Effective Date: 25 August 2026
Harmix Inc. ("Harmix," "we," "us") is a Delaware corporation that builds AI memory infrastructure for teams. Our product, Pam (Proactive AI Manager), is a web-based SaaS platform that connects to the workplace tools a customer already uses – email, calendar, document stores, chat and meeting platforms – and turns the knowledge in them into a structured, queryable memory that the customer's team and AI agents can use.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Notice describes Harmix's policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies.
Because Pam is built to hold a customer's working knowledge, it will hold personal data – the customer's own, their colleagues', and that of people they correspond and meet with. We think that obliges us to be more specific than a privacy notice usually is, so this notice says plainly what enters the system, where it goes, who processes it, and how it leaves.
Which privacy law obligations we owe you depends on how your data reached us. There are two distinct cases, and we keep them separate.
We are a data controller for:
For this data, we decide why and how it is processed, and this notice is the full description of that processing.
We are a data processor for the content a customer brings into Pam:
For this content the customer is the controller and Harmix processes it only on that customer's documented instructions, under the customer terms that govern their use of the Service. We do not decide what a customer connects, what their mailbox or meetings contain, or who they invite to a call.
If you are an employee of a Harmix customer, or a third party whose email or meeting was captured by a customer's Pam workspace, and you want your data corrected or erased, the fastest route is to contact that customer directly – they control the workspace. You may also contact us at privacy@harmix.ai and we will route your request to the correct customer and support them in answering it.
Harmix Inc. is headquartered at 300 Delaware Avenue, Ste 210 #615, Wilmington, DE 19801, United States.
Harmix has designated an internal privacy contact for questions or concerns about Harmix's personal data policies or practices, and for exercising your privacy rights. Our Chief Technology Officer holds this role:
Oleksandr Kuprii, Chief Technology Officer
Harmix Inc.
300 Delaware Avenue, Ste 210 #615, Wilmington, DE 19801, USA
When you subscribe to our newsletter or ask for a demo, the only detail we collect is your email address. If you write to us directly, we also hold whatever you choose to put in your message. We use this to reply to you, to arrange a demo, and to send product news where you have asked for it.
Newsletter subscriptions are stored in our own systems. Demo requests are relayed to our internal Slack workspace so that someone picks them up.
Our lawful basis is your consent for marketing messages, which you can withdraw at any time, and our legitimate interest in responding to a business enquiry and in running and improving our website.
When you register for Pam we collect your full name and work email address, which are required to create an account, and we record how you signed up – by email and password, or through LinkedIn. You may also tell us your company, job position and timezone; these are optional, and the account works without them. If you sign in with LinkedIn we receive your name and email address from LinkedIn in order to create the account; we do not gain access to your LinkedIn network, posts or messages.
We store your password only as a salted, computationally expensive cryptographic hash. We never store your password in plain text and cannot recover it.
We use this data to authenticate you, to create and route work to your workspace, to personalize the service, to send you service and lifecycle emails, to meter usage against your plan, and to provide support. The lawful basis is performance of our contract with you or your employer.
For subscriptions we hold your plan, subscription status, credit balance, billing records and Stripe identifiers. Card numbers and payment instruments are handled entirely by Stripe and never reach Harmix systems. The lawful basis is performance of a contract and, for the retention of invoicing records, legal obligation.
We do not sell personal information to anyone. We do not share it for cross-context behavioral advertising. We share it only with the subprocessors listed in section 8, who are contractually bound to process it solely to deliver our service.
We receive personal data about you from LinkedIn when you choose to sign in with it, and from Stripe in connection with your subscription. We do not enrich our records from data brokers.
As is true of most other websites, our websites collect certain information automatically and store it in log files. This may include internet protocol (IP) addresses, the region or general location where your device is accessing the internet, browser type, operating system, referring URL, and usage information about your visit, including the pages you view and the elements you interact with.
