This text is drafted in full and describes how the platform works today. It is awaiting final review and sign-off by the company and its legal advisers, so its wording may still change before the version adopted as definitive. While this notice is showing, the page is not indexed and must not be submitted for external review.
Privacy Policy
Language: English Español
Who we are and how to contact us
The controller of the personal data collected through M1M (the “platform”) is:
- Legal name: MARTINUKA2220, SOCIEDAD LIMITADA (“Martinuka2220, S.L.”)
- Spanish tax ID (CIF): B72816911
- Registered office: Carretera de Miñano Mayor s/n, Etxabarri-Ibiña, Álava (01196), Vitoria-Gasteiz, Spain
- Commercial Registry: Registro Mercantil de Álava (Portal de Castilla 7 bajo, 01005 Vitoria-Gasteiz), volume 1757, folio 8, sheet VI-21090, entry 1
- Phone: +34 640296736
- Email: empresa@hutrit.com
- Website: mision1m.com
Three names, one party responsible. You will see three names around this
service and you should know how they relate. M1M is an application created
from Hutrit, and Hutrit is the trading name under which Martinuka2220, S.L.
operates. That is why our
contact address sits on the hutrit.com domain and why that name appears attached
to the computing services that run the application: it is the name under which
they are provided. Towards you, the party that answers legally is
Martinuka2220, S.L., the company identified above. To be precise about the reach
of those names: neither “M1M” nor “Hutrit” is registered, either
as a trade mark or as a trade name. They are unregistered trading names of
that company, which is the only one on the register, at the Registro Mercantil de
Álava.
This policy explains what data we process when you use the platform, for what
purpose, on what legal basis, who we share it with, how long we keep it and what
you can require of us. It applies to the public website mision1m.com and to the
platform dashboard.
Territorial scope, stated precisely. The platform is operated from Spain and is today used by people and organizations in Europe, Latin America and North America. This policy is drafted under the GDPR and Spanish law, and we apply the same standard of protection to every user, wherever they are: the same security measures, the same retention periods and the same procedure for exercising rights. Where the law of your own country grants you additional rights or imposes its own requirements on the processing or the international transfer of your data, those apply in addition to what is described here; write to us and we will tell you how to exercise them.
For any matter relating to this policy, including exercising your rights, write to empresa@hutrit.com with “Data protection” in the subject line.
We have not appointed a data protection officer, as none of the cases in Article 37 GDPR applies. The contact point for any privacy matter is the email address above.
An important note on roles. With respect to your account data (sign-up, access, security and, where applicable, billing) we are the controller. With respect to the content you or your agents put into the platform — conversations, files, data from the third-party services you connect — your organization is the controller and we act as processor on its behalf, under Article 28 GDPR. The “What we use it for” section separates the two blocks expressly.
And here is a gap we would rather tell you about than have you discover. Article 28 requires that processing to be governed by a written contract, and today we have none signed with any customer: access to the platform has been granted without it. We are preparing the data processing addendum so it can be incorporated into these documents. In the meantime, this policy describes the instructions we hold ourselves to and stands as our commitment, but it does not replace that contract and we do not pretend it does. If your organization needs it signed sooner, write to us and we will sort it out with you.
What data we collect
Account and registration data. First name, surname, email address, password, the agent you state you are going to use when registering, the status of your two-step verification, the organization you belong to and your role within it, the sign-up date, your visual theme preference and, if you upload one, your profile picture. Your password is never stored, neither in the clear nor encrypted: we keep only an irreversible hash, from which the original password cannot be recovered. Registration also generates a 32-character personal access token: it is shown to you once, and of it too we keep only a cryptographic fingerprint, never the token itself.
Federated authentication data. If you sign in with your Google or Microsoft account, we receive from that provider your user identifier, your email address and your name, together with confirmation that you have passed a second authentication factor. We never receive your password, and we do not collect the profile picture from that account either. This data does not come from you directly: its source is the identity provider you choose when signing in.
Platform usage data. The content of your conversations with agents, the instructions you give them and their responses; the files you upload or your agents generate; the projects, scheduled jobs and missions you create; each agent’s configuration (including the model provider you choose); and usage metrics — number of requests, tokens consumed per model and associated cost — which we need in order to show you your spend and enforce your limits.
Technical and security data. A log of activity relevant to account security: sign-ins and sign-outs, password changes, access-token rotation or revocation, people added and removed, permission changes, denied access attempts and other administrative actions. For each one we record who did it, what they did, on what, when and from which IP address, and — for configuration changes — the value before and after. We also record agent activity events and operational request data (route, response code, duration).
