Legal

Privacy Policy

Last updated: July 22, 2026

This Privacy Policy describes how HUMAINLY Inc (“Humainly”, “we”, “us”) collects, uses, shares, and protects personal data when you use humainlyPRM — our AI-native relationship-intelligence and CRM platform — together with our websites, applications, and related services (the “Services”).

1. Who we are & scope

HUMAINLY Inc is the provider of humainlyPRM. This policy applies to personal data we process about visitors to our websites, people who request a demo or apply for a role, users of the platform, and individuals whose information appears in a customer’s CRM, mailbox, calendar, or connected accounts. If you use humainlyPRM through an organization (your employer), that organization administers your account and its data.

2. Controller and processor roles

We act as a data controller for personal data we determine the purposes of — for example, website visitors, demo and job applicants, our direct account holders, and our own marketing and business records.

We act as a data processor for the customer data our customers put into, or connect to, the platform — CRM records, and the email, calendar, contacts, and files a user connects from Google or Microsoft. For that data the customer (your organization) is the controller, and we process it on their documented instructions under our agreement.

3. Personal data we collect

Data you provide. Account and profile details (name, work email, company, role), demo-request and job-application form submissions, support communications, and any content you enter into the platform.

Data collected automatically. Usage, device, and log data (pages viewed, features used, IP address, browser, timestamps) and similar technical information, some via cookies and similar technologies.

Data from connected services. When you connect an account, we access data you authorize: email, calendar events, contacts, and (on request) documents in Drive, OneDrive or SharePoint from Google or Microsoft — which the assistant reads to answer you, and can create or update when you confirm a draft; and CRM records synced from Salesforce. Address-book contacts are added to your CRM only if your workspace has enabled contact sync and you switch it on for your own account. We access only what the permissions you grant allow.

Data from your organization and others. Your employer, colleagues, and the people you communicate with may appear in the data we process on the customer’s behalf.

4. Google & Microsoft user data

humainlyPRM connects to Google and Microsoft using the minimum permissions needed for the features you enable:

DataPermissionPurpose
Email messages (read)gmail.readonly / Mail.ReadWriteCapture email into your CRM so the full relationship history and the AI assistant work. Microsoft requires read-write on mail in order to also send on your behalf.
Send emailgmail.send / Mail.SendSend or reply on your behalf only when you explicitly review a draft and click Send.
Calendar events (read/write)calendar.events / Calendars.ReadWriteCapture meetings and create or modify calendar events you explicitly confirm.
Contacts (read)contacts.readonly / Contacts.ReadMatch your communications to the right people and accounts. Where your workspace has enabled contact sync and you switch it on for your own account, we also add people from that account’s address book as contacts in your CRM. This is off unless you turn it on, and a person whose email address is already in your CRM is skipped — never merged or overwritten.
Files — Drive, OneDrive and SharePoint (read and write)drive / Files.ReadWrite.AllLet the AI assistant find and read documents you ask about, and create or update a document only when you review a draft and click Create or Update. The assistant never writes on its own, and we do not store your file contents.

humainlyPRM’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements, and our use of Microsoft Graph data is likewise limited to providing the features you connect it for. We do not sell this data, do not use it for advertising, do not use it to train generalized AI models, and do not allow humans to read it except with your permission, for security, to comply with law, or as strictly necessary to operate the Services.

5. How we use data

We use personal data to: provide, operate, and secure the Services; capture and organize your communications and relationships; power the AI assistant and insights; personalize and improve the product; provide support; process demo and job-application requests; send service and (where permitted) marketing messages; detect and prevent fraud and abuse; and comply with legal obligations.

6. AI processing

The platform uses artificial intelligence to draft messages, answer questions, summarize, and surface insights over your data. To do this we send relevant content to trusted AI model providers — Anthropic and OpenAI — that process it solely to return a result to us. Their API terms prohibit training on customer content: Anthropic’s Commercial Terms state that “Anthropic may not train models on Customer Content from Services,” and OpenAI states that data sent to its API “is not used to train or improve OpenAI models” unless we explicitly opt in, which we do not. We do not train any model on your content ourselves, and AI features operate on a per-customer basis within that customer’s data.

7. Legal bases (GDPR/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Services); legitimate interests (to operate, secure, and improve the Services and maintain business relationships, balanced against your rights); consent (where required, e.g. certain cookies and marketing); and legal obligation. For data we process as a processor, the customer is responsible for establishing the lawful basis.

8. How we share data & sub-processors

We do not sell personal data. We share it only with:

Service providers / sub-processors who process data on our behalf, including: Nylas (email & calendar connectivity), Recall.ai (meeting capture), Amazon Web Services (hosting/infrastructure), Anthropic and OpenAI (AI processing), and email-delivery, error-monitoring and analytics providers. A current sub-processor list is available on request.

Your organization and the users it authorizes; professional advisors (legal, accounting); authorities where required by law; and a successor entity in a merger, acquisition, or asset sale.

9. Cookies & analytics

Our websites use cookies and similar technologies for essential functionality, to remember preferences, and to understand usage. You can control non-essential cookies through your browser or any cookie controls we provide.

10. Marketing communications

We may send you marketing about our Services where permitted. You can opt out at any time using the unsubscribe link or by contacting us. Transactional and service messages (e.g. security, billing, product notices) are not marketing and may still be sent.

11. International transfers

We may process and store data in countries other than yours, including the United States. Where we transfer personal data out of the UK/EEA, we use an appropriate safeguard such as an adequacy decision or Standard Contractual Clauses.

12. Data retention

We retain personal data for as long as needed for the purposes above. Account data is kept for the life of the account and a reasonable period afterward for legal and operational needs. Data connected or captured from your accounts is retained while the connection is active, until you delete it or request erasure. We may keep aggregated or anonymized data that no longer identifies you.

13. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit and at rest, encrypted storage of connection tokens, tenant isolation, and access controls. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.

14. Your rights

Subject to applicable law, you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing or withdraw consent. Where we process data on behalf of a customer — your employer or the organization that gave you access — that customer directs erasure: we refer your request to them and act on their instruction. On an authorized erasure request we delete the data from our systems, including captured message content, AI embeddings, activity and tracking records, and raw provider data. We respond within one month of a verified request and will tell you if we need longer because the request is complex. Deleted records may remain in encrypted backups until those expire on their normal schedule. To exercise rights, contact infra@humainlyprm.com. You may also lodge a complaint with your local data-protection authority.

15. Children

The Services are for business use and are not directed to children. We do not knowingly collect personal data from anyone under 18.

16. Third-party links

Our Services may link to or integrate with third-party sites and services that have their own privacy practices. This policy does not cover them; please review their policies.

17. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date, and provide additional notice where required.

18. Contact us

HUMAINLY Inc
169 Madison Ave STE 66493, New York, NY 10016
infra@humainlyprm.com