Draft notice

This is a v0.1 self-prepared draft. It reflects our intended practices and is published in good faith, but it is not legal advice and has not been reviewed by counsel. Contact legal@henosis.solutions with questions.

Privacy Policy

Last updated: 2026-05-19 · Effective: 2026-05-22

This Privacy Policy explains how Henosis Technologies, LLC ("Henosis", "we") collects, uses, and shares personal information through the Henosis application at app.henosis.solutions and the marketing website at henosis.solutions (together, the "Service").

Two roles. For information about our visitors, prospects, and account holders, Henosis is a controller. For "Customer Data" that a business customer submits into the app about its contacts and prospects, the customer is the controller and Henosis is a processor acting on the customer’s instructions under our Terms of Service and Data Processing Addendum.

1. Information we collect

You provide:

  • Account & profile data: name, work email, company, role, password (hashed), profile picture.
  • Billing data: handled by Stripe; we receive billing metadata (plan, seat count, last4, status) but do not store full card numbers.
  • Customer Data: records you input into the app: contacts, accounts, deals, proposals, notes, tasks, and communications. This is controlled by your organization.
  • Connected mailbox data: if an Authorized User connects a Microsoft mailbox, we process email metadata and message content via Nylas to sync and send messages and to record engagement (opens/clicks) you initiate.
  • Support & marketing: messages you send us, and information submitted via marketing-site forms (e.g., demo requests, newsletter signup).

Collected automatically:

  • Usage & device data: log data, IP address, browser/device, pages and features used, timestamps, error diagnostics (via Sentry), and product analytics where enabled (consent-gated).
  • Cookies: see §7.

We do not knowingly collect data from anyone under 18, and the Service is not directed to consumers.

2. How we use information

  • Provide, operate, secure, and support the Service;
  • Authenticate users and enforce tenant isolation;
  • Process payments and manage subscriptions and seats;
  • Provide AI-assisted features (see §5);
  • Send and sync email you initiate, and record engagement you initiate;
  • Monitor, debug, and improve the Service;
  • Communicate service, security, and (with your choices) marketing messages;
  • Comply with law and enforce our Terms.

Legal bases (GDPR/UK GDPR): performance of a contract (providing the Service); legitimate interests (securing, debugging, improving the Service; B2B communications); consent (non-essential cookies/analytics and marketing email); and compliance with legal obligations.

3. How we share information

We are not in the business of selling personal information and we do not sell it. We share it with:

Sub-processors (current as of 2026-05-19):

Sub-processorPurposeLocation
SupabaseDatabase, auth, storage, edge functionsUS
StripeBilling & paymentsUS
ResendTransactional + marketing email deliveryUS
NylasPer-user email send/sync + engagement trackingUS
VercelFrontend hosting & CDNMulti-region
OpenAIAI features (prompt processing)US
SentryError tracking & diagnosticsUS

We will keep a current list at /legal and give notice of changes as described in our DPA. We also share information to comply with law or valid legal process, to protect rights and safety, and in connection with a merger, acquisition, or asset sale (with continuity of this Policy).

4. International transfers

The Service is hosted primarily in the United States. If you access it from outside the US, your information will be transferred to and processed in the US. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (available via our DPA) for transfers of EEA/UK personal data.

5. AI features

Certain features (e.g., the AI assistant, "Log this", "Brief me", subject suggestions, import mapping, project planning) send prompts and limited Customer Data to OpenAI’s API to generate outputs. We use OpenAI’s API platform; per OpenAI’s API terms, data submitted via the API is not used to train OpenAI’s models. AI outputs may be inaccurate; they are tools, not advice.

6. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service, then for a limited period as required for legal, accounting, security, or dispute-resolution purposes. Customer Data is retained per your organization’s instructions and our Terms §14 (30-day post-termination export window, then deletion; backups expire on their normal cycle). You may request deletion as described below.

7. Cookies and analytics

We use strictly necessary cookies (authentication/session, security) that load without consent. We use functional/analytics cookies only with consent via our cookie banner. No non-essential analytics or marketing tags fire before consent. Details and categories will be listed in our Cookie Policy at /cookies. You can manage preferences via the banner or your browser.

8. Your rights and choices

Depending on your location (e.g., GDPR/UK GDPR, California CCPA/CPRA, and other US state laws), you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, and to opt out of "sale"/"sharing" or targeted advertising (we do not sell or share for cross-context advertising). You may also withdraw consent where processing is consent-based.

  • Account holders / visitors: exercise rights by emailing privacy@henosis.solutions. We will verify and respond within the timeframe required by applicable law.
  • Individuals whose data is in a customer’s account (Customer Data): the customer is the controller: direct your request to that organization; we will assist them as a processor.
  • Marketing email: every marketing message includes a one-click unsubscribe; you can also email us.

We will not discriminate against you for exercising privacy rights.

9. Security

We use technical and organizational measures including encryption in transit (TLS), encryption at rest, row-level multi-tenant isolation, restricted production access (limited to founders), audit logging, and error monitoring. No system is perfectly secure; we cannot guarantee absolute security. We will notify affected parties and regulators of a personal-data breach as required by applicable law (e.g., within 72 hours under GDPR where applicable).

10. Compliance specifics

  • GDPR/UK GDPR: legal bases in §2; data-subject rights in §8; transfer safeguards in §4; DPA available to business customers on request. We do not currently require an EU representative or DPO at our scale.
  • California (CCPA/CPRA): categories collected are described in §1; purposes in §2; we do not sell or share personal information for cross-context behavioral advertising; California residents have access/delete/correct/opt-out rights exercisable per §8.
  • Other US state laws (Texas, Virginia, Colorado, Connecticut, etc.): this Policy is intended to satisfy these comprehensively rather than per-state.
  • CAN-SPAM: our marketing email includes our identity, a postal contact, and one-click unsubscribe.

11. Changes

We may update this Policy. Material changes will be notified by email or in-app before they take effect; the "Last updated" date will change. Continued use after the effective date constitutes acceptance where permitted by law.

12. Contact

Henosis Technologies, LLC
Privacy requests: privacy@henosis.solutions
Legal notices: legal@henosis.solutions
Office: Dallas, TX, United States

v0.1 self-prepared draft, 2026-05-19. Not legal advice.