AI4Business Privacy Notice
Effective date: 01 September 2026 | Version: 2.0
This Privacy Notice explains how HUB4AI S.R.L. (Hub4AI, we, us or our) handles personal data in connection with AI4Business. It is intended to provide information required by the General Data Protection Regulation (GDPR) and related privacy and electronic-communications laws.
This Notice is informational. It is not a request for blanket consent, and using AI4Business does not by itself create consent for every processing activity described below.
1. Scope
This Notice applies to personal data handled through:
- the AI4Business website and sales or contact forms;
- the AI4Business web portal and customer-specific tenant;
- AI4Business add-ins for supported Microsoft Office applications;
- account, authentication, administration, billing and support functions;
- AI-powered chat, projects, workflows, prompts, templates and generated Outputs;
- optional Connectors and integrations enabled by a Customer or user; and
- service communications, analytics, security and legal-compliance activities.
It does not govern a third-party website, marketplace, identity provider, Connector or business system when that party determines its own purposes and means. Their privacy notices apply to that independent processing.
AI4Business is a business service. A business customer (Customer) decides who may use its tenant and may configure features, permissions, engines and Connectors. An individual user (Authorised User or you) may be an employee, contractor, administrator, prospect, website visitor or other business contact.
2. Who we are and how to contact us
The provider and relevant controller for the independent purposes identified in this Notice is:
HUB4AI S.R.L.
These Terms and Conditions (the Terms) form a legally binding business-to-business agreement between HUB4AI S.R.L., a Romanian limited liability company with its registered office at 4-8 Nicolae Titulescu Ave., America House, West Wing, Bucharest, Romania, registered under number J40/4347/2024, VAT number RO49681347 (Hub4AI, we, us or our), and the organisation identified in the applicable Order (Customer, you or your).
Registered office: 4-8 Nicolae Titulescu Ave., America House, West Wing, Bucharest, Romania
Trade-register number: J40/4347/2024
VAT number: RO49681347
Country of establishment: Romania
General contact: contact@hub4ai.com
Privacy requests: support@hub4ai.com
Data Protection Officer: support@hub4ai.com
Security incidents: support@hub4ai.com
If you use AI4Business through your employer or another Customer, that Customer is usually the first contact for questions about personal data it placed in the Service or decisions it makes using the Service.
3. Our roles: controller and processor
The GDPR role depends on the purpose and facts, not only on labels.
When Hub4AI is controller. We ordinarily determine the purposes and essential means for website operation, prospect and contract-contact management, our business relationship, account administration, billing records, our own security and abuse prevention, support administration, legal compliance, direct marketing and the defined service analytics described below. We are an independent controller for those activities unless a specific arrangement says otherwise and is factually accurate.
When Hub4AI is processor. A Customer generally determines why personal data in prompts, uploads, connected sources, saved chats, workflows and Outputs is processed. When we handle that personal data only to provide the Service on the Customer’s documented instructions, the Customer is controller and Hub4AI is processor. The Customer’s DPA with Hub4AI governs that processing.
Third-party providers. A cloud, AI model or support provider may be our subprocessor where it acts only on our documented instructions. If a provider independently determines a purpose, its role must be assessed separately and its own notice may apply.
The Customer’s responsibilities. The Customer must provide a lawful, transparent notice to its employees, clients and other people whose data it submits; identify its lawful basis and any Article 9 condition; respect their rights; and configure the Service consistently with those duties. Hub4AI assists as required by the DPA.
4. Where personal data comes from
We may receive personal data:
- directly from you when you sign in, use the Service, contact us, submit a form or provide feedback;
- from the Customer or an Administrator who provisions your account, assigns permissions or supplies business contact information;
- from a supported identity provider when you authenticate;
- from a Customer-enabled Connector or Microsoft Office application when you ask the Service to retrieve, analyse or write information;
- automatically from your browser, device, network and interaction with the Service;
- from a marketplace or payment channel for subscription and transaction administration; and
- from professional advisers, authorities or transaction counterparties where necessary for legal compliance or a corporate transaction.
