fulfilling a request. If you use the Service through an organisation, please also contact your organisation's administrator, who may control your account data.

12. Cookies and similar technologies

The Service uses essential storage (such as authentication tokens in local browser storage) required to keep you signed in and to operate core functionality. We do not use third-party advertising cookies. If non-essential analytics cookies are introduced in the future, we will update this policy and obtain consent where required.

13. Children

The Service is intended for professional / business use by adults and is not directed to children under 16. We do not knowingly collect personal data from children.

14. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be communicated through the Service or by other appropriate means. Continued use of the Service after an update constitutes acceptance of the revised policy where permitted by law.

15. Contact

Questions about this Privacy Policy or our data practices: tech@europeanmanagement.eu.

Controller: European Management Institute. Service: HUMINT (https://humint.digital).