Data from applications you connect. Only if you authorize a connection: the access credentials the provider issues to us, the scope granted, its expiry date, and the content of that application the agent accesses in order to carry out what you ask. This is detailed under “Third-party data you connect”.
Which data is mandatory. The data marked as required at registration — first name, surname, email and password, or the Google or Microsoft account you sign in with — is essential in order to create the account, identify you and deliver the service: without it we cannot give you access. Everything else (profile picture, preferences) is optional and you may withhold it with no consequence whatsoever.
What we do NOT collect. We use no analytics, advertising or tracking tools on the public website. We do not buy or enrich data from external sources. We do not build commercial profiles. We do not ask you for special categories of data (health, political opinions, religion, sexual orientation, biometrics) and our Terms prohibit entering them deliberately without a prior agreement with us. We are aware, however, that a source you connect — a calendar holding medical appointments, a document you hand to an agent — may incidentally contain data of those categories, without either you or us having entered it: weigh that risk before connecting it and when choosing that agent’s model provider.
What we use it for
Two blocks have to be kept apart here, because our legal role differs in each and mixing them would be incorrect.
Block A — Processing where we are the CONTROLLER. These are the ones we decide on. Each has its purpose and its GDPR legal basis:
| Purpose | Legal basis |
|---|---|
| Create and maintain your account, identify and authenticate you — including sign-in with Google or Microsoft and the second factor — and support you | Performance of the contract (Art. 6(1)(b)) |
| Invoice and keep accounting records, where the service is paid for | Performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Protect the platform and your account: logging of access and administrative actions, detection of and response to unauthorized access, abuse or fraud | Legitimate interest (Art. 6(1)(f)) in the security of the service and of every organization using it |
| Measure consumption and prevent waste: counting tokens and cost, applying caps and automatically cutting off anomalous consumption | Performance of the contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Send you essential service notices: incidents, maintenance and changes to these documents | Performance of the contract (Art. 6(1)(b)) |
| Improve the platform from technical usage metrics (request volume, latency, errors), never from customer content | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations and respond to requests from competent authorities | Legal obligation (Art. 6(1)(c)) |
Block B — Processing where we are the PROCESSOR. These concern work content, and we do not decide on them:
| Processing | Who decides |
|---|---|
| Storing, displaying and searching your conversations, files, projects and scheduled jobs | Your organization |
| Running the agents and sending the necessary content to the configured model provider | Your organization, through whoever uses it |
| Connecting third-party applications and accessing their content within the authorized scope | Your organization; the specific authorization is granted by you on the provider’s screen |
| Retaining or deleting that content | Your organization |
In this block we invoke no legal basis of our own: we neither have one nor need one, because we do not decide on these processing activities. We act on behalf of your organization and on its documented instructions, under Article 28 GDPR; the legal basis and the duty to inform the individuals concerned are its responsibility. We do not use work content for our own purposes. Should that ever become necessary, it would require your organization’s prior authorization and would be communicated to it beforehand, as Article 28(10) GDPR requires.
Automated decisions. We make no automated decisions producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 GDPR, and we do not carry out profiling. Agents act on your instructions, not ours. That said, and so as not to hide behind an absolute: the platform does apply operational spend-control automation — when a consumption cap is reached, execution stops automatically, and anomalous consumption may temporarily suspend the service. These are contractual, reversible measures that do not evaluate personal aspects of you; you can ask for them to be reviewed and lifted by writing to empresa@hutrit.com.
Transparency about AI-generated content. Agents produce synthetic text — answers, summaries, drafts and messages. Today an agent does not send email to third parties: that is a planned feature and not yet live. Once it does — or where that text leaves through any other channel you connect — whoever receives it will have no way of knowing an AI wrote it, obvious though that is inside the dashboard. The platform today embeds no automatic machine-readable marking identifying that content as AI-generated, and we would rather tell you than let you assume otherwise. The transparency obligations of Regulation (EU) 2024/1689 (the AI Act) on artificially generated content apply on their own timetable and with an allocation of roles that depends on how you use the platform; the Terms of Service set out what falls to you while that marking does not exist.
Third-party data you connect
The platform can connect to applications you already use so that your agents can work with them. Nothing connects by itself: a connection only exists if you sign in to the provider and expressly approve the scope shown to you.
