🌐 Language:

Privacy Policy & Data Processing Agreement

Effective: April 17, 2026  Β·  Last updated: April 17, 2026
Oceanic Consulting VOF Β· KVK 84553081 Β· Poortugaal, South Holland, Netherlands
privacy@hubrix.ai

πŸ“‹ Table of Contents

  1. Who We Are (Controller)
  2. What Data We Collect
  3. How We Use Your Data (Legal Basis)
  4. Data Retention
  5. Third-Party Processors & Transfers
  6. Your Rights (GDPR Art. 12–22)
  7. Security Measures
  8. Cookies
  9. Data Processing Agreement (DPA)
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact & Complaints

1 Who We Are (Data Controller)

Hubrix AI Suite is operated by Oceanic Consulting VOF, registered in the Netherlands.

DetailInformation
Legal NameOceanic Consulting VOF
Trade NameHubrix
KVK Number84553081
AddressPoortugaal, South Holland, Netherlands
Emailprivacy@hubrix.ai
Data Protection RoleData Controller (GDPR Art. 4(7))
Supervisory AuthorityAutoriteit Persoonsgegevens (AP) β€” autoriteitpersoonsgegevens.nl

πŸ‡³πŸ‡± Nederlands β€” Wie zijn wij

Hubrix AI Suite wordt beheerd door Oceanic Consulting VOF (KVK 84553081), gevestigd in Poortugaal, Zuid-Holland. Wij zijn de verwerkingsverantwoordelijke voor uw persoonsgegevens in de zin van de AVG (Algemene Verordening Gegevensbescherming / GDPR EU 2016/679).

2 What Data We Collect

2.1 Account Data

DataPurposeRequired
UsernameAccount identificationYes
Email addressAccount access, notificationsYes
Password (bcrypt hash)Authentication β€” plaintext never storedYes
Company nameMulti-tenant isolationCompany accounts
Account type & planFeature access controlYes

2.2 Usage Data

DataPurposeRetention
Chat messages & historyConversation continuityUntil deleted by user
Uploaded documentsRAG / document analysisUntil deleted by user
AI model usage (tokens)Billing & credit tracking24 months
API request logsRate limiting, abuse prevention30 days
IP addressSecurity, fraud prevention30 days

2.3 Payment Data

Payment processing is handled by Stripe (Stripe Payments Europe Ltd, Dublin). We store only your Stripe Customer ID β€” never your card details. Stripe is PCI-DSS Level 1 certified.

2.4 SSO Data (Optional)

If you connect Google or Microsoft for Single Sign-On, we receive your name and email from those providers. We do not receive passwords. You may disconnect SSO at any time in Settings.

πŸ‡³πŸ‡± Nederlands β€” Welke gegevens verzamelen wij

Wij verzamelen accountgegevens (gebruikersnaam, e-mail, wachtwoord als bcrypt-hash), gebruiksgegevens (chatgeschiedenis, geΓΌploade documenten, tokengebruik) en betalingsgegevens via Stripe. Wij slaan nooit uw bankkaartgegevens op. Chatberichten worden bewaard totdat u ze verwijdert.

3 How We Use Your Data (Legal Basis)

Processing ActivityLegal Basis (GDPR Art. 6)Details
Account creation & authenticationContract (Art. 6(1)(b))Necessary to provide the service
Delivering AI responsesContract (Art. 6(1)(b))Core service functionality
Billing & invoicingContract + Legal obligation (Art. 6(1)(b)(c))Stripe payments, Dutch tax records (7 years)
Security & fraud preventionLegitimate interest (Art. 6(1)(f))Rate limiting, abuse detection, IP logging
Service improvementLegitimate interest (Art. 6(1)(f))Aggregate analytics β€” never individual profiling
Legal complianceLegal obligation (Art. 6(1)(c))Dutch law, AP requests
Marketing communicationsConsent (Art. 6(1)(a))Only with explicit opt-in β€” withdraw anytime
βœ… We do not sell your data. We do not use your data for advertising. We do not profile individual users. AI queries are processed by third-party providers under data processing agreements β€” not used to train their models (see Section 5).

πŸ‡³πŸ‡± Nederlands β€” Rechtsgrond verwerking

Wij verwerken uw gegevens op basis van: uitvoering van de overeenkomst (Art. 6(1)(b) AVG) voor accountbeheer en dienstverlening; wettelijke verplichting (Art. 6(1)(c) AVG) voor belastingadministratie; gerechtvaardigd belang (Art. 6(1)(f) AVG) voor beveiliging; en toestemming (Art. 6(1)(a) AVG) voor marketingcommunicatie. Wij verkopen uw gegevens niet.