When we obtain personal data indirectly and act as controller, we provide the information required by Article 14 GDPR within the applicable period, unless an exception applies. Where a Customer is controller, the Customer is responsible for its Article 14 notice and we support it under the DPA.
5. Categories of personal data
Depending on how the Service is configured, we may handle:
- Business identity and contact data: name, work email, company, department, job title, business contact details and Customer relationship.
- Account and authentication data: tenant, user identifier, identity provider, login events, roles, groups, permissions and security settings. We do not receive an identity provider password.
- Administrative and billing data: subscription, Usage Credits, limits, feature or engine selected, transaction reference, invoice and tax information, and Administrator actions.
- Customer Materials: prompts, messages, documents, files, images, audio, video, templates, projects, workflows, connected-source information and other content submitted or retrieved on Customer instruction.
- Outputs: generated text, images, audio, video, code, analysis, suggested actions, files and other AI results, which may themselves contain personal data.
- Connector data: provider, permissions, encrypted access and refresh tokens, retrieved content and records created in a connected service on your instruction.
- Usage and diagnostic data: interface or feature used, timestamps, model or provider, token or data volumes, cost and credit use, latency, success/failure, error messages, conversation or project identifiers, and service-health events.
- Device and network data: IP address, browser, operating system, device type, screen resolution, language, page path, referrer and approximate country, region or city derived from network information.
- Security and abuse data: authentication risk, suspicious activity, policy flags, safety-classifier results, reports and information needed to investigate an incident.
- Support and communication data: requests, correspondence, diagnostic information, meeting notes and feedback.
- Marketing preference data: subscriptions, consent records, objections, suppression records and campaign interactions where permitted.
Customer Materials may contain personal data about people who do not have an AI4Business account. Customers and users should submit only data that is relevant and lawful for the task.
6. Data we do not collect, sell or use for training
Hub4AI does not collect or store payment-card details; payments are handled by the relevant marketplace, payment provider or invoice process. We do not sell personal data. We do not use Customer Materials or Outputs to train or fine-tune a shared or general-purpose AI model, and each offered AI provider is contractually prohibited from training on or reselling Customer Materials and Outputs. These commitments do not prevent processing necessary to provide the selected service, comply with law, investigate security or abuse, or use information that has been rendered effectively anonymous.
7. Why we process personal data and our legal bases
The following sections describe the principal processing activities. Where we rely on legitimate interests under Article 6(1)(f) GDPR, the stated interest is subject to a documented necessity and balancing assessment. Where consent is the basis, it may be withdrawn at any time without affecting earlier lawful processing.
| Processing activity | Principal purpose | Role and principal legal basis |
| Website, portal and account security | Deliver requested pages and sessions; authenticate users; protect systems | Hub4AI controller; Article 6(1)(f), and Article 6(1)(b) or (c) where applicable |
| Customer Materials and Outputs | Perform the requested AI, workflow, chat history, Memory box, storage or sharing function | Hub4AI processor on Customer instructions; the Customer determines its lawful basis |
| Gateway routing and metering | Route requests, apply limits, calculate credits, diagnose faults, investigate abuse claims and secure the Service | Processor for Customer content; controller for defined billing, security and legal-compliance purposes under Article 6(1)(f) or (c) |
| Support, billing and contract administration | Respond to requests, administer the B2B relationship, invoice and meet accounting duties | Hub4AI controller; Article 6(1)(b), (c) and/or (f), as applicable |
| Self-hosted service analytics | Understand use and improve first-party interface functionality without cross-site tracking | Hub4AI controller; Article 6(1)(f) |
| Marketing | Respond to enquiries and send permitted business communications | Hub4AI controller; Article 6(1)(b), (f), or consent where required |
8. Website delivery, essential technology and security
Data and source. IP address, device/browser data, requested page, timestamp, security events and strictly necessary cookie or local-storage data, collected from your device and network.
