Our GDPR Commitments
Controller & Processor Roles
Technical & Organizational Measures
We implement the following security measures as required by GDPR Article 32:
Sub-Processors
We use the following sub-processors. Enterprise customers are notified of new sub-processors with 30 days notice.
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Anthropic | AI model processing (Claude) | USA | Zero Data Retention (ZDR) agreement, SCCs |
| OpenAI | AI model processing (GPT-4o, Whisper) | USA | Enterprise ZDR agreement, SCCs |
| Google (Gemini) | AI model processing (Gemini Flash) | USA/EU | EU data processing terms, SCCs |
| ElevenLabs | Text-to-speech audio generation | USA | SCCs โ audio not retained |
| Stripe | Payment processing | USA/EU | Stripe DPA, SCCs, PCI-DSS compliant |
| Resend | Transactional email delivery | EU | Resend DPA โ email not retained beyond delivery |
| Hetzner | Server infrastructure (primary) | Netherlands (EU) | ISO 27001 certified, GDPR DPA |
| Google OAuth | SSO and Drive connector authentication | USA/EU | Optional โ only if you connect Google account |
| Microsoft Azure | SSO and OneDrive/SharePoint authentication | USA/EU | Optional โ only if you connect Microsoft account |
For AI providers (Anthropic, OpenAI, Google), query content is processed under Zero Data Retention agreements where available โ meaning prompts are not used for model training and are not retained after processing.
What Data Flows Where
Your documents, prompts, and responses are stored on our EU server (Netherlands). Only the content of AI queries is transmitted to AI providers. No personal account information is sent to AI providers.
- Account data โ Stays on our Netherlands server only
- AI query content โ Sent to selected AI provider (Anthropic/OpenAI/Google) for processing, returned to our server, cached and stored
- Payment data โ Sent to Stripe for processing. We receive only transaction status and customer ID.
- Emails โ Content transmitted to Resend for delivery. Not retained by Resend after delivery.
- Google Drive / OneDrive files โ Downloaded to our Netherlands server when you explicitly import them. Not transmitted to third parties.
- SSO tokens โ Stored encrypted on our Netherlands server. Not shared with third parties.
Request a Data Processing Agreement
Enterprise customers and organizations deploying Hubrix for their employees can request a formal DPA. We typically respond within 5 business days.
Exercise Your GDPR Rights
To exercise any of your rights under GDPR, contact us at privacy@hubrix.ai. We will respond within 30 days.
You can also lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl
Privacy Contact
Privacy inquiries: privacy@hubrix.ai
General: info@hubrix.ai
Address: Hubrix Consulting VOF ยท KVK 84553081 ยท Poortugaal, South Holland, Netherlands
Response time: Within 30 days for GDPR requests ยท Within 5 business days for DPA requests