Skip to content
Huematte

Your customers' data, handled with the same care as your policies.

An agent that can act on accounts, orders and bookings has to be bounded tightly. Here is what we store, how it is protected, who can see it, and what each agent is and isn't allowed to do.

Data handling

What's stored, and for how long.

We store only what the agent needs to answer and what you need to review its work. Records such as orders and bookings are read live through the access you grant, not copied in bulk.

Conversations

Messages between your customers and the agent, and any handoff notes.

Kept for your workspace retention period, then deleted.

Detected context

The intent and the record values the agent looked up to answer, such as an order status or booking time.

Stored with the conversation it belongs to.

Grounding sources

The policies, articles and rules you connect, with version history.

Kept while connected. Removed when you disconnect a source.

Action log

Every action the agent took or prepared, with the limit and policy involved.

Kept for your workspace retention period.

Retention you set

Choose the retention period for conversations per workspace. Deleted data is removed from active systems and then from backups on their normal cycle.

Access scope

Roles control who in your team can view conversations, change policies, edit limits or export data. Access is logged.

Data requests

Export or delete a specific customer's conversations on request, so you can respond to your own customers' privacy requests.

Protection

Encrypted in transit and at rest.

Standard protections, applied everywhere, with nothing left as an opt-in.

In transit

All traffic between customers, your systems and the service is encrypted with TLS.

At rest

Stored conversations, sources and logs are encrypted at rest.

Credentials

Keys and tokens you provide for record access are stored encrypted and never shown in full after entry.

Least privilege

Ask for read access first. Write access is only needed for the actions you choose to automate.

Action boundaries

Every action is configured and capped by you.

An agent can only take the actions you switch on, up to the limits you set. Anything beyond a limit is prepared and routed to a person for approval.

Returns & Orders

Refund without approval
Up to your limit
Exchanges
Inside your window
Order edits
Before dispatch only

Billing & Accounts

Account credit
Up to your limit
Plan changes
On or off
Card refunds
Always a person

Scheduling

Reschedules
Up to your count
Bookings
Within clinician rules
Clinical questions
Always staff

Healthcare deployments

The Scheduling agent works with scheduling and administrative data only: names, contact details, appointment times, clinicians and locations. It does not need, and should not be given, access to clinical records.

Health-data handling and any regulatory requirements that apply to your clinic or region are reviewed and confirmed with you before launch. Clinical questions are never answered by the agent and are passed straight to your staff.

Compliance posture

Current status only. No borrowed badges.

We describe the controls we have in place today, and we don't display certification logos for audits that haven't been completed. If your procurement process needs a security questionnaire, a data processing agreement or details of our sub-processors, ask us and we'll share what applies to your deployment.

If you believe you've found a security issue, please report it through the contact form with the subject “Security”. We review every report and will respond to let you know what happens next.