Purpose. Deliver the website and portal, maintain sessions, remember requested settings, protect accounts, prevent attacks and diagnose faults.
Role and legal basis. Hub4AI is controller. The basis is our legitimate interest in providing a secure, functional business service; Article 6(1)(b) may also apply where processing is objectively necessary for a contract directly with the individual; and Article 6(1)(c) applies to specific legal duties.
Is it required? Essential data is required to deliver the requested page or secure account. Without it, the site or Service may not function safely.
9. Account creation, authentication and tenant administration
Data and source. Work email, name, employer, tenant, identity-provider identifier, roles, groups, permissions, credit limits and login/security events, supplied by you, the Customer Administrator and identity provider.
Purpose. Create and authenticate accounts, maintain the Customer tenant, apply permissions, allocate Usage Credits, communicate service information and keep administrative records.
Role and legal basis. Hub4AI is ordinarily controller for basic account and security administration. We rely on Article 6(1)(b) where you personally contract, and otherwise Article 6(1)(f): our and the Customer’s legitimate interests in performing and administering a secure B2B service. The Customer may also be controller for its provisioning decisions.
Is it required? A verified account and assigned permissions are required for authenticated use. If required fields are not provided, we cannot create or maintain access.
10. Customer Materials, saved chats and Outputs
Data and source. Prompts, uploads, connected-source content, generated Outputs and saved project/workflow/Memory Box information, supplied by you or retrieved from a Customer-authorised source.
Purpose. Perform the requested AI or workflow task, return an Output, save the item where you choose a saved feature, and make it available according to selected permissions.
Role and legal basis. Hub4AI ordinarily acts as processor under the DPA. The Customer determines the purpose and lawful basis. We do not adopt Customer Materials for an independent training or advertising purpose.
Access. A private saved chat is intended to be accessible only to its creator through the Service, not to an ordinary Platform Administrator. Resources deliberately shared with a group are visible to that group. Authorised Hub4AI personnel may access content only for Customer-requested support, security/abuse investigation, compliance with a valid legal demand or essential service operation, subject to need-to-know controls and auditability. The Platform Administrator cases can ask Hub4AI the detailed data for a particular user.
Deletion. Deleting a chat from History is intended to delete the platform copy associated with that saved chat, but does not necessarily delete separate Gateway logs, provider safety records, backups or copies exported to another system. The retention section explains those layers.
11. Office add-ins and temporary application processing
Data and source. The active document, spreadsheet, presentation, email or other information you select or authorise through an add-in.
Purpose. Perform the selected function through supported Microsoft APIs. In Outlook, if you do not use a saved chat, retrieved content may be held temporarily in application (RAM) memory and removed when the add-in session closes. In Outlook, the add-in does not copy the email list on the server. At your request, an integration may create an item in Microsoft To Do or another connected system.
Role and legal basis. Hub4AI ordinarily acts as processor on Customer instruction. Microsoft and the Customer may separately be controllers for their environments.
Is it required? Access is optional and scoped to the feature you invoke and permissions granted. Revoking permissions stops future access but does not erase data already saved in the Service or written to the connected system.
12. Connectors and external sources
Data and source. Connector provider, granted scopes, encrypted access/refresh tokens, retrieved records and requested writes, obtained from the provider on your instruction.
Purpose. Authenticate the integration and retrieve, analyse or create records requested by you.
Role and legal basis. Hub4AI ordinarily acts as processor for the connected content. We are controller for limited security and Connector administration data. The Customer’s instruction is not itself a GDPR transfer mechanism; the Customer must ensure a lawful basis, notices and suitable provider/region.
13. AI Gateway routing, metering, reliability and safety
Data and source. User or tenant identifiers, project/prompt/conversation identifiers, provider/engine configuration, timestamps, latency, token volumes, cost, errors, status and safety information. The AI Gateway retains sent prompt text and received Output text for exactly 30 days and then automatically deletes that content.
