1. Who we are and what this policy covers
This policy describes personal information handled through the Hubyfy website, Hubyfy work platform, Hubyfy Spaces and related support. The operator identified below is responsible for its own account, billing, website and support processing. An organization using the products ordinarily decides how its workspace content is used; for that content, we act on its instructions as a service provider or processor.
- Operator
- Hubyfy LLC
- Registered address
- 777 Brickell Ave, Suite 500, Miami, FL 33131
- Country
- United States
- Contact
- hubyfy99@gmail.com
- Privacy requests
- hubyfy99@gmail.com
Spaces and Hubyfy have separate product access. Connecting them must not silently grant access to another organization’s information. This policy describes optional functionality only where that functionality is actually enabled.
2. Information we handle
- Account and organization information: name, email, profile, organization membership, permissions, authentication records and preferences.
- Work content: customer/contact information, projects, boards, documents, files, messages, tasks, calendar events and information you or your organization add or connect.
- Spaces information: profile or avatar details, office and room membership, presence and collaboration content provided through enabled Spaces features. Voice, video, recording or transcription requires the relevant feature and permission; joining a space does not itself mean a recording is made.
- Connected services: the account identifiers, authorization tokens and provider data needed for the feature you authorize. Depending on the integration, this can include email, recipients, attachments, calendars, selected cloud files, meeting details, messages and permitted CRM records.
- Optional AI and media: prompts, relevant work context, selected content, recordings, transcripts and generated results when an enabled feature uses them. Background automations may run according to the rules an authorized user configures.
- Operations and billing: IP address, browser/device details, security and error logs, support correspondence, subscription/usage records, invoices and payment-provider references. Do not send card details to our support email.
3. Purposes and legal grounds
We use account and service information to deliver the requested product, manage access, respond to support requests and administer the contract. We use proportionate security and operational information for our legitimate interests in preventing abuse and maintaining a reliable service, subject to your rights. Billing and required records may be kept to meet legal obligations. Where consent is required, including for optional tracking or particular recording activities, we request it before that processing and provide a way to withdraw it. For customer-controlled workspace information, the customer establishes its legal basis and provides instructions to us.
4. Integrations, Google data and AI
We request the permissions needed for the selected integration. You can decline a connection, disconnect it in the product where supported, and revoke access in the provider’s account settings. Disconnecting stops future authorized access; it does not necessarily erase previously imported records. Follow the data deletion instructions for erasure requests.
Hubyfy’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used for the disclosed, user-facing features you authorize. It is not sold, used for advertising, or used to train generalized AI or machine-learning models. Human access is limited to your affirmative permission for specific data, security/abuse investigations, legal obligations, or permitted internal operations on appropriately aggregated and anonymized information.
Optional AI features send the content needed for the requested function to the configured provider. This can include sensitive business content in a selected email, document or transcript. Outputs can be inaccurate and should be reviewed before use or sending. Disabling provider response storage is not a promise that all provider operational or abuse-monitoring retention is zero. Provider terms and the applicable account configuration must be checked before processing restricted data.
5. Who receives information
Information is available to the people your organization authorizes and to recipients you or an automation choose. Restricted service providers may process it to supply hosting, support, payments, AI or communications. See service providers for their purposes and activation status. A customer-connected account may also be governed by its own provider contract. We may disclose information when legally required, to investigate abuse, protect rights, or support a business transfer subject to applicable safeguards and notice. We do not sell personal information or use connected-service content for targeted advertising.
6. Locations and international transfers
Storage and processing locations depend on the deployed environment and enabled providers. We do not promise EU-only storage or a particular hosting region without an agreed deployment commitment. Where applicable law requires a transfer mechanism, we use an appropriate mechanism, such as an adequacy decision or applicable standard contractual clauses with necessary safeguards. Ask for the arrangements that apply to your organization before enabling a service with residency restrictions.
Before publication: confirm the selected hosting region, the providers actually enabled for each product, contractual transfer mechanisms and the retention schedule below.
7. Retention and deletion
Workspace content is retained while needed to supply the service and follow the customer’s instructions. Account/support records are retained for their stated purpose; security logs and recovery copies have separate, limited retention. Billing or dispute records may need to remain for a legally required period. We restrict records retained for those purposes rather than reusing them for unrelated work.
The final schedule must specify active-storage deletion, recovery-copy expiry and log retention for the actual deployment. A hidden or soft-deleted record is not necessarily erased. Verified requests cover active and soft-deleted copies and relevant provider copies under our control; backup deletion or expiry is tracked so a restore does not reintroduce erased data. We explain any lawful retention exception. Deleting Hubyfy data does not delete copies independently controlled by another provider, recipient or participant.
8. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, portability, restriction or objection, and withdraw consent for consent-based processing. Contact hubyfy99@gmail.com with the product and enough information to locate your account or record. A meeting participant or contact does not need an account to make a request. We verify identity proportionately and respond within applicable legal deadlines. Where your organization controls the data, we coordinate with it. You may complain to the competent data-protection authority.
See our cookie policy for browser storage. Organization administrators control some sharing and retention settings. No consequential decision about an individual should rely solely on an AI suggestion from these products.
9. Children, updates and contact
The products are intended for professional use and are not directed to children. Tell us if you believe a child has supplied personal information without appropriate authorization. We date material policy changes and notify affected users before a materially different use requiring notice or renewed consent. The contact above handles privacy questions and requests.
Need help?
Contact hubyfy99@gmail.com. Include the product and relevant organization, but never send passwords, access tokens or payment-card details.
