GDPR Compliance & Data Protection

Last Updated: [Aug, 2026]

ConnectorHub is committed to protecting personal data and complying with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

This page explains how ConnectorHub approaches GDPR compliance, how we protect personal data, the rights available to individuals in the European Economic Area (EEA), and the responsibilities of organizations that use ConnectorHub to process personal data.

This page should be read together with our Privacy Policy, Data Processing Addendum (DPA), Cookie Policy, and applicable Terms of Service.

1. Our Commitment to GDPR

ConnectorHub is designed to support secure, controlled, and transparent processing of business and operational data.

Our GDPR approach is based on the core principles of data protection, including:

  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

We apply appropriate technical and organizational measures to protect personal data and maintain appropriate controls throughout the data lifecycle.

ConnectorHub does not sell personal data.

When we process data on behalf of customers using our platform (e.g., workflow logs, connector metadata, integration execution details).

2. When GDPR Applies

The GDPR may apply to ConnectorHub when:

  • We process personal data of individuals located in the EEA;
  • We offer services to individuals or organizations in the EEA;
  • We monitor the behavior of individuals in the EEA; or
  • We process personal data on behalf of an organization that is subject to the GDPR.

Where GDPR applies, ConnectorHub processes personal data in accordance with applicable GDPR requirements.

3. Controller and Processor Roles

ConnectorHub may act as either a data controller or a data processor, depending on the circumstances.

ConnectorHub as Data Controller

ConnectorHub generally acts as a controller when we determine why and how personal data is processed for our own business purposes.

Examples include:

  • Managing website visitors
  • Managing customer and prospect relationships
  • Processing demo and contact requests
  • Managing user accounts
  • Sending permitted marketing communications
  • Website analytics
  • Security monitoring
  • Customer support
  • Business administration

In these circumstances, ConnectorHub determines the purposes and means of processing.

ConnectorHub as Data Processor

ConnectorHub may act as a processor when customers use our platform to process personal data through integrations, workflows, synchronization, automation, or other customer-configured functionality.

In these circumstances:

  • The customer generally determines the purposes of processing;
  • The customer determines which data is connected to ConnectorHub;
  • ConnectorHub processes the data according to the customer's documented instructions;
  • ConnectorHub applies appropriate technical and organizational safeguards;
  • Processing is governed by an applicable Data Processing Addendum or equivalent agreement.

Where ConnectorHub acts as a processor, the customer remains responsible for establishing an appropriate legal basis for processing personal data and providing required privacy notices to individuals.

4. Data Protection Addendum

For customers subject to GDPR, ConnectorHub provides contractual data protection commitments through its Data Processing Addendum (DPA).

The DPA addresses matters including:

  • Processing instructions
  • Confidentiality obligations
  • Security measures
  • Subprocessor requirements
  • Assistance with data-subject requests
  • Personal data breach notification
  • International data transfers
  • Data deletion and return
  • Audits and compliance information
  • Processor and controller responsibilities

Where required, ConnectorHub enters appropriate data processing terms with customers before processing personal data on their behalf.

5. Categories of Personal Data

Depending on how ConnectorHub is used, personal data may include:

Identity and Professional Information

  • Name
  • Business email address
  • Telephone number
  • Company name
  • Job title
  • Professional role

Account Information

  • Username
  • Authentication information
  • Account identifiers
  • Organization information
  • User roles and permissions

Technical Information

  • IP address
  • Browser and device information
  • Operating system
  • Device identifiers
  • Log information
  • Session information
  • Security and authentication information

Usage Information

  • Website interactions
  • Product usage
  • Workflow activity
  • Connector usage
  • Error and diagnostic information
  • Audit information

Communication Information

  • Contact-form submissions
  • Support requests
  • Email communications
  • Feedback
  • Survey responses

Integration and Workflow Data

Where customers configure integrations, ConnectorHub may process data transmitted between connected systems.

The types of personal data contained within such information are determined by the customer and the connected systems.

6. Lawful Bases for Processing

Where GDPR applies, ConnectorHub processes personal data using one or more lawful bases under Article 6 GDPR.

Performance of a Contract

We may process personal data where processing is necessary to:

  • Provide requested services
  • Manage accounts
  • Provide customer support
  • Process transactions
  • Maintain the customer relationship
  • Perform contractual obligations

Legitimate Interests

We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the individual's rights and freedoms.

Examples may include:

  • Protecting the security of our services
  • Preventing fraud and abuse
  • Improving our products
  • Managing business relationships
  • Maintaining service reliability
  • Conducting appropriate B2B communications
  • Defending legal claims
  • Protecting our systems and property

Consent

Where required, we may rely on consent for activities such as:

  • Non-essential cookies
  • Certain analytics technologies
  • Certain marketing communications
  • Other optional processing activities

Individuals may withdraw consent at any time.

Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.

Legal Obligations

We may process personal data where necessary to comply with legal, regulatory, accounting, tax, security, or law enforcement obligations.