Purpose. Route a request to the selected engine, balance capacity, enforce limits, calculate Usage Credits and costs, diagnose errors, monitor service quality, respond to abuse reports sent by Customer administrator or by AI engine providers, and meet security/legal duties.
Role and legal basis. For content and Customer-specific processing, Hub4AI generally acts as processor. For its own billing integrity, platform security, fraud/abuse prevention and legal compliance, Hub4AI may act as controller based on Article 6(1)(f) legitimate interests and Article 6(1)(c) legal obligations. The boundary must match the DPA and actual use.
Gateway access. Access to retained Gateway prompt and Output content is limited to Hub4AI’s Chief Executive Officer and Chief Technology Officer. Each access is logged and permitted only for a documented scenario: (1) a Customer specifically requests troubleshooting of its own session; (2) a substantiated security, abuse or AI-provider policy alert requires investigation; (3) Hub4AI must comply with a valid binding legal demand; or (4) a Customer Administrator sends Hub4AI a documented request for content from its own dedicated cluster for a legitimate Customer purpose, including an internal investigation, protection of the Customer’s intellectual property or compliance/e-discovery. Hub4AI acts on that request as processor, verifies the administrator’s authority and applicable scope, and may refuse or limit a request where necessary to protect rights, confidentiality, security or law.
14. Usage analytics and product administration
Data and source. Page path/title/referrer, browser, operating system, device type, screen resolution, language, approximate location, event name/properties, session hash and, if configured, work email. Collected from the Service interaction.
Purpose. Understand adoption and navigation, troubleshoot usability, plan capacity and improve interface functionality.
Role and legal basis. Hub4AI is controller. Service analytics is exclusively self-hosted in the EU, cookie-free and does not use Google Analytics, Microsoft Clarity or cross-site tracking. We rely on Article 6(1)(f): our legitimate interest in proportionate first-party service analytics. If any non-essential cookie, SDK, local-storage access or similar technology is introduced, we will request prior consent where required.
Email, approximate location, device data and a session hash are personal or pseudonymous data; we do not describe them as anonymous.
15. Support and service communications
Data and source. Contact details, request content, correspondence, diagnostic data and account context supplied by you or the Customer.
Purpose. Respond to questions, investigate issues, deliver contracted support, notify users of service/security changes and keep a support record.
Role and legal basis. Hub4AI is controller for support administration and may be processor for Customer Materials included in a ticket. We rely on Article 6(1)(b) where relevant and Article 6(1)(f): our legitimate interest in supporting and improving a B2B service.
16. Billing, marketplace and accounting
Data and source. Customer identity, contract contact, subscription, transaction/reference, invoice/tax data, Usage Credits and Administrator usage information, obtained from the Customer, Service or marketplace.
Purpose. Administer the Order, calculate charges, invoice, reconcile payments, manage marketplace transactions, prevent billing fraud and comply with accounting/tax duties.
Role and legal basis. Hub4AI is controller based on Article 6(1)(b) where the individual is party to the contract, Article 6(1)(f) for B2B administration and fraud prevention, and Article 6(1)(c) for tax/accounting obligations. A marketplace or payment provider may be a separate controller for its transaction.
17. Sales enquiries and direct marketing
Data and source. Business contact details, employer, enquiry, interests, communications and marketing preferences, supplied by you, your organisation or a lawful business source.
Purpose. Respond to enquiries, manage prospects and send relevant product information.
Role and legal basis. Hub4AI is controller. We rely on Article 6(1)(b) for requested pre-contract steps, Article 6(1)(f) for proportionate B2B relationship management, and consent where electronic-marketing law requires it. We use the existing-customer exception only where its conditions are met and always offer a free, easy opt-out.
You may object to direct marketing at any time. We then retain a minimal suppression record so we can honour the objection.
