Legal · Last updated 30 September 2026
Privacy Policy
A bridge carries your integration’s calls to Microsoft Graph or HubSpot and back. The content of those calls — messages, events, contacts, CRM records — passes through and is never stored or logged. This policy explains what we do keep.
1. Who we are
Avakode Bridges (EWS Bridge at ewsbridge.com, Legacy Bridge at legacybridge.dev, the console at bridges.avakode.com) is a service of Individual Entrepreneur Darya Avakova, Tax ID 534556558, Parkent street 9, apt. 78, Mirzo Ulugbek district, Tashkent, Republic of Uzbekistan. In this policy “we” and “Avakode” mean that entity.
2. What this policy covers, and our role
Personal data we handle when you visit this website, create a bridge and use the console, when your integration calls a hosted bridge, when a self-hosted server checks its licence, when you buy a plan and when you contact support. For the content your integration sends through a hosted bridge, you (or your organisation) are the controller and we act as your processor, only to perform the calls you send. A self-hosted bridge runs entirely on your server; we receive only its licence check (section 5).
3. What passes through and is never stored
- Request and response bodies. Each call is translated in memory, performed with your tenant’s or portal’s credentials and answered. Message bodies, subjects, addresses, attachments, events, contacts and CRM properties are not written to any database, file, log or report.
- Coverage events hold metadata only: the operation name, whether it translated, a short reason or error code, the names of schema fields that could not be returned, the number of upstream calls, the latency and a request id. They feed your usage figures and gap report.
- Free tools. Files uploaded to the EWS log analyzer and the HubSpot scanner are read in memory and discarded with the response.
4. What we store
- Your bridge: the email address you signed in with, your licence key and plan, and the name you give a portal. The licence key is stored encrypted (AES-256-GCM).
- Upstream access: for EWS, the id of your Microsoft 365 tenant confirmed by your administrator’s sign-in, and a default mailbox address if one is set; for HubSpot, the access token you save and your portal id. The token is stored encrypted and never shown again.
- Bridge keys and console sessions: stored only as SHA-256 hashes; a key is shown to you once.
- Identifiers the translation needs, in a cache: short-lived Microsoft Graph tokens; for HubSpot, your portal id, the mapping between legacy and current list ids, engagement types and paging positions (a day) and the names and types of your portal’s properties (10 minutes); for EWS, mailbox ids (a day) and the mapping between older Exchange item ids and Graph ids (30 days), stored under hashed keys; and, for EWS synchronisation, the ids of items in a synchronised folder with Microsoft’s change link, encrypted, for 30 days after the last use.
- Agency sign-in: your email address and one-time sign-in links, stored as hashes and valid for a short time.
- Backups: a daily copy of the database, deleted after 90 days.
5. Licence checks
A hosted bridge checks your licence with api.avakode.com when you sign in and once a day. A self-hosted server sends its licence key, the product name and its own address to api.avakode.com when it starts and once a day. Nothing your integration sends is part of these checks.
6. Purchase data
Payments are processed by Paddle, our Merchant of Record, under the Paddle Buyer Terms; Paddle handles your payment details as its privacy policy describes. We receive your name, email, billing country and the transaction record. We never receive card numbers.
7. Support and technical data
If you write to us, we keep the message, your email address and anything you choose to attach; we never ask for your mail or CRM data. Our hosting provider processes connection data (IP address, user agent, requested path, time) to deliver and protect the service. We keep no request logs; counters of failed key attempts are kept per IP address for a minute.
8. Why we handle it
To perform the contract with you (the bridge, the console, licences, support), on the basis of legitimate interest (keeping the service secure and working), and to meet legal obligations (tax and accounting records).
9. Who else handles it
Cloudflare hosts the service, its database, storage and email sending. Microsoft and HubSpot receive the calls your integration sends through the bridge, for your tenant or portal only. Paddle handles payments. We do not sell personal data and do not share it with advertising networks. These websites load no analytics, trackers or third-party scripts, and their fonts come from our own servers; only the checkout on the pricing pages loads Paddle’s.
10. International transfers
Our providers operate globally, so data may be processed outside your country. Transfers from the EEA and the UK rely on Standard Contractual Clauses or the UK Addendum.
11. How long we keep it
- Your bridge — its settings and tokens, bridge keys, usage figures, console sessions, EWS synchronisation state, coverage events and the cache entries kept under its id: while your plan is active. When the licence ends, the bridge is suspended; once our licence server has refused its licence for twelve months — counted from the first daily check that finds it suspended for its licence, with a last licence check just before — it is deleted automatically. Earlier on request.
- Cache entries not kept under your bridge’s id (Microsoft Graph tokens, mailbox and item id mappings): they expire within 30 days. EWS synchronisation state: 30 days after its last use. Database backups: 90 days.
- An agency account (its sign-in email) stays until you ask us to delete it.
- Purchase and tax records: 7 years, as required by law. Support correspondence: 3 years.
12. Your rights
You may ask us for a copy of your data, to correct or delete it, to restrict processing, or for it in a portable format. Write to support@avakode.com and we will answer within 30 days. If you are in the EEA or the UK you may also complain to your supervisory authority.
13. Changes
If we make a material change we will announce it here and, for customers, by email at least 30 days before it takes effect.
14. Contact
Email support@avakode.com, or write to Individual Entrepreneur Darya Avakova, Parkent street 9, apt. 78, Mirzo Ulugbek district, Tashkent, Republic of Uzbekistan.