We use this to design our site to better suit our users' needs, to diagnose problems with our servers, to administer the site, to analyze trends, and to understand which of our pages and campaigns are useful. Harmix has a legitimate interest in understanding how customers and potential customers use its website. Where this processing relies on cookies or similar technologies that are not strictly necessary, we act on your consent as described in section 6.
On the Pam application (pam.harmix.ai) we do not use advertising or analytics cookies. The application keeps your session using browser local storage – your access and refresh tokens and your interface preferences, such as sidebar width, theme color and view modes. These are strictly necessary to keep you signed in and to remember how you have set the application up. They are not used to track you and are not shared with anyone. Clearing your browser storage signs you out.
On our public websites we use the following categories:
| Category | Purpose |
|---|---|
| Strictly necessary | Site operation, security, load balancing |
| Analytics – Google Analytics, deployed through Google Tag Manager, and Mixpanel | Understanding which pages and features people use, so we can improve them |
| Marketing | Not currently used. If we enable it, we will update this notice first. |
Our analytics tools record page views, clicks and interactions with page elements, along with your IP address, approximate location derived from it, and your browser and operating system. We use this to see which pages and campaigns are useful and to fix what is not working.
You can refuse or delete cookies in your browser settings, and Google publishes a Google Analytics opt-out browser add-on that prevents Google Analytics from collecting data about your visit. Blocking cookies may affect how parts of the site work.
This section describes what Pam does with content once a customer connects it. For this content Harmix acts as a processor on the customer's instructions, as explained in section 2.
At a customer's direction, and only after that customer authorizes the connection through an OAuth flow they can revoke at any time, Pam ingests content from their Gmail or Outlook mailbox, Google Drive, Notion, Slack and other integrations they choose to connect. The full set of integrations available at any time is shown in the application. These connections are brokered by Composio, which holds the OAuth tokens and performs the retrieval on our behalf.
This content is the customer's own business correspondence and documents. It routinely contains personal data about people who are not Harmix users – the customer's colleagues, clients and counterparties.
Disconnecting a source stops future ingestion, but does not by itself erase what has already been processed. When you disconnect an integration we immediately stop synchronizing from it and remove the connected account and its access tokens from Composio, so we can no longer reach that account. The content already ingested, and the memory records built from it, remain in your workspace so that your existing memory stays intact and usable. To remove that material as well, delete it explicitly in the application, or delete your account to remove everything at once (section 13).
Where a customer enables the meeting notetaker, a bot provided by Recall.ai joins the meetings on their calendar, records the call, and produces a transcript, a participant list and derived insights. Customers can also upload their own recordings. Audio is transcribed and separated by speaker using ElevenLabs Scribe, and voice input to the agent is transcribed using OpenAI.
Recording a meeting captures everyone on the call, not only the Harmix customer. Whether a given meeting may lawfully be recorded, and whether the other participants have been told and – where the law requires it – have agreed, is the customer's responsibility as controller of that meeting. Our terms require customers to obtain whatever notice and consent applies to them.
Our notetaker always joins as a visible participant named "Harmix Pam Notetaker", shown in the participant list like any other attendee. There is no silent or hidden mode. Anyone on the call can see it is there, ask what it is, and ask the organizer to remove it.
Pam analyzes ingested content to produce memory records – structured summaries, extracted facts, and the connections between them, organized so they can be retrieved when relevant. These derive from material containing personal data and we treat them as carrying the same sensitivity as their sources. They are stored in the customer's own workspace, are retrievable only by users the customer has authorized, and are never pooled with another customer's data.
Pam is not designed to process special categories of personal data under Article 9 GDPR – data about health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, biometrics for identification, or sex life or orientation. Because Pam ingests free-form mail, documents and conversation, such data may nonetheless appear incidentally in a customer's content. We do not target, index for, or make inferences about these categories, and our terms ask customers not to use Pam as a system of record for them.
Pam produces summaries, suggestions, drafts and task proposals. It does not make decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. A human always decides whether to act on what Pam suggests.