18. Security, legal claims and corporate transactions
Data and source. Relevant account, contract, usage, security, communication and transaction information, obtained from the Service, Customer, advisers or authorities.
Purpose. Protect rights and systems, investigate fraud or misuse, comply with law, respond to lawful authority requests, establish or defend claims, obtain professional advice and conduct a merger, financing, reorganisation or sale subject to confidentiality safeguards.
Role and legal basis. Hub4AI is controller based on Article 6(1)(c) legal obligations and Article 6(1)(f) legitimate interests in security, legal protection and responsible corporate administration.
19. De-identified statistics and product improvement
We may use Usage Data and aggregate statistics to operate, secure, measure and improve the Service. Where information remains personal data, we rely on the specific basis described above and apply purpose limitation, minimisation and access controls. Information is treated as anonymous only after measures make re-identification not reasonably likely, including through extraction or linkage. Anonymous information is no longer personal data under the GDPR.
We do not use Customer Materials or Outputs to train or fine-tune a shared or general-purpose AI model by default or improve the Service. Any opt-in training programme would require separate documentation explaining the data, purpose, legal roles, lawful basis, Article 9 condition where relevant, safeguards and controls.
20. AI processing, model providers and content safeguards
AI4Business routes Customer Inputs to a model selected or permitted by the Customer. The model generates an Output, which may contain or infer personal data. Model providers can also operate automated safety and abuse systems that flag, block or retain certain requests.
We use enterprise or API arrangements under which each offered AI provider is contractually prohibited from training on or reselling Customer Inputs and Outputs. Normal provider retention is typically no more than 30 days, subject to documented safety, legal or stateful-feature exceptions. The AI providers currently offered through the Service are signatories to the applicable AI Code of Practice. The current provider, hosting route, region, purpose, training position, normal retention, safety exception and transfer mechanism are shown in the Service and the register at https://hub4ai.com/Hub4AI_Subprocessor_and_Engine_Register/.
Outputs are probabilistic and may be wrong, biased, outdated or fabricated. Users must verify them. A Customer must not use an Output as the sole basis for a decision with legal or similarly significant effects unless the processing is lawful, an approved feature-specific framework applies, and required human intervention and safeguards are available.
AI4Business will inform users that they are interacting with AI as required by applicable AI Law. Hub4AI and Customers must also meet their respective duties concerning machine-readable marking, deepfake disclosures and public-interest content labels. Those AI Act notices complement, but do not replace, this GDPR transparency.
21. How data moves through AI4Business
The Service may process data at several layers:
- Your device and front end. Data may be held temporarily in application memory. The browser may cache conversation history, generated files, language and interface theme. From version 2.9, cached conversation history and file contents are encrypted on your device. The key is stored on our servers against your user account, sent to your browser after sign-in, and held in memory only for the session. File names, sizes, language and theme are cached without encryption.
- Customer AI4Business tenant. Each Customer has a dedicated single-tenant Microsoft Azure cluster in the European Union. The tenant stores Customer-selected saved chats, files, projects, workflows, prompts, templates, account configuration, group permissions, encrypted Connector credentials and administrative data needed to provide the Service.
- Hub4AI AI Gateway. The Gateway is hosted in the EU and routes AI requests. It retains prompt and Output text for exactly 30 days, then automatically deletes it; it retains metering, reliability, provider/engine and security metadata for the contract term plus four years.
- Selected AI service. Customer Input is processed by the deliberately selected model route. In Auto mode, processing remains entirely in the EU. A non-EU transfer occurs only when an Authorised User deliberately selects an engine labelled USA or Global. Provider retention and location differ by engine, stateful feature and safety exception.
- Service analytics. The self-hosted, cookie-free EU analytics system processes navigation, device and event data for service improvement and does not use Microsoft Clarity or Google Analytics.
