Privacy & Trust Center

Privacy Policy

Learn how Hublink360 Limited collects, utilizes, protects, and respects your personal information across our websites, mobile applications, CRM extensions, and cloud APIs.

Effective Date: October 1, 2026
Last Updated: October 1, 2026
UK ICO Registration: ZC191432

Our Core Privacy Commitment

HubLink 360 (operated by Hublink360 Limited) maintains an uncompromising standard of data protection, transparency, and user privacy. We are officially registered with the UK Information Commissioner's Office (ICO Ref: ZC191432) and adhere to the UK Data Protection Act 2018, Apple App Store Review Guidelines, and Google API Services User Data Policies. We do not sell, rent, or trade personal data to third parties.

01Introduction & Corporate Identity

This Privacy Policy describes the policies and procedures of Hublink360 Limited (trading as "HubLink 360", "we", "us", or "our") regarding the collection, storage, processing, and disclosure of personal data when you interact with our websites (including https://hublink360.com), our mobile applications (iOS and Android), our custom CRM plugins (HubSpot, Salesforce, Shopify), and our proprietary conversational automation platforms (including the AtNimo engine).

Hublink360 Limited is an incorporated entity in the United Kingdom, headquartered in London, and duly registered as a Data Controller with the UK Information Commissioner's Office (ICO) under registration reference ZC191432.

By installing our applications, accessing our websites, subscribing to our services, or connecting your CRM and messaging platforms to HubLink 360, you consent to the data practices described in this policy.

02 Information We Collect

Depending on whether you visit our public website, utilize our mobile applications, configure integrations, or engage our custom software engineering services, we collect information across the following categories:

Personal & Account Data

Full name, corporate email address, telephone number, job title, company name, physical billing address, and encrypted account credentials.

Communications & Messaging

Customer message payloads, broadcast templates, support tickets, conversation metadata, contact tags, and webhook logs routed through your connected accounts.

Device, Mobile & Telemetry

IP address, device model, operating system version, browser user agent, mobile device identifiers (IDFV/Android ID), diagnostic crash logs, and session timestamps.

We adhere strictly to the principle of data minimization: we collect only personal data that is strictly required to fulfill our contractual commitments, ensure infrastructure security, and provide reliable technical support.

03 How We Collect Your Data

We gather data through three primary mechanisms:

  • Direct Submissions: Information you voluntarily provide when creating an account, booking an architectural discovery call, submitting a contact form, requesting customer support, or configuring messaging credentials.
  • Automated Technologies: As you navigate our site or mobile apps, technical telemetry, cookie identifiers, and performance metrics are automatically recorded to ensure service stability and performance optimization.
  • Third-Party Integrations & APIs: When you connect CRM suites (such as HubSpot or Salesforce), messaging networks (such as WhatsApp Business API, Telegram, or Instagram), or developer tools, authorized OAuth tokens and event webhooks are securely exchanged to execute synchronization.

04Purposes of Processing & Legal Bases (UK DPA 2018)

Under the UK Data Protection Act 2018 and statutory privacy legislation, every instance of personal data processing must be grounded upon an established lawful basis:

  • Contractual Performance (Article 6(1)(b)): To provision software workspaces, route real-time customer messages, deliver engineering milestones, process recurring subscriptions, and render customer service.
  • Legitimate Interests (Article 6(1)(f)): To safeguard infrastructure integrity, prevent fraud, protect against unauthorized system access, benchmark service uptime, and improve our software architecture—where these interests are not overridden by your fundamental rights.
  • Compliance with Legal Obligations (Article 6(1)(c)): To maintain statutory financial records, satisfy UK HMRC tax reporting requirements, comply with telecommunications regulations, and respond to valid statutory requests.
  • Explicit Consent (Article 6(1)(a)): Where you provide opt-in consent for optional product newsletters, webinars, or non-essential analytics tracking. You retain the right to revoke consent at any moment without penalty.

05Stripe & Payment Processing Disclosure

HubLink 360 utilizes Stripe, Inc. as our primary merchant payment processor for all software subscriptions, engineering retainers, and platform invoices.

PCI-DSS Level 1 Compliance & Zero Card Storage

We do not store, process, or transmit raw credit card or debit card numbers on our servers. All payment transactions are conducted directly via Stripe’s tokenized, PCI-DSS Level 1 certified payment infrastructure. Stripe processes your payment data in accordance with the Stripe Privacy Policy.

We retain only non-sensitive transactional metadata, including Stripe customer identifiers, invoice numbers, payment dates, currency (GBP / USD), tax amounts, and the last 4 digits of your payment card for billing management and accounting audits.

