Event-driven engagement platform · web console and API

From first contact to conversion, every event counts.

Missivia follows a prospect from their first interaction until they become a customer, and beyond.

Native and business events set off nurturing sequences, journeys, campaigns and service messages, with scoring, conditions, delays and conversion goals.

Every message honours consent per purpose and an authorisation computed server-side; e-mail is the first channel, others will follow.

  • Native and business events
  • Triggers, delays and de-duplication
  • Sequences, journeys and conversion goals
  • Scoring and dynamic segments
  • Consent per purpose
  • Authorisation computed server-side
EVENTSDECISIONSMESSAGESOpen, clicknative eventOrder placedbusiness eventEntry into a segmentnative eventTriggercondition · delayJourneywait · branchgoal → exitMessage deliveredconsent checkedBounded resendone send at mostGoal reachedconversion counted
What comes in, what decides, what goes out. The pulses follow the real path from an event to a message.
What the platform does

Six areas, in the order they come into play

It starts with what happens — an event —, turns it into a reaction, decides who may do what with it, composes the message, proves the consent, plugs in your tools, and delivers. The detail — the grammar of events and journeys, the authorisation matrix, data classes, API conventions — lives on its own page.

01

Events, triggers and conversion journeys

Native events — open, click, bounce, unsubscribe, entry into a segment — and business events posted by your tools with their payload set off what comes next: nurturing sequences, branching journeys, campaigns, service messages. Conditions, delays, de-duplication, waits for an event, A/B tests, and conversion goals that end the journey the moment the order is placed or the appointment booked.

See the detail
02

Authorisation and access

An organisation, its spaces, its roles and its API keys compose into a single authorisation, computed by the server on every call. Rights are inherited from the role, added to by named permissions, and capped by the class of the key. A resource belonging to another space is not found, never forbidden.

See the detail
03

Templates, kits and public pages

A template editor with no code execution, reusable fragments frozen into every sent version, a live preview. Content that reads the latest event of each type, so you write from what just happened. The import of an HTML kit delivered by an agency, a file library inside the perimeter, and unsubscribe and preference pages in your own branding.

See the detail
04

Consent, sensitive data and traceability

A prospect comes in with their proof of consent: a register of acts per purpose that keeps the exact wording presented, the date, the source and the address of the form. Two tracking pixels kept under two distinct regimes. Sensitive attributes encrypted outside the record and readable on a named permission. An append-only audit log, retention periods, irreversible anonymisation and a reversibility export.

See the detail
05

API, integration and operations

A contract published before the code: opaque identifiers, cursor pagination, idempotent creations, standard errors. This is where your tools post their events and read back what happens: signed webhooks, an event log, exports with no personal data. A sandbox where nothing leaves, and a path to production made of artefacts, with no manual operation.

See the detail
06

Delivery and deliverability (e-mail channel)

The first channel open, e-mail is delivered by the platform itself: messages are handed directly to the recipients’ mail servers, from its own IP addresses. Sending domains verified with SPF, DKIM and DMARC, per-IP warm-up, bounce and complaint handling, automatic pause when a space’s thresholds are crossed.

See the detail
How it works

Four moments, from an observed fact to a delivered message

Nothing starts from an intention: everything starts from a fact. Here is what happens between the event and the inbox.

Open, click, bouncenative eventOrder placedbusiness eventThe trigger evaluates itcondition · delay · de-duplicationThe journey moves onwait · branch · A/B testgoal reached → exitThe message is deliveredconsent per purpose checked
  1. An event arrives

    Native — an open, a click, a bounce, an entry into a segment — or business, posted by your tools with its payload: “order placed”, “appointment booked”.

    EventTriggerJourneyMessage
  2. The trigger evaluates it

    A condition on the payload and on the record, a delay from zero to thirty days, an explicit de-duplication rule: every time, once only, or at most once per period.

    Every decision — fired, skipped with its reason, executed — is written to the contact’s log.

    EventTriggerJourneyMessage
  3. The journey moves on

    Relative or dated waits, waits for an event, conditions, switches, weighted splits, A/B tests.

    Any step that depends on an open or a click has three outcomes, never two: did it, did not do it in time, cannot be measured. As soon as the conversion goal is reached, the enrolment ends, wherever it stands.

    EventTriggerJourneyMessage
  4. The message is delivered

    Consent for the purpose is checked at render time, the authorisation is computed server-side, and delivery goes through the first channel open: e-mail, handed straight to the recipient’s mail server.

    EventTriggerJourneyMessage
  • 20people: the threshold below which a counter served to a platform role is masked
  • 2distinct pixels, kept under two legal regimes
  • 3outcomes on any measured step: did it, did not, cannot be measured
  • 24 hof idempotency-key replay, with no side effect at all
Authorisation

A single decision, server-side, on every call

Five elements compose the authorisation — and the interface making the call decides none of them.

  1. 1

    Space

    Derived from the token. The call cannot name another one.

  2. 2

    Role

    A set of capabilities inherited as a whole, not a checkbox per screen.

  3. 3

    Named permissions

    Cumulative, granted to a designated person, and logged.

  4. 4

    Key class

    It caps the whole: what it cannot reach, no role gives back.

  5. 5

    Decision

    A single matrix decides, and writes its decision — refusals included.

A resource belonging to another space is not found, never forbidden: the existence of an access to people is not observable from the outside.

See the matrix, role by role →

Sensitive data

What is sensitive does not travel

An attribute’s class decides, server-side, where the value is written, who may read it back and what is logged about it. A sensitive value is never a merge variable: the message is differentiated by choosing the journey.

Contact recordname, address, attributesone-way indexon a named permissionEncrypted tableAES-256-GCM, outside the recordMessage deliveredwithout the sensitive attribute
The sensitive value is never written with the record, and never leaves in a message.

A Dataventure product

Missivia is the engagement platform behind Dataventure Group’s lead-collection tools, opened to partners as a multi-space platform. Each space gets its own keys, domains, quotas and roles. E-mail is the channel served today; the platform is built to take on others, with the same consent register and the same authorisation.