- Optional external services. Identity providers, Microsoft Office APIs, marketplaces and Customer-enabled Connectors process data needed for their function and may operate under separate notices.
22. Administrators and other users
Customer Administrators may see provisioned users, work email, groups, permissions, credit limits, feature/engine usage, cost and other tenant-administration information. An ordinary Platform Administrator is not intended to see private chat content through the administrative interface. A Customer Administrator may, however, email Hub4AI to request prompt and Output content sent or received by an Authorised User in that Customer’s dedicated cluster. Hub4AI will disclose only content within the verified Customer’s authority and the documented request, and only for a legitimate Customer purpose such as an internal investigation, protection of Customer intellectual property, compliance or e-discovery. Users should understand that a private-chat interface does not override this Customer-directed disclosure process.
The person who creates a private chat, personal prompt or other private resource ordinarily controls access to it. Workflow templates, team prompts, Word templates, projects and other resources may be shared with groups; group members can then access them according to permissions. Customers must configure groups carefully and tell users about workplace monitoring or administration required by law.
23. Recipients and disclosures
We disclose personal data only where necessary for the described purpose, including to:
- cloud hosting, storage, network and infrastructure providers;
- AI model and inference providers selected or enabled for the Customer;
- authentication, Microsoft Office, marketplace and payment providers;
- security, error-monitoring and support providers;
- our self-hosted analytics environment and any verified service operators;
- Customer-enabled Connector providers and destination systems;
- professional advisers, auditors and insurers under confidentiality duties;
- a prospective buyer, investor or successor under appropriate safeguards; and
- courts, regulators, law enforcement or other authorities when disclosure is legally required or necessary to protect rights and safety.
We do not sell personal data or permit a third-party AI provider to use Customer Materials for targeted advertising. We do not disclose content to a provider merely because it is a listed potential engine; disclosure occurs only through an active route or feature.
The current subprocessor list identifies the actual legal entities and processing locations at https://hub4ai.com/Hub4AI_Subprocessor_and_Engine_Register/ Optional Connectors are listed separately from mandatory sub processors. We give Customers at least 30 days’ prior notice of a new or replacement subprocessor, subject to the DPA’s objection process.
24. Processing locations and international transfers
Each Customer’s AI4Business tenant, Hub4AI AI Gateway and self-hosted service analytics are hosted in a dedicated single-tenant Microsoft Azure cluster in the European Union. The Service labels available AI engines as follows; an Administrator may restrict the permitted catalogue for the Customer tenant.
| Engine label | Processing and data-at-rest position | Current routes |
| Auto | Processing remains entirely in the EU; data at rest remains in the EU | EU Azure, Google Cloud Platform or AWS route selected by Hub4AI |
| (EU) | Processing and data at rest remain in the EU | Azure, Google Cloud Platform, AWS, OpenAI or Anthropic EU route |
| (USA) | Processing and storage are in the United States | Azure, Google Cloud Platform, AWS, OpenAI or Anthropic route |
| (Global) | Provider may process in its global data centres; data at rest is in the United States | Azure, Google Cloud Platform, AWS, OpenAI or Anthropic route |
Personal data leaves the EU only when an Authorised User deliberately selects an engine labelled USA or Global. The user sees that label before routing, and the Customer may limit which labels are available. The label and user choice identify the chosen route; they are not by themselves the legal safeguard for an international transfer.
When personal data is transferred outside the EEA, we use an applicable European Commission adequacy decision where the recipient and transfer are covered. Otherwise we use appropriate safeguards, typically the 2021 EU Standard Contractual Clauses with the correct module, a transfer assessment and supplementary technical, contractual or organisational measures where needed. US Data Privacy Framework reliance applies only after verifying that the specific recipient and data are covered by an active certification.
Remote access from a third country and onward transfers are included in our transfer assessment. A copy or summary of relevant safeguards may be requested at privacy@hub4ai.com subject to lawful redaction of confidential information.
