Certifications & Compliance
Humind maintains compliance with applicable regulations and pursues industry-recognized certifications. The table below reflects the current status of each framework.
| Framework / Certification | Scope | Status | Details |
|---|---|---|---|
| RGPD | All personal data processing | Compliant | Privacy by design, DPA available, DPO appointed. All data stored and processed in the EU. |
| AI Act | AI Shopping Assistant | Compliant | Classified as limited-risk AI system. Transparency obligations met: users are informed they interact with an AI. |
| CCPA | US-based end users | Compliant | Compliant with the California Consumer Privacy Act. Privacy rights of California residents are fully supported. |
Our infrastructure providers (compute, database, AI) hold SOC 2 Type II, ISO 27001, and CSA STAR certifications.
AI Security
Humind's AI shopping assistant is built with security, transparency, and accuracy as core requirements. This section details our AI architecture, data handling, and safeguards.
Humind's AI assistant is designed to provide reliable, contextualized responses. For each question, the AI draws on the merchant's product catalog and configured knowledge base to generate accurate and relevant answers. This ensures responses are sourced and specific to each brand.
Humind operates under a Zero Data Retention policy for all LLM interactions:
- Our LLM provider is configured in Zero Data Retention mode. No prompts, completions, or embeddings are stored by the provider.
- Conversation data processed by the LLM exists only in memory for the duration of the request and is discarded immediately after the response is generated.
- Customer conversations are never used to train, fine-tune, or improve any AI model — neither ours nor our providers'.
Humind's Factual Mode ensures the AI only provides verifiable, source-backed responses:
- Every response is grounded in retrieved product data. The AI cites specific products and attributes from the merchant's catalog.
- When the AI lacks sufficient information to answer a question, it explicitly states that it cannot answer rather than generating speculative content.
- Guardrails prevent the AI from making claims about pricing, availability, or product specifications that are not present in the indexed catalog data.
Multiple layers of defense protect against LLM-specific attack vectors:
- Prompt injection protection: defense-in-depth mechanisms prevent end users from overriding the AI's behavior.
- Output guardrails: automated controls prevent the AI from disclosing internal instructions or information outside its designated scope.
- Scope limitation: the AI is restricted to the merchant's product catalog and configured knowledge base. It cannot access external data or perform actions outside its defined role.
- Monitoring: all AI interactions are logged (without PII) for quality assurance, anomaly detection, and continuous improvement of guardrails.
Humind's AI shopping assistant is classified as a limited-risk AI system under the EU AI Act (Regulation 2024/1689):
- Transparency: end users are clearly informed that they are interacting with an AI system, not a human agent.
- Human oversight: merchants retain full control over the AI's knowledge base, behavior configuration, and can disable the assistant at any time.
- Documentation: technical documentation on the AI system's capabilities, limitations, and intended use is maintained and available upon request.
Humind uses an LLM-as-a-Judge system where a dedicated evaluation model continuously assesses the quality and safety of AI-generated responses:
- Response quality evaluation: each AI response is automatically assessed for relevance, accuracy, and completeness against the retrieved product data.
- Hallucination detection: a dedicated evaluation model verifies that generated responses do not contain fabricated information or claims unsupported by the source data.
- Inappropriate content filtering: responses are screened to block off-topic, offensive, or non-compliant content before reaching the end user.
Infrastructure & Cloud
Humind's infrastructure runs on enterprise-grade cloud services hosted in Europe (Paris).
European hosting
Data hosted in Europe (Paris) on enterprise-grade cloud services. No transfer outside the European Union.
Encryption
AES-256 encryption at rest and TLS 1.2+ in transit. Secure key management with least-privilege access policies.
Network Protection
DDoS protection, WAF rules, and TLS termination via a global CDN. Secured CI/CD pipelines with secret scanning and dependency review.
Data Isolation
Strict data isolation between merchants. Each merchant can only access their own data.
Backups
Continuous backups with point-in-time recovery and periodic restore tests. Replication within the European Union for disaster recovery.
Data Protection
Humind processes personal data on behalf of merchants in compliance with the GDPR. This section describes roles, data flows, and privacy safeguards.
Humind
Data ProcessorHumind processes personal data strictly on behalf of merchants, following their instructions and the terms defined in the Data Processing Agreement (DPA).
Merchant
Data ControllerThe merchant determines the purposes and means of processing personal data of their end users. They are responsible for obtaining appropriate consent and informing their customers.
