_Last updated: version 2026-09-25. This is a template and must be reviewed by a lawyer (and, for the EU, checked against the GDPR) before use._
[Your company legal name] is responsible for personal data processed through NovuHub. Contact: [privacy contact email].
Data is hosted in EU (Germany). Payment is handled by our payment provider (a merchant of record) which processes billing data under its own privacy terms; we do not store card numbers.
We share personal data only with the processors listed below, each bound by a data-processing agreement under Art. 28 GDPR, and with authorities where the law requires it. We do not sell personal data. The list is generated from the services this installation actually uses, so it is current by construction; we announce a new sub-processor at least 30 days before it starts processing customer data, and you may object within that period.
| Purpose | Sub-processor | Location of processing | Safeguard |
|---|---|---|---|
| Hosting of the application and database | Hetzner Online GmbH, Gunzenhausen, Germany | Germany (EU) | EU processor — Art. 28 contract (Hetzner AVV) |
| Transactional e-mail (invitations, password resets, notifications) | Your configured SMTP relay (smtp.gmail.com) | as configured | Art. 28 contract with the relay operator |
AI features (optional). When an AI key is added — by us for the whole installation, or by your company in Settings → Integrations — some features send data to the AI provider (Anthropic PBC, USA) to produce their result: My Assistant sends the calculated findings for the person's own view (titles, figures, and the names of the people and clients involved — never chat messages, mailboxes or confidential HR fields); reading invoices from e-mail sends the text of that e-mail; the P&L import sends account numbers and names. Without a key none of this happens. When your company uses its own key, your company's own contract with the provider applies to that processing.
We keep each class of data only as long as the purpose or the law requires:
| Data | Kept for | Why |
|---|---|---|
| Workspace data of an active customer (tasks, documents, finance and HR records) | for the life of the contract | it is the customer's data; the customer deletes what they no longer need |
| Workspace data after the contract ends (export stays available in that time) | 30 days | time to export or to reverse a cancellation; then deleted |
| Encrypted database backups (rolling) | 30 days | disaster recovery; a deletion propagates to backups within this period |
| Server, access and security logs (IP address, user agent, request identifier) | 90 days | detecting and investigating abuse (Art. 6(1)(f) GDPR) |
| Our invoices to you and payment records | 10 years | statutory retention under § 147 AO and § 257 HGB |
| E-mail addresses that bounced or complained (suppression list) | until removed on request | so that the address is never mailed again |
| Trial workspaces that were never converted | 90 days after the trial ends | keeping only data that serves a contract |
When a period ends the data is deleted from the live system; backups rotate out within the backup period stated above. A workspace administrator can delete an account or export the workspace at any time from within the Service.
Subject to law, you may request access, correction, export (data portability), deletion ("right to erasure"), or restriction of your personal data. Workspace administrators can produce a data export and delete an account from within the Service; for other requests contact [privacy contact email].
We use access controls (per-user, server-enforced), encryption in transit, security headers, login throttling, audit logging and regular backups. No system is perfectly secure, but we work to protect your data.
We use only the cookies necessary to keep you signed in and secure. We do not use advertising cookies.
We will post updates with a new version and date, and where required ask you to accept them.
Contact for privacy questions: [privacy contact email]