25. Retention and deletion
We retain personal data only for the period needed for the stated purpose, the Customer’s documented instruction and applicable legal duties. The schedule below is the current public summary; Customer data may also be held during an applicable legal hold.
| Data category | Retention period | Notes |
| Customer cluster, saved chats and Customer Materials | Contract term and applicable retrieval/switching period; then permanently deleted within 30 days | A deletion certificate is available on written request. Backups and legal-hold copies are isolated and deleted on their verified cycle. |
| AI Gateway prompt and Output content | Exactly 30 days | Automatically deleted after 30 days. |
| AI Gateway usage, cost, reliability and security metadata | Contract term plus four years | Retained for billing, service integrity, security and legal claims. |
| AI-provider runtime data | Typically no more than 30 days | Safety, legal or stateful-feature exceptions are identified in the engine register. |
| Unsaved add-in session data | Active session only | Removed when the add-in/session closes, subject to documented failure and recovery controls. |
| Connector credentials | Until disconnected, account deletion or contract end | Then deleted from production and backups within 30 days, unless law requires preservation. |
| Self-hosted analytics | Contract term plus four years | Then deleted or rendered effectively anonymous. |
| Support records | Contract term plus 30 days. | Longer only for an active claim or security investigation. |
| Billing, tax and contract records | 5 years from 1 July of the year following the relevant financial year | Retained to comply with Romanian accounting and tax-record retention requirements. Records may be retained longer where necessary to resolve a dispute, comply with another legal obligation, or establish, exercise or defend legal claims. |
| Marketing and suppression records | Until withdrawal/objection and for the needed suppression period | A minimal suppression record is retained to honour the opt-out. |
| Local device data | Until browser/application expiry, clearing or account removal | Users and Customers control their device backups and exports. |
Where deletion from an active system is not immediately possible, data is isolated from ordinary use and deleted on the verified cycle. Anonymous statistics may be retained because they no longer identify a person.
26. Security and access controls
We use technical and organisational measures designed to provide a level of security appropriate to risk. Depending on the component, these include encryption in transit, encryption at rest, dedicated tenant separation, restricted administrative privileges, monitoring, logging, secure development and incident-response procedures. Hub4AI maintains ISO 27001 and ISO 9001 certification within the scope shown in its current certificates. More detail is provided to Customers in the DPA security annex at https://hub4ai.com/AI4Business_Data_Processing_Agreement/.
Connector access and refresh tokens are stored per user in encrypted form. Access to retained Gateway content is limited to the CEO and CTO in the documented Gateway-access scenarios above; every access is logged. Customers are responsible for user provisioning, endpoint security, Microsoft Entra ID configuration, appropriate region/engine choices and secure handling of exports. The DPA contains audit rights and permits Hub4AI to satisfy an audit request by providing current third-party certification and audit evidence where the DPA so provides.
No system can guarantee absolute security. If you suspect an account or data compromise, contact support@hub4ai.com immediately. We will notify Customers, authorities and affected individuals where and as required by applicable law and the DPA.
27. Automated decision-making and profiling
Hub4AI does not currently intend to use personal data to make a solely automated decision about an individual that produces legal effects or similarly significant effects within Article 22 GDPR.
Automated safety filters may block or alter a request, and automated security systems may flag suspicious activity. These actions are intended to protect the Service and generally do not themselves produce a legal or similarly significant effect. A user may request support or human review through support@hub4ai.com.
Platform Administrators may activate the Usage Metadata feature. When activated, a dedicated additional AI processing operation, performed in the EU, analyses usage metadata to generate the usage statistics and indicators displayed in the administrative console. The specific categories of statistics are shown to the Platform Administrator in that console. This feature may consume additional AI credits for each user. The resulting statistics are accessible to Platform Administrators only and are intended to support platform administration and service usage oversight; Hub4AI does not use them to make decisions producing legal effects or similarly significantly affecting individual users.