- Conversation data: questions asked to the AI assistant and generated responses
- Navigation data: pages visited, products viewed, interaction timestamps
- Technical data: browser type and device information. The IP address is not stored: it is only used in memory to derive a coarse location.
- Identification data: name, email, phone number or order number, only if the visitor shares them spontaneously in the conversation (the assistant never asks for them)
End users can exercise their rights by contacting the merchant (data controller) or by writing to Humind's DPO at dpo@thehumind.com. Humind supports the following rights:
- Right of access: obtain a copy of personal data held
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request deletion of personal data
- Right to restriction: limit the processing of personal data
- Right to data portability: receive data in a structured, machine-readable format
Conversation data (transcripts, attachments, satisfaction ratings, contact records) is kept in the active database for 13 months by default from the visitor's last interaction, then deleted automatically. The merchant may request a shorter period, or a longer one under its own responsibility. At the end of the contract, data is returned on request and then deleted within 30 days. LLM interactions are not retained (Zero Data Retention).
Data is hosted and processed exclusively in France and the European Union. No transfer outside the European Economic Area.
The Humind widget sets no cookies and performs no cross-site tracking. It relies only on strictly functional trackers stored in the browser (localStorage / sessionStorage), exempt from consent under Article 82 of the French Data Protection Act: a pseudonymous visitor identifier (13 sliding months), a tab-scoped session identifier, conversation resume data (deleted 90 days after last activity) and, if the merchant enables the consent module, the visitor's choice (13 months). Usage measurement (PostHog Cloud EU) runs without cookies, without storage and without any visitor identifier.
Sub-processors
| Name | Service | Location | Purpose |
|---|---|---|---|
| Microsoft Ireland Operations Limited | Azure (hosting, storage, AI Foundry) | Europe (France Central, Paris) | AI response generation (Zero Data Retention), hosting and storage |
| MongoDB Atlas | Database | Europe (Paris) | Product catalog, conversation history, analytics |
| PostHog | PostHog Cloud EU | Europe (Frankfurt) | Widget usage measurement (anonymous events, no cookies, no visitor identifier) |
| Microsoft Ireland Operations Limited | Azure Application Insights | Europe | Technical logs and service telemetry |
Availability & Continuity
Humind is designed for high availability, with redundancy provided within the European Union.
SLA 99.9%
Committed uptime of 99.9% for production environments, measured monthly. SLA terms are defined in each merchant's service agreement.
Status Page
Real-time service monitoring with automated alerts for service degradation. Incident history available upon request.
View Status Page arrow_forwardPlanned maintenance windows are scheduled outside peak business hours (preferably between 10 pm and 6 am, Paris time) and communicated at least 72 hours in advance by email.
Organizational Security
Security is embedded in our organization through policies, training, and access controls.
Information Security Policy (PSSI)
Comprehensive information security policy covering asset management, access control, incident management, business continuity, and supplier relationships. Reviewed annually.
Security Training
All employees complete security awareness training upon onboarding and annually thereafter. Development team members receive additional training on secure coding practices and OWASP Top 10.
Access Control
Principle of least privilege enforced across all systems. Multi-factor authentication (MFA) required for all internal access. Access reviews conducted quarterly.
Confidentiality Agreements
All employees and contractors sign non-disclosure agreements before accessing any company systems or customer data.
Incident Reporting
Internal incident reporting process with defined escalation paths. Security incidents are documented, investigated, and remediated with a post-mortem review. Affected merchants are notified without undue delay and no later than 48 hours after we become aware of the breach, so that they can meet their own 72-hour deadline towards their supervisory authority.
Penetration Testing
Penetration tests are performed at least once a year by a qualified independent third party, complemented by regular vulnerability scans. Detailed reports and remediation plans are available on request under NDA.
Responsible Disclosure
Humind encourages responsible vulnerability disclosure. Security researchers can report vulnerabilities to security@thehumind.com. Each report is reviewed and addressed promptly.
Documents & Resources
The following documents are available upon request. Some documents require a signed NDA.
DPA
Data Processing Agreement compliant with GDPR Article 28. Defines processing scope, security measures, and sub-processor management.
lockRequest documentGeneral Terms of Service
General terms governing the use of Humind's platform, including SLA commitments, liability, and termination conditions.
lockRequest documentNDA
Mutual non-disclosure agreement for the exchange of confidential information during evaluation or partnership.
lockRequest documentPublic documentation
The following references are published and require no request.












