1. Who this policy covers
This policy explains how APIHUB handles personal data from visitors, workspace users, and people whose account or content is processed through the Service. The APIHUB operator is the controller for its own account, security, support, and billing data. A customer generally remains responsible for the personal data it places in content or connected accounts.
2. Information we process
Depending on enabled features, this may include account and contact details, workspace roles, authentication and API-key metadata, connection identifiers, OAuth permissions and token lifecycle metadata, publishing instructions, media metadata, provider outcomes, webhooks, audit events, support messages, device and security logs, and billing information where billing is enabled. We do not ask you to send provider passwords to APIHUB.
3. Why we process information
We process data to provide and secure the Service, create and manage workspaces, execute your publishing and connection instructions, maintain audit trails, respond to support requests, prevent abuse, meet legal obligations, and improve reliability. Our legal bases can include performance of a contract, legitimate interests in security and service operation, consent where required, and legal obligations.
4. Third-party platforms and processors
When you connect a platform, APIHUB sends only the data and instructions necessary for the permissions you authorize. That platform processes data under its own privacy terms. We may use carefully selected processors for infrastructure, communications, storage, monitoring, payments, and support. Processors may handle data only under our documented instructions and appropriate contractual safeguards.
5. International transfers
A provider or processor may handle data outside the European Economic Area. Where applicable, we use a lawful transfer mechanism, such as an adequacy decision or contractual safeguards, and take supplementary measures where required by law.
6. Retention and deletion
We retain data only for as long as needed for the purposes described here, including security, audit, contractual, and legal obligations. Disconnecting an account stops future authorization where technically possible and initiates the applicable credential revocation or deletion flow. Backups and legally required records may remain for a limited period before deletion.
7. Security
We apply organizational and technical measures appropriate to the Service and its current maturity, including access controls, tenant scoping, request validation, rate limiting, auditability, and provider-specific permission boundaries where implemented. No internet service can guarantee absolute security. Keep your own credentials confidential and report suspected incidents promptly.
8. Your privacy rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing. Where processing relies on consent, you may withdraw it. If you are a customer processing another person's data, you remain responsible for handling their request unless our agreement says otherwise.
9. Cookies and similar technology
APIHUB may use strictly necessary technology to operate the Service, keep a session secure, remember essential settings, and prevent abuse. We do not use advertising cookies in the current application. If optional analytics or marketing technology is introduced, the Service will request any consent required by law before it is activated.
10. Contact and updates
Use the support or privacy contact published in your account, agreement, or the production legal notice to make a privacy request. You may also complain to the competent data protection authority. We may update this policy when our processing or legal requirements change, and will communicate material changes through a reasonable channel.