4 Data Retention

Data CategoryRetention PeriodBasis
Account dataDuration of account + 30 days after deletion requestContract
Chat history & documentsUntil deleted by user, or account closureUser control
Token usage / billing records24 monthsLegitimate interest
Stripe payment records7 yearsDutch tax law (Belastingdienst)
Security logs (IP, rate events)30 daysLegitimate interest
Backups30 days remote, 10 days localBusiness continuity

Upon account deletion, all personal data is permanently removed within 30 days, except where retention is required by law (e.g. tax records).

πŸ‡³πŸ‡± Nederlands β€” Bewaartermijnen

Accountgegevens worden 30 dagen na verwijderingsverzoek gewist. Chatgeschiedenis wordt bewaard totdat u deze verwijdert. Betalingsgegevens worden 7 jaar bewaard conform de Nederlandse belastingwetgeving. Beveiligingslogboeken worden 30 dagen bewaard.

5 Third-Party Processors & International Transfers

We use the following sub-processors. All have signed Data Processing Agreements and provide adequate safeguards under GDPR Chapter V.

ProcessorPurposeLocationSafeguard
AnthropicClaude AI modelsUSADPA + SCCs (Art. 46(2)(c)). Zero Data Retention available.
OpenAIGPT models, Whisper STT, EmbeddingsUSADPA + SCCs. Zero Data Retention available.
GoogleGemini models, OAuth SSOEU/USADPA + SCCs + EU adequacy decisions where applicable.
ElevenLabsText-to-SpeechUSADPA + SCCs
StripePayment processingIreland (EU)EU entity β€” GDPR compliant. PCI-DSS Level 1.
Hetzner OnlineServer hostingGermany (EU)EU entity β€” ISO 27001 certified. Data stays in EU.
ResendTransactional emailUSADPA + SCCs
πŸ”’ AI Provider Data Policy: Your prompts are sent to AI providers solely to generate responses. Anthropic and OpenAI offer Zero Data Retention (ZDR) β€” meaning prompts are not stored or used for model training. Enterprise customers may request ZDR-enabled API configurations. Contact privacy@hubrix.ai.

πŸ‡³πŸ‡± Nederlands β€” Subverwerkers en doorgifte

Wij maken gebruik van subverwerkers voor AI-verwerking (Anthropic, OpenAI, Google), betalingen (Stripe, Ierland) en hosting (Hetzner, Duitsland). Alle overdrachten naar de VS zijn gebaseerd op Standaard Contractbepalingen (SCC's) conform Art. 46(2)(c) AVG. Uw gegevens worden niet gebruikt om AI-modellen te trainen.

6 Your Rights (GDPR Art. 12–22)

As an EU data subject, you have the following rights. All requests are responded to within 30 days (extendable to 90 days for complex requests with notice).

πŸ“‹

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

✏️

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

πŸ—‘οΈ

Right to Erasure (Art. 17)

Request deletion of your data ("right to be forgotten").

⏸️

Right to Restriction (Art. 18)

Restrict how we process your data in certain circumstances.

πŸ“¦

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format.

🚫

Right to Object (Art. 21)

Object to processing based on legitimate interests.

πŸ€–

Automated Decision-Making (Art. 22)

We do not make solely automated decisions with legal effect on individuals.

↩️

Right to Withdraw Consent (Art. 7(3))

Withdraw consent at any time where processing is consent-based.

To exercise any right, email privacy@hubrix.ai with subject line "GDPR Request β€” [Right]". We may verify your identity before processing.

πŸ‡³πŸ‡± Nederlands β€” Uw rechten

U heeft recht op inzage (Art. 15), rectificatie (Art. 16), verwijdering (Art. 17), beperking (Art. 18), overdraagbaarheid (Art. 20) en bezwaar (Art. 21). Verzoeken worden binnen 30 dagen beantwoord. Stuur een e-mail naar privacy@hubrix.ai met als onderwerp "AVG-verzoek β€” [recht]". U kunt ook een klacht indienen bij de Autoriteit Persoonsgegevens via autoriteitpersoonsgegevens.nl.

7 Security Measures

MeasureImplementation
Encryption in transitTLS 1.2/1.3 enforced via Nginx + Let's Encrypt. HSTS enabled.
Encryption at restHetzner server-level encryption. Database on encrypted volumes.
Authenticationbcrypt password hashing (cost factor 12). JWT HttpOnly cookies. API keys SHA-256 hashed.
Access controlRow-Level Security (RLS) on 13 PostgreSQL tables. 4-tier role model.
API securityRate limiting (30 req/min), parameterized queries (no SQL injection), XSS sanitization.
BackupsDaily encrypted backups. Remote copy to secondary EU server. 30-day retention.
Incident responseData breaches reported to AP within 72 hours (GDPR Art. 33). Affected users notified within 72 hours where required (Art. 34).

