UHUBS POLICY

Data Security, Privacy Lifecycle Management & Sub-Processors Policy

Last reviewed on 30 October 2025
This document outlines the key aspects of data security and privacy lifecycle management. It covers robust data governance, key data protection processes such as data classification, encryption, and data minimization, documentation and data pipelines, the responsibilities of the Data Protection Officer (DPO), GDPR obligations, types of data stored, data protection impact assessment (DPIA) criteria and framework, and working with sub-processors.

1. Robust Data Governance:

1.1 Established Policies and Procedures:

Uhubs maintains a comprehensive set of data governance policies and procedures. These documents cover all aspects of data management, ensuring alignment with applicable laws such as GDPR. Policies are established, documented, approved, communicated, enforced, evaluated, and maintained to meet high standards of data protection.

2. Key Data Protection Processes:

2.1 Data Classification:

Use our robust data classification system to categorize data based on sensitivity and importance. This process ensures appropriate protection measures are applied to different data types.

2.2 Encryption and Access Controls:

Prioritize encryption for sensitive data and enforce strict access controls. This ensures confidentiality and limits access to authorized personnel.

2.3 Data Minimization Policy:

Adopt a 'data-minimization' policy, storing the minimum amount of personal data necessary for service operation. Utilize techniques such as hashing, anonymization, and pseudo-anonymization to mitigate the impact of potential breaches.

3. Documentation and Data Pipelines:

3.1 Technical Documentation:

Maintain internal, technical documentation for all key systems and data pipelines (i.e. in JIRA). Regular updates to this documentation ensure a current and accurate understanding of our data architecture.

4. Data Protection Officer (DPO) Responsibilities:

4.1 Ultimate Responsibility for Data Governance:

Uhubs's Data Protection Officer (DPO) holds ultimate responsibility for data governance. The DPO ensures compliance with relevant data protection laws, oversees data protection impact assessments, and acts as a central point for data-related matters.

5. GDPR Obligations:

5.1 Data Retention and User Rights:

Under GDPR, Uhubs acknowledges users' rights, including data retention policies. Users can request a copy of their data or request deletion by emailing support@uhubs.co.uk. We commit to prompt and compliant responses to such requests.

6. Types of Data Stored:

6.1 Personal Data Categories:

Uhubs stores personal data, including but not limited to names, emails, job titles, performance reviews, manager, and business metrics including but not limited to sales metrics, CRM data, sales activity data, call data, deal data, and calendar data. This data is vital for enhancing the user experience and improving sales team performance.

7. Data Protection Impact Assessment (DPIA) Criteria:

7.1 Uhubs's DPIA Criteria:

Our DPIA considers the following criteria:

  • Data Sensitivity: Assessing the sensitivity of the data processed.
  • Volume of Data: Evaluating the scale of data processing activities.
  • Data Sharing: Identifying instances where data is shared with third parties.
  • Data Processing Technology: Assessing the technology used for data processing.
  • Data Security Measures: Evaluating the security measures in place to protect data.
  • Impact on Individuals: Considering the potential impact on individuals' rights and freedoms.

8. DPIA Framework:

8.1 DPIA Process:

Uhubs employs a systematic DPIA framework involving:

  • Identification of Processing: Identify and describe the processing activities.
  • Assessment of Necessity and Proportionality: Evaluate the necessity and proportionality of the processing.
  • Risk Assessment: Conduct a risk assessment to identify and mitigate potential risks.
  • Consultation with Stakeholders: Engage with relevant stakeholders during the DPIA process.
  • Documentation: Maintain detailed documentation of the DPIA process and outcomes.
  • Review and Update: Regularly review and update DPIAs in response to changes in processing activities.

9. Working with Sub-Processors:

9.1 Sub-Processor Engagement:

Uhubs engages with sub-processors based on principles of transparency, security, and legal compliance. Sub-processors are selected following thorough assessments of their ability to meet our data protection standards. Clear contractual agreements outline responsibilities and compliance requirements for sub-processors.

9.2 Uhubs Sub-Processors

Provider# Customers GloballySOC2ISO27001Industry Leader
Google Cloud500,000+ companiesView SOC2View ISO27001Yes
Postgres80,000+ companiesRelated Email ThreadRelated Email ThreadYes
AirTable25,000+ companiesCertificationCertificationYes
CustomerIO7,600+ companiesAvailable on RequestAvailable on RequestYes
Auth09,000+ companiesAvailable on RequestAvailable on RequestYes
Zapier10,000+ companiesAvailable on RequestAvailable on RequestYes
Typeform125,000+ companiesCertificationCertificationYes
Amplitude7,500+ companiesSecurity ReportSecurity ReportYes
Tableau (Owned by Salesforce)75,000+ companiesSOC2 Report

Email Support
ISO27001Yes
Fivetran5,000+ companiesAvailable to ClientsAvailable to ClientsYes


10. Regular Policy Review and Updates:

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

No items found.