ConnectorHub is committed to protecting personal data and complying with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
This page explains how ConnectorHub approaches GDPR compliance, how we protect personal data, the rights available to individuals in the European Economic Area (EEA), and the responsibilities of organizations that use ConnectorHub to process personal data.
This page should be read together with our Privacy Policy, Data Processing Addendum (DPA), Cookie Policy, and applicable Terms of Service.
ConnectorHub is designed to support secure, controlled, and transparent processing of business and operational data.
Our GDPR approach is based on the core principles of data protection, including:
We apply appropriate technical and organizational measures to protect personal data and maintain appropriate controls throughout the data lifecycle.
ConnectorHub does not sell personal data.
When we process data on behalf of customers using our platform (e.g., workflow logs, connector metadata, integration execution details).
The GDPR may apply to ConnectorHub when:
Where GDPR applies, ConnectorHub processes personal data in accordance with applicable GDPR requirements.
ConnectorHub may act as either a data controller or a data processor, depending on the circumstances.
ConnectorHub generally acts as a controller when we determine why and how personal data is processed for our own business purposes.
Examples include:
In these circumstances, ConnectorHub determines the purposes and means of processing.
ConnectorHub may act as a processor when customers use our platform to process personal data through integrations, workflows, synchronization, automation, or other customer-configured functionality.
In these circumstances:
Where ConnectorHub acts as a processor, the customer remains responsible for establishing an appropriate legal basis for processing personal data and providing required privacy notices to individuals.
For customers subject to GDPR, ConnectorHub provides contractual data protection commitments through its Data Processing Addendum (DPA).
The DPA addresses matters including:
Where required, ConnectorHub enters appropriate data processing terms with customers before processing personal data on their behalf.
Depending on how ConnectorHub is used, personal data may include:
Where customers configure integrations, ConnectorHub may process data transmitted between connected systems.
The types of personal data contained within such information are determined by the customer and the connected systems.
Where GDPR applies, ConnectorHub processes personal data using one or more lawful bases under Article 6 GDPR.
We may process personal data where processing is necessary to:
We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the individual's rights and freedoms.
Examples may include:
Where required, we may rely on consent for activities such as:
Individuals may withdraw consent at any time.
Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
We may process personal data where necessary to comply with legal, regulatory, accounting, tax, security, or law enforcement obligations.
ConnectorHub follows data minimization and purpose limitation principles.
We seek to process only the personal data reasonably necessary for a defined and legitimate purpose.
We do not intentionally access customer data payloads unless access is:
Customer-configured integrations determine what information is transmitted between connected systems.
ConnectorHub implements technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, destruction, or unlawful processing.
ConnectorHub's security practices are designed to support enterprise requirements for confidentiality, integrity, availability, and accountability.
ConnectorHub may engage third-party service providers to support the delivery and operation of its services.
These providers may support:
Where ConnectorHub acts as a processor, subprocessors are engaged subject to applicable contractual and data protection requirements.
ConnectorHub requires subprocessors to maintain appropriate safeguards for personal data.
ConnectorHub may process or transfer personal data outside the EEA.
Where GDPR restricts an international transfer, ConnectorHub uses an appropriate transfer mechanism recognized under applicable law.
Depending on the circumstances, these mechanisms may include:
The European Commission recognizes Standard Contractual Clauses as an appropriate mechanism for certain transfers of personal data from the EEA to third countries.
Where required, ConnectorHub evaluates international transfer risks and implements appropriate supplementary technical, contractual, and organizational safeguards.
ConnectorHub retains personal data only for as long as necessary for the applicable processing purpose, unless a longer retention period is required or permitted by law.
Retention periods may depend on:
When personal data is no longer required, ConnectorHub will delete, anonymize, or securely dispose of it in accordance with applicable retention procedures.
For customer data processed as a processor, deletion and return requirements are generally governed by the applicable DPA and customer instructions.
Individuals whose personal data is subject to GDPR may have the following rights.
You may request confirmation of whether we process your personal data and request access to that information.