06Mobile Applications & App Store Disclosures

In accordance with the Apple App Store Review Guidelines (Section 5.1) and the Google Play Developer Distribution Agreement & Data Safety Standards, we provide transparent disclosures regarding our mobile applications:

  • Device Permissions: Our mobile apps may request permissions strictly necessary to execute their features, such as Push Notifications (to notify you of inbound customer messages) and Camera/Photos (only when you explicitly choose to attach a document or media asset to a customer conversation). We never access your photo library or camera in the background.
  • No Third-Party Advertising Trackers: Our mobile applications do not contain third-party ad-tracking SDKs (such as Facebook Pixel or ad broker SDKs) and do not track users across apps and websites owned by other companies for targeted advertising.
  • Contacts Access: If an application feature allows importing contacts for CRM cleansing or synchronization, contacts are accessed only after explicit runtime user authorization and are transmitted over encrypted TLS channels solely to your designated CRM workspace.
  • Crash Reporting & Diagnostics: Anonymized diagnostic logs (e.g., stack traces, operating system versions) may be collected to identify and resolve software errors.

07Google API User Data Policy & Limited Use

When you choose to connect Google Workspace, Google Calendar, or other Google services to HubLink 360 applications or plugins, our integration strictly complies with the Google API Services User Data Policy, including the Limited Use requirements:

  • Affirmation of Limited Use:HubLink 360's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • No Advertising Use: Google user data accessed via Google APIs is never used to serve, target, or evaluate advertisements.
  • No Sale of Google User Data: We never sell, transfer, or license data obtained through Google APIs to third-party data brokers, advertising platforms, or information aggregators.
  • No AI Training Without Consent: We do not use Google user data to train, retrain, or improve generalized machine learning or artificial intelligence models without your affirmative, explicit consent.
  • Human Access Restrictions: No human employees are permitted to read Google user data unless you have provided explicit permission for troubleshooting, it is strictly necessary for security investigations, or required by applicable law.

08Omnichannel & CRM Integrations

HubLink 360 bridges customer communications across WhatsApp (Meta Cloud API), Telegram, Instagram, HubSpot, Salesforce, and custom endpoints. When using these integrations:

  • You act as the Data Controllerfor your customers' personal information, and HubLink 360 acts as the Data Processor.
  • You represent and warrant that you have obtained all necessary prior opt-in consents from your end customers before dispatching outbound communications, in full compliance with telecommunications laws, Meta WhatsApp Business Terms, and anti-spam legislation.
  • All conversational payloads transmitted across external networks are encrypted in transit using industry-standard TLS 1.3 cryptographic protocols.

09Third-Party Sharing & Subprocessors

We never sell, rent, or monetize your personal information. We share data only with vetted, high-security infrastructure subprocessors strictly required to operate our platform, under binding contractual obligations:

  • Cloud Hosting & Server Infrastructure: Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). All primary web applications, compute clusters, and databases reside in ISO 27001-certified German / EU data centers, governed by an executed Data Processing Agreement (DPA) incorporating rigorous Technical and Organizational Measures (TOMs) for physical access control, cryptographic isolation, and system resilience.
  • Edge Routing & DDoS Mitigation: Cloudflare, Inc. for global Anycast DNS resolution, SSL/TLS cryptographic termination, and network-level DDoS defense.
  • Email Delivery & System Alerts: Brevo (Sendinblue SAS, Paris, France — EU Data Centers) for transactional messaging, system notifications, verification emails, and authorized client communications in full accordance with high European and international data protection standards.
  • Discovery & Consultation Booking: Calendly LLC for scheduling technical architecture discovery calls and project scoping appointments.
  • Payment Processing & Billing: Stripe, Inc. for secure subscription billing, merchant invoicing, and PCI-DSS Level 1 compliant card transaction handling.
  • Messaging & Omnichannel APIs: Meta Platforms Ireland Ltd. for official WhatsApp Business Cloud API conversational connectivity.
  • Legal & Regulatory Authorities: We may disclose data if legally compelled by a valid court order, warrant, or binding statutory mandate issued by competent UK courts or law enforcement authorities.

Every subprocessor is bound by signed Data Processing Agreements (DPAs) ensuring data confidentiality, strict security controls, and adherence to UK ICO data protection standards.

10Data Protection & Cryptographic Security

We implement defense-in-depth security architecture to safeguard your personal data against unauthorized access, accidental loss, alteration, or disclosure:

TLS 1.3 Encryption in Transit

All data transmitted between browsers, mobile devices, external APIs, and HubLink 360 servers is encrypted with modern 256-bit TLS 1.3 cryptographic suites.