Planned connection categories and what they are used for:
- Basic identity — your name and your email, to sign in, register or recognize your account and show you which one you have connected. It is not used for advertising or to profile you.
- Email — sending on your behalf only the messages you ask to be sent. We do not request read access to your mailbox.
- Files and documents, including spreadsheets — opening the documents you select and saving the results the agent produces.
- Calendar — checking your availability and creating or modifying the events you ask for.
- Notes and tasks — reading the content you authorize and writing to it when you ask.
- Messaging — receiving instructions and sending replies over the channel you connect.
How we do it, specifically:
- Broad permissions, narrow use. Some of the permissions these providers grant are, by their own design, broader than the specific task you give the agent: the calendar read permission, for instance, reaches all your calendars and all their events, not just the day you are asking about. We show you the real scope of each one under “Limited Use of Google Data” instead of describing them as if they were minimal.
- We never see your password. Authorization happens on the provider’s own site; what reaches us is an access credential, not your password.
- Access happens only on your instruction. The agent reads or writes when it performs a task you have requested or scheduled, and within the granted scope.
- We do not copy your account. We make no replicas or bulk dumps of the connected application’s content; only what the task needs is accessed. What the agent produces (a summary, for instance) is kept in your workspace, because it is your work product, and is retained like the rest of your work content.
How to revoke it and what happens next. You can withdraw a connection at any time from the platform, and also from your account with the provider itself. When you revoke it from the platform, the connection is revoked immediately and we delete the associated credential from the store; should that deletion fail, the connection stays revoked all the same and is never used again. That is the reliable route, and it is worth using before closing your account (see “Where data is stored and for how long”). Content already saved in your workspace (a generated file, for example) stays there until you delete it or the account is deleted; you can ask us to delete it at any time.
Limited Use of Google Data
When you sign in with your Google account, and when you connect a Google application to an agent — a planned feature that is not yet live — the processing of information obtained through Google APIs is governed, in addition to this policy, by Google’s official Limited Use declaration, which we reproduce verbatim:
“The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.”
Which permissions we request, what each one actually allows and what we use it for. The permissions in the first row are requested today, if you choose to sign in with Google. The rest belong to application connections, which are not yet live: they will be requested only once the feature exists and you enable it.
| Permission | What it actually allows | What we use it for |
|---|---|---|
openid, email, profile | Confirming your identity and obtaining your identifier, your email and the basic public information of your profile, including name and picture. | Signing you in with your Google account and registering or recognizing your user. Of all that we keep only identifier, email and name: we do not collect the picture. |
https://www.googleapis.com/auth/gmail.send | Sending messages on your behalf. Grants no read access whatsoever: with this permission we cannot open, search or list the messages in your mailbox. | Sending only the messages you order to be sent. |
https://www.googleapis.com/auth/calendar.readonly | Reading the list of all your calendars and all their events. | Checking your availability and answering questions about your schedule. |
https://www.googleapis.com/auth/calendar.events | Creating, modifying and deleting events in your calendars; includes reading them. | Creating or changing the events you ask to create or change. |
https://www.googleapis.com/auth/drive.file | Accessing — including writing — only the files you select and those the application itself creates. It does not reach the rest of your Drive. | Opening the document you point to and saving the agent’s results to your Drive. |
Two clarifications, instead of the usual “we request the bare minimum” formula:
- We request no restricted permission at all, and that is a deliberate
decision. Google classifies as restricted the permissions to read the whole
mailbox (
gmail.readonly) and the whole Drive (drive.readonly). We do not request them: from your mail we ask only to send, and from your files only those you select. We give up features we could otherwise offer — the agent cannot search, read or summarize your mailbox — in exchange for the platform never holding technical access to all your mail or all your drive. - Some permissions overlap, and not by oversight.
calendar.eventsincludes reading events, so it largely overlaps withcalendar.readonly, which additionally allows seeing the list of your calendars: they cover different things, which is why both exist.drive.file, by contrast, overlaps with nothing: it is the narrowest permission there is for working with documents, because what it reaches is decided by you, file by file.
What really limits these permissions is not their name, but the commitments we make below, your decision about which connections to authorize, and your ability to revoke them at any time.
Commitments we make regarding Google data, in line with the Limited Use requirements:
- Use restricted to user-facing features. Data received from Google APIs is used exclusively to provide or improve platform features that you see and use, and that you have expressly enabled.
