Privacy Policy

Application: API ConnectorLicensor: HUNG DAO VUONG ACADEMY JOINT STOCK COMPANYEffective date: October 2, 2026

This Privacy Policy explains what data API Connector (the "Application") processes, why, how long it is kept and how it is deleted. The Application is operated by HUNG DAO VUONG ACADEMY JOINT STOCK COMPANY ("we", "us"). It applies to every Bitrix24 account (the "account") on which the Application is installed and to the users of those accounts.

1. Roles

For CRM and workflow data that an account sends through the Application, the organization that owns the account is the data controller and we act as a processor on its behalf. For the account and security data we need to operate the Application (installation records, sessions, logs) we act as the controller.

2. Data we store

  • Account record. Bitrix24 account domain, member ID, account name, installed application version and the registration status of the robots.
  • Account OAuth credentials. The access and refresh tokens Bitrix24 issues to the Application for the administrator who installed it and, on Bitrix24 Market installations, for the Application's system user, plus the application token Bitrix24 uses to sign its requests to us. They are used only to call the Bitrix24 REST API for your account and to verify that requests really come from Bitrix24. They are never shown in the interface and never passed to robot code.
  • User sessions. When an account user opens the Application: Bitrix24 user ID, name, email address (when Bitrix24 provides it), administrator flag and access roles, that user's Bitrix24 OAuth tokens (encrypted with AES-GCM), a random session identifier, and creation and last-activity timestamps. If a user chooses to set a password for signing in outside Bitrix24, we store only a bcrypt hash of it.
  • Credentials vault. API keys, bearer tokens and basic-auth secrets that a account administrator saves for robots to use. They are encrypted with AES-GCM, are never returned by any API or shown again after saving, and are only decrypted on our server at the moment a robot makes the corresponding request.
  • Robot configurations. Code robot source code, input variable names and output mappings that administrators create.
  • Job log. One entry per robot run: robot type, target Bitrix24 method or external URL, request parameters or body as resolved by Bitrix24 (which can include CRM field values), workflow and document identifiers, HTTP status, a truncated copy of the response, the values returned to the workflow and any error message.
  • REST call log. One entry per Bitrix24 REST API call the Application makes: method, HTTP status, error code, duration and a truncated copy of the request and response with tokens and secrets removed. Bitrix24 Market requires applications to keep such a log.
  • Technical logs. Server logs with timestamps, request paths and error messages, used for troubleshooting. We do not write OAuth tokens or vault secrets to these logs.

3. CRM data passing through robots

The Application does not copy your CRM database. It processes only the data that a workflow passes to a robot and the data returned by the Bitrix24 methods or external URLs that your administrators configure. That data is processed in memory to run the robot and is kept afterwards only in the job log and REST call log described above. When a robot is configured to send data to an external URL, that data leaves our control and is handled under the terms and privacy policy of the receiving service.

4. Why we process data

  • to install the Application, run the robots and return results to your workflows (performance of our agreement with you);
  • to authenticate users and protect the Application and your account against misuse (legitimate interest in security);
  • to troubleshoot failed jobs and answer support requests (legitimate interest);
  • to meet the logging requirements of the Bitrix24 Market (legal and contractual obligation).

We do not sell data, use it for advertising, build marketing profiles or use analytics or tracking services in the Application.

5. Cookies

The Application sets a strictly necessary, HttpOnly session cookie that keeps you signed in, and a preferences cookie that remembers interface settings such as theme and sidebar state. No advertising or third-party tracking cookies are used.

6. Where data is stored and who can access it

Data is stored in a PostgreSQL database on a server operated by our hosting provider. Daily database backups are kept in private Cloudflare R2 storage. Access is limited to the people who operate the Application, for operation, security and support purposes. We disclose data to authorities only when required by law. Inside an account, the job log is visible only to account administrators.

7. Retention

  • Finished job log entries are deleted automatically after 14 days.
  • REST call log entries are deleted automatically after 7 days.
  • Database backups are deleted automatically after 30 days, so deleted data disappears from backups within that period.
  • All other data is kept while the Application is installed on the account, then handled as described in the next section.

8. Deletion when the Application is uninstalled

When a account administrator uninstalls the Application, Bitrix24 notifies us and we act immediately:

  • If the administrator chooses to delete the application data during uninstallation, every record for that account is permanently deleted: account record, OAuth credentials, user sessions and passwords, credentials vault, robot configurations, job log and REST call log.
  • Otherwise, all OAuth credentials and the application token are erased, all user sessions are deleted and pending robot jobs are cancelled. Robot configurations, vault entries and logs are kept so that settings are restored if the Application is installed again; logs still expire on the schedule above. You can ask us to delete the remaining data at any time through the channels on the Support page.

9. Security

Traffic is encrypted with HTTPS. Requests from Bitrix24 are verified before any data is stored. User tokens and vault secrets are encrypted at rest. Robot code runs in an isolated sandbox without access to our environment, database or tokens; its network requests are HTTPS-only and requests to internal network addresses are blocked. Every database query is scoped to a single account.

10. Your rights

Depending on the law that applies to you, you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to lodge a complaint with a data protection authority. Because account data belongs to the organization that owns the account, we may forward requests about CRM data to that organization's administrator. To exercise your rights, contact us using the details below.

11. Children

The Application is a business tool and is not directed at children.

12. Changes to this policy

We may update this Privacy Policy by publishing a new version at this address with a new effective date.

13. Contact