You may request correction of inaccurate or incomplete personal data.
You may request deletion of your personal data in circumstances provided by GDPR.
This right is subject to applicable exceptions, including where retention is necessary to comply with a legal obligation or establish, exercise, or defend legal claims.
You may request restriction of processing in circumstances provided by GDPR.
Where applicable, you may request personal data you provided to us in a structured, commonly used, and machine-readable format.
You may object to certain processing based on legitimate interests or other applicable legal grounds.
You may object to direct marketing at any time.
Where processing is based on consent, you may withdraw your consent at any time.
Where applicable, GDPR provides rights relating to decisions based solely on automated processing, including profiling, where such processing produces legal or similarly significant effects.
ConnectorHub does not intend to make decisions concerning individuals based solely on automated processing that produce legal or similarly significant effects.
To submit a GDPR request, contact:
Privacy Contact: security@connectorhub.ai
Please include:
We may request additional information where reasonably necessary to verify your identity and protect personal data against unauthorized disclosure.
We generally respond to valid GDPR requests without undue delay and, in principle, within one month of receiving the request.
Where permitted by GDPR, this period may be extended by up to two additional months where necessary because of the complexity or number of requests.
We will inform you where an extension applies.
You have the right to lodge a complaint with a competent data protection supervisory authority if you believe that our processing of your personal data violates applicable data protection law.
You may generally contact the supervisory authority in the country where you:
You are not required to contact ConnectorHub before exercising this right.
However, we encourage individuals to contact us first so that we can investigate and attempt to resolve privacy concerns.
The European Commission provides guidance on exercising GDPR rights and contacting data protection authorities.
ConnectorHub does not intentionally request special-category personal data for general website or marketing activities.
Special categories under GDPR include information concerning:
However, customers may configure integrations that transmit information containing special categories of personal data.
Where ConnectorHub acts as a processor, such processing is performed according to the customer's instructions and applicable contractual requirements.
Customers are responsible for ensuring that they have an appropriate legal basis and, where required, an additional condition under Article 9 GDPR for processing special-category data.
ConnectorHub may use automation, analytics, and AI-assisted functionality to support product functionality, workflow configuration, mapping, security, service improvement, and operational processes.
ConnectorHub does not intend to use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
Where such processing is introduced in the future and GDPR requirements apply, ConnectorHub will provide appropriate information and implement applicable safeguards and individual rights.
Where applicable, individuals may have the right to:
ConnectorHub may send marketing communications where permitted by applicable law.
These may include:
You may opt out of marketing communications at any time.
Each marketing email will provide an unsubscribe mechanism where required.
You may also contact our privacy team to request that your personal data no longer be used for direct marketing.
Withdrawal from marketing communications does not affect essential service, security, transactional, or account-related communications.
ConnectorHub may receive personal data from third-party sources, where permitted by applicable law.
These sources may include:
Where required under GDPR, ConnectorHub will provide appropriate information concerning the source of personal data and the purposes and legal basis for processing.
ConnectorHub maintains procedures designed to identify, assess, contain, investigate, and respond to personal data breaches.
Where ConnectorHub acts as a processor, we will notify affected customers of qualifying personal data breaches in accordance with the applicable DPA and GDPR requirements.
Where ConnectorHub acts as a controller, we will assess notification obligations and notify the relevant supervisory authority and affected individuals where required by applicable law.
ConnectorHub incorporates privacy and security considerations into its product and operational processes.
Where appropriate, we apply:
Where required by GDPR, ConnectorHub may conduct Data Protection Impact Assessments (DPIAs) or other privacy risk assessments for processing activities presenting a high risk to individuals.
ConnectorHub's services are intended for business and professional users and are not directed to children under 16. We do not knowingly collect personal data from children under 16 through our website or services.
If we become aware that personal data has been collected from a child in circumstances where such collection is unlawful, we will take appropriate steps to delete the information.
We may update this GDPR page from time to time to reflect changes to:
The Effective Date and Last Updated date at the beginning of this page identify the current version.
Where required, we may provide additional notice of material changes.