The personal information we hold is stored in databases and object storage operated by Google Cloud Platform in the europe-west1 region (Belgium). We engage a set of subprocessors to deliver parts of the service. Each is bound by a written agreement containing confidentiality and data protection commitments, and may use the data only to provide its service to us.
Our current subprocessors:
| Subprocessor | Purpose | Data it receives | Location |
|---|---|---|---|
| Google Cloud Platform | Hosting, database, object storage, messaging, secrets, logging | All customer data at rest | EU (europe-west1) |
| Google Cloud / Vertex AI | Model inference for memory processing and the agent | Customer content | Google's global endpoint – processing may occur outside the EU (see section 9) |
| Composio | OAuth brokering and content retrieval from connected accounts | Mailbox, document and chat content; OAuth tokens | USA |
| Recall.ai | Meeting bot: joining, recording, transcription, participant lists | Meeting audio, transcripts, calendar data | USA |
| ElevenLabs, OpenAI | Speech-to-text transcription and speaker diarization | Meeting and recording audio, voice input | USA |
| Stripe | Subscription billing and payments | Name, email, billing data, payment instruments | USA |
| Customer.io | Lifecycle, notification and transactional email | Name, email, notification content | EU data centre |
| Sentry | Application error and exception tracking | Technical telemetry, which may include user identifiers | USA |
| Google Analytics (via Google Tag Manager), Mixpanel | Website analytics | Website usage data | USA |
The current version of this list is maintained at trust.harmix.ai. We notify customers in advance of changes to it, as our customer terms require.
We do not otherwise reveal your personal data to non-Harmix persons or businesses for their independent use unless: (1) you request or authorize it; (2) the information is provided to comply with the law – for example, compelled by law enforcement to comply with a search warrant, subpoena or court order – to enforce an agreement we have with you, or to protect our rights, property or safety or those of our employees or others; (3) the information is provided to our agents, vendors or service providers who perform functions on our behalf; (4) to address emergencies; (5) to address disputes or claims, or to persons demonstrating legal authority to act on your behalf; or (6) in connection with a merger, acquisition or sale of assets, subject to this notice.
We may also produce aggregated statistics about our services and website that do not identify any individual, and disclose those.
Since it was founded, Harmix has received zero government requests for customer information.
Customer content in Pam is stored in the European Union, in Google Cloud's europe-west1 region, and encrypted at rest. That is the default position and it is where the data lives.
Personal data nonetheless crosses borders in two ways, and we want to be direct about both.
First, Harmix Inc. is a United States company. Our personnel administer the service from outside the EU, so authorized Harmix staff can access EU-stored data in the course of operating, supporting and securing it.
Second, several of the subprocessors listed in section 8 are established in the United States, and content is sent to them to be processed – most significantly to Composio for retrieval from connected accounts, to Recall.ai for meeting capture, and to ElevenLabs and OpenAI for transcription.
We should be equally direct about model inference on Google Cloud. Although your data is stored in europe-west1, we call Vertex AI through Google's global endpoint, which we use because it gives the service materially better availability and capacity than a single regional endpoint. That means the inference itself may be carried out in a Google data centre outside the European Union. The content is processed to serve your request and returned; it is not retained by the model provider or used to train models (see section 10).
In every case, data in transit between our systems and these recipients is encrypted with TLS, and access to it is restricted to what each recipient needs to perform its function. If you have questions about a specific transfer, write to privacy@harmix.ai.
Pam is an AI product, so we state this explicitly rather than leaving it to be inferred.
Harmix does not train, fine-tune or otherwise develop AI models on customer content. Content is sent to model providers only to serve the request in front of it – to summarize a meeting, to build a memory record, to answer a query – and the output is returned to the customer's own workspace.
Our model providers are contractually barred from training on your data. We use Google's models through Google Cloud, along with OpenAI and ElevenLabs for transcription. All are used under commercial API terms, which are separate from the consumer products those companies also offer and which prohibit using submitted content to train their models. Content is sent to serve a request and is not retained by them for their own purposes afterwards.
Memory is never pooled across customers. Retrieval for one customer runs only over that customer's own workspace.