- We do not sell or transfer it. We do not sell, disclose or transfer Google data to third parties, except in the four cases Google’s own policy allows, and on the same terms: (a) to provide or improve platform features that are visible and prominent in its user interface, to the providers strictly necessary to carry out the operation you requested — among them the model provider you yourself configure for that agent — bound by equivalent confidentiality obligations, only with your consent and always within the list of admissible providers in commitment 4; (b) for security purposes, for example to investigate abuse; (c) where required by law; or (d) as part of a merger, acquisition or sale of assets, after obtaining your explicit prior consent. Outside those four cases, we do not transfer.
- We do not use it for advertising. Not for serving ads, not for targeting, not for personalized, retargeted or interest-based advertising. We do not run advertising at all.
- We do not use it to train AI models, and here is how we guarantee that. We neither develop nor train models, and we do not hand that content to anyone for training purposes. In addition, our Terms of Service require content obtained from Google APIs to be routed only to model providers with a contractual no-training guarantee, as a condition of use of that connection. It matters that you understand its nature: this is a contractual obligation on the configuration you choose, not an automatic technical block in the platform; routing that content to another provider is a breach of the Terms. As for the providers that do offer the guarantee, the no-training commitment is theirs and is set out in their commercial terms; what we do not do is make promises on behalf of a third party whose contract we do not control.
- No human reads it. No member of our team reads content obtained from Google, except (a) where you give explicit consent for specific messages, (b) where it is strictly necessary for security purposes — for example, investigating abuse — (c) where required by law, or (d) where the data has been aggregated and anonymized for internal operations.
When you revoke the connection from the platform, we mark it as revoked — it can no longer be used from that moment — and we delete the associated credential from the secret store; should that deletion fail, the connection stays revoked all the same and is never used again. That is the reliable way to withdraw an agent’s access. We also recommend withdrawing the permission from your own Google account at myaccount.google.com/permissions: it is the only way to invalidate it at source, and it is worth doing before you close your platform account, for the reasons explained under “Where data is stored and for how long”.
Who we share data with
We do not sell personal data. Ever. We do not disclose it for advertising purposes and we do not trade it with anyone for commercial gain.
We share data only with those necessary to deliver the service to you, and only what is necessary:
1. AI model providers. This is the most significant category and we want you to understand it properly. For an agent to answer, the platform sends the model provider you configured for that agent the content needed to generate the response: your instruction, the conversation context and, if the task requires it, the content of the files or connected applications you asked it to work on. The provider returns the response.
The platform is deliberately open: you can choose from a broad catalogue of providers, including OpenRouter, Anthropic (Claude), OpenAI, Google (Gemini models), DeepSeek, xAI (Grok), Mistral, Groq, NVIDIA, Hugging Face, Alibaba (Qwen), Moonshot (Kimi), MiniMax, z.ai (GLM) and others. The full, current list is shown in the platform itself when you configure each agent, and that is where you choose.
The legal role of these providers, without ambiguity. Today the only model provider we contract is Google in its enterprise AI service (Gemini models): it acts as a sub-processor and we require the Article 28 GDPR guarantees of it. Every other provider in the catalogue — including OpenRouter and providers established outside the EEA — necessarily runs on an account and a key that you supply: in those cases the contract is between you and that provider, its role and its obligations are set by that contract and not by ours, and we merely direct the request to the account you configured.
Three consequences you should know before choosing:
- The provider you choose receives your content. There is no way for a model to answer without receiving the question.
- Each provider has its own terms and its own privacy policy. Ours do not replace theirs. Read them before sending sensitive information.
- Some providers in the catalogue operate outside the European Economic Area, including countries without a European Commission adequacy decision (for example, providers with infrastructure in China). Choosing one of them entails an international transfer that your organization decides on, and whose legal cover is explained under “Where data is stored and for how long”.
2. MCP servers and tools you connect. If you extend an agent’s capabilities by connecting external tools, those tools receive the data they need for the requested operation, within the scope you authorized.
3. Applications you connect. They receive the requests the agent makes on your behalf, within the granted scope (see “Third-party data you connect”).
4. Technology infrastructure providers hosting the platform and its backups, and ancillary service providers (transactional email, support and, if we ever bill, billing). All act as processors under an Article 28 GDPR agreement, are bound by confidentiality and security measures, and may only process data on our instructions.
5. Authorities and advisers, where there is a legal obligation, a valid request from a competent authority, or where it is necessary to bring or defend legal claims.
6. In a corporate transaction (merger, acquisition or sale of assets), the acquirer, with prior notice to you and maintaining the guarantees in this policy. Data obtained from Google APIs would only be transferred in that scenario with your explicit consent.