7. Data Minimization and Purpose Limitation

ConnectorHub follows data minimization and purpose limitation principles.

We seek to process only the personal data reasonably necessary for a defined and legitimate purpose.

We do not intentionally access customer data payloads unless access is:

  • Required to provide the requested service;
  • Necessary for troubleshooting or support;
  • Required for security or compliance purposes; or
  • Explicitly authorized by the customer.

Customer-configured integrations determine what information is transmitted between connected systems.

8. Security and Technical Safeguards

ConnectorHub implements technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, destruction, or unlawful processing.

  • Encryption in transit
  • Encryption at rest
  • Role-based access controls
  • Multi-factor authentication
  • Single sign-on support
  • Tenant isolation
  • Secure credential and API-key management
  • Audit logging
  • Monitoring and anomaly detection
  • Security controls and access restrictions
  • Data loss prevention measures
  • Incident response procedures
  • Backup and recovery controls
  • Vulnerability and security management

ConnectorHub's security practices are designed to support enterprise requirements for confidentiality, integrity, availability, and accountability.

9. Subprocessors

ConnectorHub may engage third-party service providers to support the delivery and operation of its services.

These providers may support:

  • Cloud infrastructure
  • Hosting
  • Storage
  • Authentication
  • Security
  • Monitoring
  • Customer support
  • CRM
  • Analytics
  • Communications
  • Payment processing
  • Other essential business functions

Where ConnectorHub acts as a processor, subprocessors are engaged subject to applicable contractual and data protection requirements.

ConnectorHub requires subprocessors to maintain appropriate safeguards for personal data.

10. International Data Transfers

ConnectorHub may process or transfer personal data outside the EEA.

Where GDPR restricts an international transfer, ConnectorHub uses an appropriate transfer mechanism recognized under applicable law.

Depending on the circumstances, these mechanisms may include:

  • An adequacy decision;
  • EU Standard Contractual Clauses (SCCs);
  • Appropriate supplementary safeguards;
  • Binding Corporate Rules, where applicable;
  • An applicable certification or approved mechanism; or
  • Another lawful transfer mechanism recognized under GDPR.

The European Commission recognizes Standard Contractual Clauses as an appropriate mechanism for certain transfers of personal data from the EEA to third countries.

Where required, ConnectorHub evaluates international transfer risks and implements appropriate supplementary technical, contractual, and organizational safeguards.

11. Data Retention and Deletion

ConnectorHub retains personal data only for as long as necessary for the applicable processing purpose, unless a longer retention period is required or permitted by law.

Retention periods may depend on:

  • The purpose of processing
  • The nature of the information
  • The sensitivity of the data
  • Contractual requirements
  • Legal obligations
  • Security requirements
  • Regulatory requirements
  • Dispute resolution
  • Establishment or defense of legal claims

When personal data is no longer required, ConnectorHub will delete, anonymize, or securely dispose of it in accordance with applicable retention procedures.

For customer data processed as a processor, deletion and return requirements are generally governed by the applicable DPA and customer instructions.

12. Data Subject Rights Under GDPR

Individuals whose personal data is subject to GDPR may have the following rights.

Right of Access

You may request confirmation of whether we process your personal data and request access to that information.

Right to Rectification

You may request correction of inaccurate or incomplete personal data.

Right to Erasure

You may request deletion of your personal data in circumstances provided by GDPR.

This right is subject to applicable exceptions, including where retention is necessary to comply with a legal obligation or establish, exercise, or defend legal claims.

Right to Restriction

You may request restriction of processing in circumstances provided by GDPR.

Right to Data Portability

Where applicable, you may request personal data you provided to us in a structured, commonly used, and machine-readable format.

Right to Object

You may object to certain processing based on legitimate interests or other applicable legal grounds.

You may object to direct marketing at any time.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time.

Rights Regarding Automated Decision-Making

Where applicable, GDPR provides rights relating to decisions based solely on automated processing, including profiling, where such processing produces legal or similarly significant effects.

ConnectorHub does not intend to make decisions concerning individuals based solely on automated processing that produce legal or similarly significant effects.

13. How to Exercise Your GDPR Rights

To submit a GDPR request, contact:

Privacy Contact: security@connectorhub.ai

Please include:

  • Your name
  • Contact information
  • Organization, if relevant
  • The right you wish to exercise
  • Sufficient information to help us identify the relevant personal data

We may request additional information where reasonably necessary to verify your identity and protect personal data against unauthorized disclosure.

We generally respond to valid GDPR requests without undue delay and, in principle, within one month of receiving the request.

Where permitted by GDPR, this period may be extended by up to two additional months where necessary because of the complexity or number of requests.

We will inform you where an extension applies.

14. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that our processing of your personal data violates applicable data protection law.

You may generally contact the supervisory authority in the country where you:

  • Live
  • Work; or
  • Believe an infringement occurred.

You are not required to contact ConnectorHub before exercising this right.