The European Union's General Data Protection Regulation and other countries' privacy laws provide certain rights for data subjects. Rights under the GDPR include:
This Privacy Notice is intended to provide you with information about what personal data Harmix collects about you and how it is used.
If you wish to confirm that Harmix is processing your personal data, or to have access to the personal data Harmix may have about you, please contact us at privacy@harmix.ai. You may also request information about the purpose of the processing, the categories of personal data concerned, who else outside Harmix might have received the data, what the source of the information was if you did not provide it directly, and how long it will be stored. You have a right to correct the record of your personal data if it is inaccurate. You may request that Harmix erase that data or cease processing it, subject to certain exceptions. You may also request that Harmix cease using your data for direct marketing.
If you are a Pam user, you can act on most of these rights yourself. You can correct your profile in the application, disconnect any integration at any time, which stops further ingestion from that source, and delete your account from the application, which erases your data as described in section 13.
If your data is in a customer's Pam workspace and you are not that customer, see section 2 – the customer controls that workspace and we will route your request to them and support them in answering it.
Reasonable access to your personal data will be provided at no cost. We respond within one month, and will tell you if we need to extend that as the GDPR permits. If access cannot be provided within a reasonable time frame we will give you a date when the information will be provided, and if access is denied we will explain why.
In many countries you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Harmix processes your personal data. If you are in the European Union you can complain to your national data protection authority; in the United Kingdom, to the Information Commissioner's Office.
California residents may have rights to know, access, delete and correct their personal information, to opt out of its sale or sharing – we do neither – and to non-discrimination for exercising these rights.
Harmix operates a security program aligned to SOC 2 and reviewed at least annually. In summary:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your personal data is stored by Harmix on Google Cloud Platform infrastructure in the europe-west1 region, in a managed database and in object storage. Encrypted backups are taken daily and retained for 7 days, with point-in-time recovery.
We keep data only as long as we have a purpose for it:
| Data | Retention |
|---|---|
| Pam account and customer content | For as long as the account is active. Deleted on account deletion or a verified request. |
| Content from a disconnected integration | Ingestion stops immediately and our access is revoked. Content already ingested, and memory built from it, stays until you delete it explicitly or delete your account. |
| Newsletter, demo and prospect data | Until you ask us to delete it or unsubscribe, or 24 months after your last interaction with us. |
| Billing records | As required by tax and accounting law, typically 7 years. |
| Operational and security logs | 12 months, unless needed longer for an investigation. |
| Backups | 7 days, after which deleted data ages out of the backup set. |
When you delete your account, we erase your record and all data associated with it from the production database – your conversations and messages, uploaded files, your workflows and their history, your integration connections and the access tokens behind them, your memory records, your meeting and calendar data, your billing and credit balance, your settings, and any API keys or access tokens issued to you – and we delete your memory data from object storage. Deleting your account from the application takes effect immediately. Where you ask us to delete data by writing to us instead, we verify the request and complete the deletion within 30 days. In both cases residual copies age out of our encrypted backups within a further 7 days as the backup set rolls forward. Disconnecting an integration also removes the connected account from Composio, revoking our access to it.
Data held by our subprocessors. Our transcription and inference providers do not retain your content: OpenAI, ElevenLabs and our model providers process it once to return a result and do not store it afterwards. Sentry receives technical error telemetry rather than customer content. Recall.ai holds meeting recordings only briefly, and they expire automatically under the retention setting on our account.
For more information on where and how long your personal data is stored, contact us at privacy@harmix.ai.
Pam is a business product intended for use by organizations and their staff. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us with personal data, contact us at privacy@harmix.ai and we will delete it.
If you have questions, concerns or complaints, or would like to exercise your rights, please contact us at:
Harmix Inc.
Oleksandr Kuprii, Chief Technology Officer
300 Delaware Avenue, Ste 210 #615, Wilmington, DE 19801, USA
We may update this Privacy Notice from time to time. The Effective Date at the top shows the latest revision, and we will highlight substantial changes on the site or by email where appropriate.