Use of your data in AI models
This is the section that matters most, so we write it without ambiguity, even where the honest answer is less comfortable than an absolute headline.
What we can guarantee unconditionally:
- We do not train models. Martinuka2220, S.L. neither develops nor trains artificial intelligence models. Your content — conversations, files, instructions, data from connected applications — is never used to train, fine-tune or improve any model of ours, quite simply because there are none.
- We do not hand your content to anyone to train on it. We do not sell or supply datasets, and we do not give third parties access to your content for model training, research or development purposes.
- What is sent is what is needed to answer, not your account. The model provider receives the content strictly required to handle the specific instruction: your instruction and, where the agent needs it to maintain continuity, a bounded fragment of the recent context of that same conversation. Your full account is never sent, nor the complete history of all your conversations, and that fragment first passes through a filter that hides credentials and secrets that might appear in the text.
What we guarantee contractually — not through a technical block:
- Content obtained from Google APIs must be routed only to providers with a contractual no-training guarantee. Our Terms of Service require it as a condition of use of that connection, on the terms of the Limited Use of Google Data section. It is an obligation on the configuration you choose, and we present it that way — rather than as an automatic behaviour of the system — because that is exactly what it is.
What depends on the provider you choose — and why we cannot promise it on their behalf:
Your content has to reach the model provider you configured for the agent to be able to answer. What that provider does with what it receives is determined by their terms, not ours. And they do not all say the same thing:
- Providers with a contractual no-training guarantee. Some providers’ commercial API terms commit to not using customer-submitted content to train or improve their models. Today that is the case for Anthropic (Claude models) and for Google in its enterprise AI service (Gemini models contracted by us for the platform). If you need a no-training guarantee, configure your agents with one of these providers; and if you connect Google applications, the Terms require you to.
- Model aggregators. Services such as OpenRouter do not run the model: they route your request on to third-party providers. Their own terms warn that some of those models may store and train on what you send them, and that being able to opt out of that training depends on each model’s terms, not on the aggregator. Whether your content ends up with a provider that trains on it depends on a setting in your own account with the aggregator — not on us, as we can neither see it nor change it — and the actual destination may vary from one request to the next. There is something you can do about it, and you should know it: their terms state that, where possible, they have opted out of model training on the models they use, and their account settings let you switch off routing to providers that train, with separate settings for paid and free models. On the logging of your requests their terms are clear in both directions: if you turn prompt logging on you grant them a licence over that content that is perpetual, irrevocable, sublicensable and extends to their own commercial purposes, and if you do not, they state that they do not store your inputs beyond categorizing them; separately from that option, they keep a licence over anonymized inputs limited to usage metrics on their site. Even so: an aggregator is not a provider with a contractual no-training guarantee, and you must not route confidential content or third-party personal data through one.
- Your own provider account (a key you supply). The platform is designed for you to use your own credentials with most providers. In that case the contract is between you and that provider: that account’s settings — including those about training on your data — are under your control. We cannot read them, change them or enforce them. Bear in mind that some free or developer plans from very well-known providers do use content to improve their products, while their paid or enterprise plans do not: the difference lies in the plan, not only in the brand.
What we do about that reality, instead of hiding it:
- We tell you where your content goes. Each agent’s provider and model are chosen when configuring it and can be reviewed and changed at any time from the platform.
- We turn it into a contractual obligation. Our Terms of Service require you, if you connect Google applications or any other source holding confidential content or third-party personal data, to configure that agent with one of the providers with a contractual no-training guarantee named above.
- Practical recommendation. To process third-party personal data or confidential information, use those providers and do not route that content through aggregators.
We would rather tell you exactly where our commitment ends and someone else’s begins than sign an absolute that does not depend on us. A commitment we cannot keep protects no one.
Prohibitions we commit to
Regardless of the legal basis available to us, we bind ourselves to the following. This list is a commitment, not a description:
- We do not sell personal data, nor rent it, nor disclose it for consideration.
- We do not use it for advertising purposes, ours or anyone else’s: no ads, no targeting, no personalized, retargeted or interest-based advertising.
- We do not build commercial or behavioural profiles unrelated to delivering the service, and we do not make automated decisions with legal effects on people.
- We do not use your content to train models of our own — we have none — nor do we hand it to anyone to train on it. What the model provider you choose does with what it receives is not up to us and we do not promise it on their behalf: the difference, provider by provider, is explained under Use of your data in AI models.