However, we encourage individuals to contact us first so that we can investigate and attempt to resolve privacy concerns.

The European Commission provides guidance on exercising GDPR rights and contacting data protection authorities.

15. Special Categories of Personal Data

ConnectorHub does not intentionally request special-category personal data for general website or marketing activities.

Special categories under GDPR include information concerning:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade-union membership
  • Genetic data
  • Biometric data used for uniquely identifying an individual
  • Health data
  • Sex life or sexual orientation

However, customers may configure integrations that transmit information containing special categories of personal data.

Where ConnectorHub acts as a processor, such processing is performed according to the customer's instructions and applicable contractual requirements.

Customers are responsible for ensuring that they have an appropriate legal basis and, where required, an additional condition under Article 9 GDPR for processing special-category data.

16. Automated Decision-Making and Profiling

ConnectorHub may use automation, analytics, and AI-assisted functionality to support product functionality, workflow configuration, mapping, security, service improvement, and operational processes.

ConnectorHub does not intend to use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

Where such processing is introduced in the future and GDPR requirements apply, ConnectorHub will provide appropriate information and implement applicable safeguards and individual rights.

Where applicable, individuals may have the right to:

  • Obtain meaningful information about the processing;
  • Request human intervention;
  • Express their point of view;
  • Contest a decision; and
  • Exercise other rights provided under GDPR.

17. Cookies and Tracking Technologies

ConnectorHub uses cookies and similar technologies on its website.

These technologies may include:

  • Necessary cookies
  • Functional cookies
  • Analytics cookies
  • Performance technologies
  • Marketing or advertising technologies, where applicable
  • Pixels, tags, scripts, and similar technologies

Where GDPR or applicable ePrivacy requirements require consent, ConnectorHub will obtain consent before using non-essential tracking technologies.

You may withdraw or change your cookie consent through the cookie preference mechanism made available on our website.

You may also control certain cookies through your browser settings.

18. Marketing Communications

ConnectorHub may send marketing communications where permitted by applicable law.

These may include:

  • Product announcements
  • Product updates
  • Educational resources
  • Webinars
  • Events
  • Industry content
  • Product-related offers

You may opt out of marketing communications at any time.

Each marketing email will provide an unsubscribe mechanism where required.

You may also contact our privacy team to request that your personal data no longer be used for direct marketing.

Withdrawal from marketing communications does not affect essential service, security, transactional, or account-related communications.

19. Personal Data Obtained From Third Parties

ConnectorHub may receive personal data from third-party sources, where permitted by applicable law.

These sources may include:

  • Customers
  • Business partners
  • Referral partners
  • Professional networking platforms
  • Publicly available business sources
  • Lead-generation providers
  • Analytics providers
  • CRM and marketing platforms
  • Third-party applications connected by customers

Where required under GDPR, ConnectorHub will provide appropriate information concerning the source of personal data and the purposes and legal basis for processing.

20. Personal Data Breaches

ConnectorHub maintains procedures designed to identify, assess, contain, investigate, and respond to personal data breaches.

Where ConnectorHub acts as a processor, we will notify affected customers of qualifying personal data breaches in accordance with the applicable DPA and GDPR requirements.

Where ConnectorHub acts as a controller, we will assess notification obligations and notify the relevant supervisory authority and affected individuals where required by applicable law.

21. Accountability and Privacy by Design

ConnectorHub incorporates privacy and security considerations into its product and operational processes.

Where appropriate, we apply:

  • Data minimization
  • Access controls
  • Privacy-conscious system design
  • Security by design
  • Purpose limitation
  • Retention controls
  • User permissions
  • Auditability
  • Risk-based security controls

Where required by GDPR, ConnectorHub may conduct Data Protection Impact Assessments (DPIAs) or other privacy risk assessments for processing activities presenting a high risk to individuals.

22. Children's Data

ConnectorHub's services are intended for business and professional users and are not directed to children under 16. We do not knowingly collect personal data from children under 16 through our website or services.

If we become aware that personal data has been collected from a child in circumstances where such collection is unlawful, we will take appropriate steps to delete the information.

23. Data Protection Officer

24. Related Privacy Documents

For additional information, please review:

  • Privacy Policy — how ConnectorHub collects and uses personal data
  • Data Processing Addendum (DPA) — contractual data-processing commitments for customers
  • Cookie Policy — cookies and tracking technologies
  • Subprocessor List — third-party providers supporting ConnectorHub services
  • Data Retention Policy — retention, deletion, and data export practices
  • Terms of Service — terms governing use of ConnectorHub

25. Updates to This GDPR Page

We may update this GDPR page from time to time to reflect changes to:

  • Applicable privacy laws
  • Regulatory guidance
  • ConnectorHub's products and services
  • Data-processing activities
  • Security practices
  • International transfer mechanisms
  • Privacy rights and procedures

The Effective Date and Last Updated date at the beginning of this page identify the current version.

Where required, we may provide additional notice of material changes.