Policies
Integrations data policy
What can leave InMyWords through a connection, who is responsible for it once it has, and what InMyWords records.
The parties
- The organisation is the controller of the data it holds in InMyWords.
- InMyWords, a service of INT6 Ltd, company number SC547705, registered office 3 Prospect Place, Westhill, AB32 6SY, is the processor.
- A connection is made by the organisation, to software the organisation chooses.
- The software at the other end of a connection is the organisation's own recipient. Once it has read data, what it does with that data is the organisation's responsibility and not that of INT6 Ltd.
What can leave through a connection
Data leaves only through the scopes the organisation gives a connection.
| Scope | What can be read |
|---|---|
| Read conversations | Each conversation's details, its transcript in both languages, and its facts. |
| Read summaries | Each conversation's summary. |
| Read cases | Each case's details and the conversations and documents in it. |
| Write cases | The case and conversation created, and the address that opens it. |
| Send documents | The document sent and its status. |
| Read documents | Each document sent through the connection and its translation. |
| Read people | Each person's name, email address, job title, group, whether they are disabled, when they last signed in and when they joined; pending invitations. |
| Manage people | As Read people, for the people added or changed. |
| Read groups | Each group's name, description and permissions. |
| Manage groups | As Read groups, for the groups added or changed. |
| Manage webhooks | The connection's webhook addresses and events. |
- Transcripts and facts can contain special category data, for example about health, ethnicity or religion, as the people in a conversation said it.
- Summaries can contain the same.
How data leaves
- Nothing is pushed. Data leaves only when the connection reads it with its key.
- Webhooks carry ids and the name of the event. They never carry the words of a conversation, summary or document.
- Webhooks are sent only to
httpsaddresses on port 443 that are not private or internal. Redirects are not followed.
What InMyWords records
| Record | Holds | Kept |
|---|---|---|
| Call log | Each call's time, method, address, status, duration and IP address. | 90 days |
| Audit trail | Each change a connection makes, and each read of a conversation's words, under the connection's name. | As the organisation's audit trail is kept. |
| Keys | A one-way hash of each key and its last four characters. The key itself is not kept. | Until the connection is removed. |
| Acceptance | Who accepted this policy, which version, and when; who withdrew it, and when. | For the life of the organisation. |
Acceptance
- A person holding Manage integrations accepts this policy for the organisation.
- Acceptance is by version. When the policy changes, the new version must be accepted before any connection works again.
- Withdrawing acceptance stops every connection at once.
- Accepting again lets connections work again. Connections and keys are kept while acceptance is withdrawn.
Version dated 3 October 2026.
Document control
- Reference
- IMW-POL-010
- Version
- 01
- Release date
- 2 October 2026
- Status
- Released