- We do not cross data between organizations. One organization’s content is never used for anything related to another, under any circumstances.
- We do not enrich your profile from external sources and we do not buy data from brokers.
- We do not put your content to any purpose other than those stated in this policy, including the narrow cases of human access and disclosure to third parties described in it: outside those cases, there is no other use. Should a new purpose arise in the future, we would tell you and, where the law requires it, ask for your consent before carrying it out.
Human access to your data
By default, nobody on our team reads your content. Access to the content of conversations, files and data from the applications you connect is restricted and may only occur in these narrow cases:
- At your request or with your explicit consent — for instance, when you open a support ticket and authorize us to look at a specific case in order to resolve it.
- For security — where it is strictly necessary to investigate an incident, unauthorized access, abuse of the platform or a threat to other organizations.
- Legal obligation — to respond to a valid request from a competent authority.
- On aggregated and anonymized data, which does not allow anyone to be identified or content to be reconstructed.
Controls we apply to such access:
- Strict minimum. Only people whose job requires it, only over what is strictly necessary and only for as long as necessary.
- Traceability. Access and administrative actions are logged with author, time, object of the action and origin of the connection.
- Confidentiality. All personnel are bound by a duty of confidentiality that survives the end of their relationship with the company.
- For Google data, the specific restriction in the Limited Use of Google Data section applies in addition.
Where data is stored and for how long
Where. The platform and its backups are hosted in the United States, in facilities of infrastructure providers acting as processors. In addition, the content you send to an AI model is processed wherever the provider you chose operates, which may be in other countries (see “Who we share data with”).
International transfers. We are established in Spain, so Chapter V GDPR applies to the transfers we make regardless of where you live: what triggers that regime is the position of whoever exports the data, not the nationality or residence of the person the data is about. In practice, the safeguards in point 1 protect you too if you are in Latin America or North America; and if your own country’s law imposes its own conditions, those apply on top of these. Two situations have to be distinguished, because their legal cover is not the same and presenting them together would be inaccurate:
- Transfers we make ourselves — hosting, backups, ancillary services and the only model provider we contract, Google’s enterprise AI service. Here we are a party to the contract, and any exit from the European Economic Area relies on the safeguards in Chapter V GDPR: Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914) and, where the provider is certified, the EU-US Data Privacy Framework, together with any supplementary measures identified by the transfer impact assessment. You may request a copy of the safeguards applied.
- Transfers resulting from your organization’s choice of model provider — any other provider in the catalogue, all of which run on an account and key you supply and therefore have no contract with us: aggregators such as OpenRouter and providers established outside the EEA, among others. In that case we cannot supply Chapter V safeguards for that transfer: we are not a party to that contract. The transfer stems from an instruction of your organization, and it is your organization that must ensure it has a valid basis for it. We say so plainly so that you can decide with the right information: if you need every transfer to be covered by safeguards of ours, restrict your agents’ configuration to the model provider we contract.
For how long. We distinguish what the platform prunes on its own from what is only deleted when the account is deleted. We would rather put it that way than announce automation that does not exist:
- Access and audit logs (sign-ins, IP, administrative actions, denied attempts) — 90 days. A daily platform process prunes them automatically once that period is exceeded.
- Agent activity events — 180 days, with the same daily automatic pruning.
- Historical consumption snapshots — 365 days, with the same daily automatic pruning.
- Per-agent usage records (the tokens and cost you see in your spend dashboards) — not pruned by the passage of time: they are kept for as long as the account exists, because they are the basis of your spending history and of your limit calculations. They are deleted when the account is deleted.
- Work content — conversations, files, projects, scheduled jobs, agent outputs and any content an agent has brought in from a connected application and left in the thread — is not deleted automatically by the passage of time. It is kept for as long as the account or the organization exists, or until you delete it, and is deleted together with them.
- Account and profile data — for as long as the account exists.
- Credentials of connected applications (access and refresh tokens) — until you revoke the connection from the platform, at which point the connection is revoked and we delete the credential from the secret store; should that deletion fail, the connection stays revoked all the same and is never used again. In addition, when we carry out the deletion of an account we also manually delete its connections’ credentials from the secret store, for as long as the platform does not do so by itself. That said, and so you can act knowing where you stand: closing the account does not, by itself, revoke these credentials, and we do not notify the revocation to the provider. So if you are going to stop using the platform, revoke your connections before closing the account and also withdraw the permission from your account with the provider — for Google, at myaccount.google.com/permissions — which is the only way to invalidate it at source. And if you have already lost access — because you closed the account or your organization deactivated you — withdraw the permission on that same page and write to us at empresa@hutrit.com so that we delete the credential: you are still entitled to demand it.
