Privacy Policy
Product: OIA Shield24 | Bitrix24 Marketplace App: infinitybht_llc.oia_shield24
1. Zero-Memory Data Streaming
OIA Shield24 is engineered as a pass-through edge proxy. Request payloads passing between third-party vendors and your Bitrix24 portal are streamed in zero-memory using standard `ReadableStream` interfaces (`body: request.body`). We do not store, index, or sell your CRM deals, leads, contact databases, or financial records.
2. Web Crypto AES-GCM Token Encryption
API keys and Bitrix24 OAuth access tokens are stored securely in an Encrypted Relational Database using AES-GCM symmetric encryption backed by the `MASTER_SECRET_KEY`. Proxy API keys are verified exclusively via deterministic SHA-256 hashes (`api_key_hash`), ensuring raw secrets are never readable in database backups.
3. Regional Data Residency & Location Hints
OIA Shield24 allows enterprise administrators to lock proxy endpoints to specific legal jurisdictions using Jurisdictional Location Hints:
weur — Western Europe (GDPR compliant processing)enam — Eastern North America (HIPAA compliant processing)apac — Asia-Pacific Jurisdiction4. SRE Telemetry & Automated 90-Day Evaporation
For Threat Intelligence monitoring, OIA Shield24 collects high-level metadata (HTTP status codes, latency in ms, caller IP address, and execution region). To guarantee data privacy, all analytics logs automatically expire and evaporate after 90 days.
5. GDPR Compliance & Data Rights
Bitrix24 administrators retain complete control over all data stored by OIA Shield24. You may request total data deletion at any time by uninstalling the application from your portal or contacting privacy@oiashield24.com.