πŸ‡³πŸ‡± Nederlands β€” Beveiligingsmaatregelen

Wij passen TLS 1.3-versleuteling toe voor datatransmissie, bcrypt-wachtwoordhashing, roltoegangscontrole en dagelijkse versleutelde back-ups. Datalekken worden binnen 72 uur gemeld aan de Autoriteit Persoonsgegevens conform Art. 33 AVG.

8 Cookies

CookieTypePurposeDurationConsent
hubrix_tokenStrictly necessaryAuthentication session JWT7 daysNot required
hubrix_consentFunctionalStores your cookie consent choice1 yearSet on consent

We use no tracking cookies, no advertising cookies, and no third-party analytics cookies (e.g. Google Analytics). The authentication cookie is strictly necessary β€” it cannot be declined without losing access to the service.

πŸ‡³πŸ‡± Nederlands β€” Cookies

Wij gebruiken uitsluitend een strikt noodzakelijk authenticatiecookie (hubrix_token) en een toestemmingscookie (hubrix_consent). Er worden geen tracking- of advertentiecookies gebruikt. Strikt noodzakelijke cookies vereisen geen toestemming op grond van Art. 5(3) van de ePrivacy-richtlijn.

9 Data Processing Agreement (DPA) For Business Customers

This section constitutes the Data Processing Agreement between Oceanic Consulting VOF ("Processor") and the business customer ("Controller") as required by GDPR Art. 28.

9.1 Subject Matter

Oceanic Consulting VOF processes personal data on behalf of the Controller solely for the purpose of providing the Hubrix AI Suite service as described in the service agreement.

9.2 Nature and Purpose of Processing

9.3 Types of Personal Data

The categories of personal data processed are determined by the Controller and may include: names, email addresses, and any personal data contained within documents or prompts submitted to the platform.

9.4 Processor Obligations (Art. 28(3))

Oceanic Consulting VOF agrees to:

9.5 Sub-processors

The Controller authorises use of sub-processors listed in Section 5. Oceanic Consulting VOF will notify the Controller of any intended changes to sub-processors with at least 30 days' notice, giving the Controller the opportunity to object.

9.6 International Transfers

Data transfers to sub-processors outside the EEA (Anthropic, OpenAI, ElevenLabs) are governed by Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and Commission Implementing Decision (EU) 2021/914.

9.7 Audit Rights

The Controller has the right to conduct audits or inspections, or to mandate an independent auditor. Requests must be submitted to privacy@hubrix.ai with 30 days' notice. Costs are borne by the Controller unless non-compliance is found.

9.8 Termination

Upon termination of the service agreement, Oceanic Consulting VOF will delete all Controller personal data within 30 days, unless longer retention is required by applicable law.

πŸ“„ Signed DPA: Enterprise customers requiring a separately signed DPA document may request one at privacy@hubrix.ai. We respond within 5 business days.

πŸ‡³πŸ‡± Nederlands β€” Verwerkersovereenkomst

Dit gedeelte vormt de verwerkersovereenkomst tussen Oceanic Consulting VOF (Verwerker) en de zakelijke klant (Verwerkingsverantwoordelijke) conform Art. 28 AVG. Wij verwerken persoonsgegevens uitsluitend op basis van gedocumenteerde instructies van de Verwerkingsverantwoordelijke. Enterprise-klanten kunnen een afzonderlijk ondertekende verwerkersovereenkomst aanvragen via privacy@hubrix.ai.

10 Children's Privacy

Hubrix AI Suite is intended for business use only. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has created an account, contact privacy@hubrix.ai and we will delete the account immediately.

πŸ‡³πŸ‡± Nederlands β€” Privacy van minderjarigen

Hubrix AI Suite is uitsluitend bedoeld voor zakelijk gebruik. Wij verzamelen niet bewust persoonsgegevens van personen onder de 16 jaar. Meld eventuele minderjarige gebruikers via privacy@hubrix.ai.

11 Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via:

Continued use of Hubrix after the effective date of changes constitutes acceptance of the updated policy.

πŸ‡³πŸ‡± Nederlands β€” Wijzigingen

Wezenlijke wijzigingen in dit privacybeleid worden per e-mail en via een melding in de app gecommuniceerd. Voortgezet gebruik na de ingangsdatum geldt als aanvaarding van het gewijzigde beleid.

12 Contact & Complaints

πŸ“¬ Contact Us

Privacy requests & DPA enquiries:
privacy@hubrix.ai

General:
info@hubrix.ai

Postal address:
Oceanic Consulting VOF
Poortugaal, South Holland
Netherlands

You have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
autoriteitpersoonsgegevens.nl/contact
Telefoon: 088 – 1805 250