- Model provider API keys you supply — for as long as you keep them configured. You can replace or delete them at any time; deleting them removes them immediately from production systems. When an account is deleted, the process itself attempts to delete these keys from the secret store automatically. It is an attempt with a safety net, not a guarantee: should that deletion fail, the account deletion still proceeds, the failure is logged and our team completes it by hand. If you stop using the platform, rotate or revoke those keys in your provider’s console: that is the only way to invalidate them at source.
- Backups — kept in cyclical rotation: the criterion is to keep the number of copies needed to restore the service after a recent incident, and no copy is kept beyond that cycle, at the end of which it is overwritten. Data deleted from production systems may therefore survive in a backup until that backup is overwritten; in the meantime it remains encrypted, protected and unused for any purpose.
- Billing and accounting records — none exist today: the service is provided free of charge and we issue no invoices for its use, so there is no accounting obligation to meet and no billing data to keep. If you contract a paid plan in the future, from that moment they will be kept for 6 years from the last entry, as required by law (Spanish Commercial Code), and 4 years for tax purposes, the longer period prevailing.
- Data needed to handle claims — for the limitation period of any legal action that may arise — as a general rule, five years for personal actions, Article 1964 of the Spanish Civil Code — blocked and available exclusively to authorities and courts.
How an account is deleted. There is no deferred automatic deletion and no self-destruct button: deleting an account, an organization and their content is a process carried out on request by our team when you or your organization ask for it, in the manner described under “Your rights, revocation and deletion”. Until then, work content is retained.
How we protect it
We describe guarantees and outcomes, not the specific technology behind them: that part is confidential information, and publishing it would weaken the protection itself.
- Encryption. Data travels encrypted in transit and is stored encrypted at rest.
- Isolation between organizations. Each organization operates in its own logical space and the system prevents, by design, one from reaching another’s content. Agents are likewise isolated from each other.
- Credentials live apart, and none is stored in the clear. Your password is stored as an irreversible hash — not encrypted, but transformed so that it cannot be recovered — and of the access token we keep only a fingerprint. The API keys and application tokens you connect are held encrypted at rest in a separate secret store, apart from the rest of the data and from the machines where agents run.
- Least privilege. Every component and every person has only the permissions they need, and nothing more.
- Hardened access. Federated sign-in with Google or Microsoft requires resolving a second authentication factor, and two-step verification is mandatory for the platform’s administration accounts. In all cases: controlled sessions and immediate credential revocation on request.
- Traceability. Relevant actions are logged so that what happened, who did it and when can be reconstructed.
- Backups taken regularly, encrypted, with the ability to recover from an incident.
- Incident handling. Should a security breach occur, we act according to our role in each case: where it affects data for which we are the controller (account, authentication, security and, where applicable, billing), we will notify the Spanish Data Protection Agency (AEPD) within 72 hours of becoming aware of it, and will inform you without undue delay where the risk to you is high; where it affects work content, for which your organization is the controller, we will notify your organization without undue delay, under Article 33(2) GDPR, so that it can meet its own duty to notify the authority and the individuals concerned.
No system is invulnerable. We commit to maintaining appropriate, up-to-date measures and to being transparent if something fails.
Your rights, revocation and deletion
The GDPR grants you the following rights over your personal data:
- Access — to know what data of yours we process and obtain a copy.
- Rectification — to correct inaccurate or incomplete data.
- Erasure (the “right to be forgotten”) — to have it deleted where it is no longer necessary, you withdraw consent, or you successfully object to the processing.
- Restriction of processing — to have us keep it but stop using it while a challenge is resolved.
- Portability — to receive the data you provided in a structured, commonly used, machine-readable format, or to have it sent directly to another controller where technically feasible.
- Objection — to object to processing based on our legitimate interest, explaining your particular situation.
- Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out beforehand.
- Not to be subject to automated decisions with legal effects. As stated under “What we use it for”, we do not make them.
Your right to object, set out separately. Article 21(4) GDPR requires this right to be presented to you expressly and separately from the rest, not as one more bullet inside a list: you may object at any time, on grounds relating to your particular situation, to the processing we base on our legitimate interest — the security of the platform and improving the service from technical usage metrics. If you do, we will stop processing that data, unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or which are needed to establish or defend legal claims.