AES-256 Encryption at Rest

Database records, encrypted access credentials, OAuth tokens, and platform backups are secured utilizing enterprise-grade AES-256 hardware encryption.

Role-Based Access Control (RBAC)

Access to production systems is restricted strictly to authorized senior engineers requiring access to fulfill job duties, secured with mandatory Multi-Factor Authentication (MFA).

11Account Deletion & Right to be Forgotten

In compliance with Apple App Store Guideline 5.1.1(v), Google Play Data Safety, and the UK Data Protection Act 2018, users have the absolute right to delete their account and request permanent erasure of their personal information:

How to Delete Your Account and Data

In-App Deletion: You can initiate account deletion at any time within your mobile app or platform dashboard by navigating to Settings > Account > Delete Account.

Direct Request: Alternatively, you can submit an account and data erasure request by emailing our Data Protection Officer at [email protected] or [email protected] with the subject line "Account Deletion Request".

Upon receiving a verified deletion request, we will permanently purge or irreversibly anonymize your account profile, credentials, customer contact records, and stored messages from our active production databases within thirty (30) days. Encrypted disaster recovery backups are systematically overwritten in accordance with our standard 30-day backup cycle. We retain only records strictly required to comply with statutory UK accounting and legal obligations.

12 Your Data Protection Rights

Under the UK Data Protection Act 2018 and our registration with the UK ICO (Ref: ZC191432), you have the following enforceable rights:

Right of Access

Request copies of the personal data we hold about you and receive information regarding our processing activities.

Right to Rectification

Request the immediate correction of inaccurate or incomplete personal records in your account profile.

Right to Erasure

Request permanent deletion of your data when it is no longer necessary for the original purposes of collection.

Right to Restrict / Object

Request restriction of processing or object to processing conducted on the basis of legitimate interests.

Data Portability

Receive your data in a structured, commonly used, and machine-readable format (JSON or CSV) for transfer to another service.

Lodge an ICO Complaint

You have the right to lodge a formal complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

To exercise any of these rights, contact us at [email protected]. We respond to all verified statutory requests within one calendar month at zero charge.

13Cookies & Tracking Technologies

Our websites use cookies—small text files placed on your device—to deliver essential site features and measure performance:

  • Strictly Necessary Cookies: Essential for site navigation, user authentication, and security validation. These cannot be disabled.
  • Functional Cookies: Remember your workspace settings, language preferences, and currency selections.
  • Performance & Analytics Cookies: Aggregate, anonymized traffic measurements used to diagnose page speed, identify broken links, and optimize user experience.

You can configure your browser to reject all or some browser cookies. Please note that disabling cookies may affect the usability of authenticated dashboard features.

14 International Data Transfers

HubLink 360 primarily hosts customer data within secure cloud data centers located in the United Kingdom and the European Economic Area (EEA). When data is transferred to subprocessors outside the UK or EEA, we ensure an equivalent level of protection through:

  • UK International Data Transfer Agreements (IDTA) and European Commission Standard Contractual Clauses (SCCs).
  • Transfers to countries recognized as having an Adequacy Decision by the UK Secretary of State and European Commission.
  • End-to-end cryptographic safeguards ensuring data in transit cannot be intercepted or read by intermediaries.

15Children's Privacy Notice

Our services, mobile applications, and software platforms are intended strictly for enterprise, business, and commercial use by individuals aged 18 years or older. We do not knowingly collect, solicit, or market to children under the age of 13 (or under 16 in the UK/EU).

If we become aware that we have inadvertently collected personal data from a child without verified parental consent, we will take immediate steps to permanently delete that information from our records. If you believe a minor has provided us with personal information, please notify us immediately at [email protected].

16Policy Updates & Notifications

We may update this Privacy Policy periodically to reflect technological advancements, product evolutions, or statutory changes. When material changes occur, we will update the "Last Updated" date at the top of this document and notify active account holders via email or dashboard announcements prior to the changes taking effect.

We encourage you to review this page periodically to remain informed about our data protection practices.

17Contact & DPO Inquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or our data governance practices, please reach out to our Data Protection Office:

Hublink360 Limited Data Protection Office

Committed to enterprise data security, user transparency, and rigorous regulatory compliance.

Data Protection Officer[email protected]
General & Support[email protected]
Telephone Support+44 7741398352
Corporate Headquarters58 Inks Green, London E4 9EL, UK
UK ICO RegistrationRef: ZC191432