← Trust, privacy & support

HUBYFY + HUBYFY SPACES

Data processing addendum

Proposed terms for processing customer personal data.

Review draft · Prepared 1 October 2026 · Applies to the products and features described below

Status and parties

This proposed Data Processing Addendum (DPA) is for incorporation into a service agreement between the customer and the operator in the legal notice. It takes effect only when agreed with the parties and completed processing schedule. Reading or downloading this page does not execute a DPA. It covers personal data processed on the customer’s behalf through the selected Hubyfy or Spaces services.

1. Roles and instructions

The customer acts as controller, or as a processor authorized by its controller, and determines the purposes and means of the customer processing. The operator acts as processor or subprocessor for that processing. We process personal data only on documented instructions, including agreed product settings and lawful user actions, unless law requires otherwise. We notify the customer of a conflicting legal obligation where permitted and inform it if we believe an instruction infringes applicable data-protection law.

2. Processing schedule

Schedule to complete with the customer
Subject and purposeProviding the subscribed work-management or virtual-office service and specifically enabled integrations.
DurationThe service term plus the agreed return/deletion and recovery-copy periods.
OperationsCollection, organization, storage, retrieval, authorized sharing, optional selected analysis and deletion as instructed.
IndividualsCustomer users, staff, contacts, invitees and participants whose information the customer lawfully supplies.
Data categoriesAccount/contact details, membership, work content and configured communication/media data described in the privacy policy.
Sensitive dataNo assumption of suitability for special-category data. The parties must agree any required safeguards before such processing.
Locations and transfersTo be specified for hosting and enabled providers, with applicable transfer safeguards.
Retention and returnTo be specified, including export format, active deletion, backup expiry and required retained records.

3. Confidentiality and security

Persons authorized to process customer personal data must be bound to confidentiality or an equivalent statutory duty. We implement technical and organizational measures appropriate to the agreed processing and risk, including access restriction, credential protection, transport protection, recovery arrangements and incident handling. The measures schedule must identify the deployed safeguards and must not rely on an unverified certification claim.

4. Subprocessors

The agreed provider schedule identifies authorized subprocessors. We impose data-protection obligations appropriate to their work and remain responsible for our subprocessor obligations. With general written authorization, we notify the customer in advance of intended changes and allow it to object on reasonable data-protection grounds before the new processing begins. The parties must agree the notice period and a workable resolution or termination process.

5. Requests and assistance

Taking account of the nature of the processing and available information, we assist the customer with individual-rights requests, security obligations, breach notifications, impact assessments and required consultations. Requests received directly are referred to the customer where appropriate, unless the law requires another response. We do not disclose customer data to an unverified requester.

6. Personal-data breaches

We notify the customer without undue delay after becoming aware of a personal-data breach affecting the customer processing and provide available information needed for its obligations. Further details may follow as the investigation develops. We cooperate on containment, correction and communications without making unauthorized statements on the customer’s behalf.

7. International transfers

Transfers subject to a legal restriction require an appropriate mechanism and any necessary supplementary measures. Where standard contractual clauses are needed, the correct modules, parties, annexes, destinations and safeguards must be completed and incorporated. This draft is not itself a signed set of transfer clauses.

8. Return, deletion and audit

At the end of the processing, we return or delete customer personal data at the customer’s choice as agreed, and delete existing copies unless law requires retention. Restricted recovery copies follow the agreed expiry and restore-deletion procedure. We make information available to demonstrate compliance with the agreed processor obligations and allow and contribute to appropriate audits or inspections, subject to safeguards protecting other customers and systems.

9. Priority and contact

The agreed DPA prevails over inconsistent service terms for the processing it covers; applicable mandatory transfer clauses take priority where required. Contact hubyfy99@gmail.com to complete the customer, product, provider, security, retention and transfer schedules before execution.

Need help?

Contact hubyfy99@gmail.com. Include the product and relevant organization, but never send passwords, access tokens or payment-card details.