How to exercise them. Write to empresa@hutrit.com stating which right you are exercising. We may need to verify your identity before acting on the request, in order to protect your own data. We will respond within one month of receipt; if the request is particularly complex, we may extend that by two further months, telling you why within the first month. Exercising these rights is free of charge.
If you are a member of an organization, note that your organization is the controller of the work content: we may forward your request to it and act on its instructions, as Article 28 GDPR requires. We will tell you if that happens.
Revoking a connected application. You can withdraw the authorization granted to an external application at any time from the platform itself: when you do, the connection is revoked immediately and we delete the associated credential from the store; should that deletion fail, the connection stays revoked all the same. Do it before closing your account, because closure does not revoke connections by itself, and also withdraw the permission from your account with the provider — for Google, at myaccount.google.com/permissions — which is the only way to invalidate it at source. If you can no longer sign in to the platform, withdraw the permission on that page and write to us: we will delete the credential for you.
Deleting your account. Deletion is neither automatic nor deferred: it is a process carried out on request. Ask for it by writing to empresa@hutrit.com; before carrying it out we will offer you a copy of your content, and once confirmed we delete the account and its work content without undue delay and, in any event, within the one-month period in which we must respond to you. In that same process, the deletion attempts to remove your agents’ API keys from the secret store automatically, and we delete by hand the credentials of your connected applications, which today are not removed on their own. Excluded are data we must keep by legal obligation, which will remain blocked, and any residue surviving in backups until those are overwritten.
Complaint to the supervisory authority. If you believe we have not handled your request properly or that we are processing your data improperly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es, which is our country’s supervisory authority. You are not obliged to go to it: Article 77 GDPR lets you complain to the supervisory authority of the Member State where you reside, where you work, or where the alleged infringement took place. And if you are outside the European Economic Area, you may also approach your own country’s data protection authority, where one exists. We would appreciate the chance to resolve it with you first, but it is your right and you may exercise it directly.
Cookies and similar technologies
Let us be specific, because this is an area where vague language is widely abused:
The public website mision1m.com uses no cookies. No analytics, no tracking
pixels, no advertising, no third-party cookies. We do not know who visits us and
we do not try to find out.
The only thing this website stores in your browser is a local preference
(m1m-lang-suggestion-dismissed), created only if you dismiss the notice
suggesting you read the page in another language. Its purpose is to avoid showing
it again. It identifies nobody, it never travels to any server, and you can delete
it from your browser. Being a preference you set through an express action of your
own, it does not require prior consent.
The platform dashboard uses strictly necessary cookies. When you sign in, a session cookie is created that keeps your identity authenticated as you browse and protects the session from misuse. Without it, signing in is not possible. It is a technical, necessary cookie, exempt from the prior consent requirement under Article 22.2 of the Spanish LSSI; it is removed when you sign out or when it expires.
We use no analytics, profiling or advertising cookies, whether ours or third parties’. Should we ever do so, we would ask you first through a consent mechanism and update this section.
You can configure your browser to block or delete cookies and local storage. If you block technical cookies, you will not be able to sign in to the dashboard.
Minors and changes to this policy
Minors. M1M is a service intended exclusively for people over 18. It is designed for professional or business use, although whoever uses it may qualify as a consumer and then keeps the rights the law grants them, as explained in the Terms of Service. It is not directed at minors, we do not knowingly collect minors’ data, and access is restricted to accounts authorized by an organization. If we find that an account has been created by a minor, we will delete it together with its data. If you believe a minor has provided us with data, write to empresa@hutrit.com and we will act immediately.
Changes to this policy. We may update this policy to reflect changes in the service, in the providers involved or in applicable law. The date of the last update appears at the top of the document.
- If the change is material — a new purpose, a new category of recipients or a change to retention periods, for example — we will notify you by email or through the platform at least 30 days before it takes effect.
- If the change is minor — wording corrections, clarifications, contact updates — we will publish the new version and update the date.
- Where a change requires your consent, we will ask for it expressly before applying it. Continuing to use the platform after a change that does not require consent takes effect means you accept the version in force.
Previous versions. Announcing a change is only useful if you can check what it consists of, so: we keep the previous versions of this document and, if you need to know what it said on a given date or what has changed since the previous one, ask us and we will provide it. The advance notice of a material change will state what changes, not merely that a new version exists.
This policy is available in Spanish and English. In the event of any discrepancy between the two versions, the Spanish version prevails.