OIA Shield24 Privacy Policy
← All Legal Docs Install On Bitrix24
Terms of Service Privacy Policy EULA System Specs & Limits Disclaimer
Effective: August 5, 2026 Last Updated: August 5, 2026 GDPR Compliant

Privacy Policy

Product: OIA Shield24 | Bitrix24 Marketplace App: infinitybht_llc.oia_shield24

1. Zero-Memory Data Streaming

OIA Shield24 is engineered as a pass-through edge proxy. Request payloads passing between third-party vendors and your Bitrix24 portal are streamed in zero-memory using standard `ReadableStream` interfaces (`body: request.body`). We do not store, index, or sell your CRM deals, leads, contact databases, or financial records.

2. Web Crypto AES-GCM Token Encryption

API keys and Bitrix24 OAuth access tokens are stored securely in an Encrypted Relational Database using AES-GCM symmetric encryption backed by the `MASTER_SECRET_KEY`. Proxy API keys are verified exclusively via deterministic SHA-256 hashes (`api_key_hash`), ensuring raw secrets are never readable in database backups.

3. Regional Data Residency & Location Hints

OIA Shield24 allows enterprise administrators to lock proxy endpoints to specific legal jurisdictions using Jurisdictional Location Hints:

    weur — Western Europe (GDPR compliant processing) enam — Eastern North America (HIPAA compliant processing) apac — Asia-Pacific Jurisdiction

4. SRE Telemetry & Automated 90-Day Evaporation

For Threat Intelligence monitoring, OIA Shield24 collects high-level metadata (HTTP status codes, latency in ms, caller IP address, and execution region). To guarantee data privacy, all analytics logs automatically expire and evaporate after 90 days.

5. GDPR Compliance & Data Rights

Bitrix24 administrators retain complete control over all data stored by OIA Shield24. You may request total data deletion at any time by uninstalling the application from your portal or contacting privacy@oiashield24.com.