A Customer may use an Output in its own decision-making. That does not automatically make Hub4AI controller for the Customer’s decision. The Customer must give its own Article 13/14 and, where applicable, Article 22 information and comply with AI Law. Individuals should contact the Customer that made the decision.
28. Cookies, local storage and similar technologies
AI4Business uses strictly necessary cookies or similar storage to maintain Microsoft Entra ID authentication and security, preserve an expressly requested session, remember essential settings and store the encryption key for designated browser cache. From version 2.9, the designated browser cache is encrypted and the related key is stored in a cookie. These technologies are necessary to provide a feature you request and may not be optional.
The exclusively self-hosted service analytics design does not use analytics cookies, Microsoft Clarity or cross-site tracking. It nevertheless processes personal or pseudonymous event data under the legal basis described above.
We will not set or access non-essential analytics, advertising or similar technology before obtaining consent where required. Rejecting must be as accessible as accepting, and withdrawal must be as easy as consent.
The term cookies here includes browser storage for authentication.
29. Your GDPR rights
Subject to conditions and exceptions in law, you may have the right to:
- access your personal data and receive information about its processing;
- rectify inaccurate data and complete incomplete data;
- erase data in qualifying circumstances;
- restrict processing in qualifying circumstances;
- receive or transmit portable data where processing is automated and based on consent or contract;
- object to processing based on legitimate interests, including an absolute right to object to direct marketing;
- withdraw consent at any time where consent is the basis, without affecting earlier processing;
- obtain safeguards relating to qualifying automated decisions, including human intervention, an opportunity to express your view and contest the decision; and
- complain to a supervisory authority.
These rights are not absolute. For example, we may retain data needed to comply with law or establish, exercise or defend legal claims. We will explain a refusal or restriction where required.
30. How to exercise your rights
For personal data in Customer Materials, contact the Customer that provided your account or controls the relevant data. When Hub4AI acts as processor, we will forward or assist with the request as appropriate but ordinarily cannot override the Customer’s lawful instructions.
For processing where Hub4AI is controller, email, support@hub4ai.com and describe your request. We may ask for information reasonably necessary to verify identity and protect other people. An authorised representative may act where applicable authority is demonstrated.
We ordinarily respond within one month. The period may be extended by up to two further months for a complex or numerous request; if so, we will explain the extension within the first month. Requests are generally free, but the GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
You may complain to the supervisory authority where you live or work or where the alleged infringement occurred. If Hub4AI’s main establishment is confirmed in Romania, the Romanian authority is:
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
B-dul General Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania
Website: https://www.dataprotection.ro/
Email: anspdcp@dataprotection.ro
We encourage you to contact us first so we can try to resolve the concern, but you are not required to do so before complaining.
31. Special-category data, criminal data and children
AI4Business is not directed to children and Authorised Users must be at least 18. Customers must not intentionally submit children’s personal data unless a signed Order and DPA expressly approve the use, the use is lawful and appropriate safeguards are implemented.
Customers must not intentionally submit special-category personal data or criminal-conviction/offence data unless the feature and contract expressly permit it. The Customer must identify an Article 9 condition or applicable criminal-data authority, perform any required DPIA and give appropriate notice. Hub4AI’s legitimate interest does not provide the Customer with an Article 9 condition.
If we discover prohibited or unauthorised sensitive data, we may restrict processing, notify the Customer and securely delete or return it in accordance with the DPA and law.
32. Marketing choices and service messages
You can unsubscribe from marketing by using the link in the message or contacting support@hub4ai.com. The objection does not stop essential service, security, billing or legal notices associated with an active account.
We do not use Customer Materials to target advertising. If that practice ever changes, it would require a separate legal and product review, clear prior notice and any required consent.
33. Legal requests and government access
We may preserve or disclose personal data where required by a valid, binding demand from an authority with jurisdiction. We assess the legal basis and scope, seek clarification or challenge disproportionate demands where reasonably available, disclose only what is required and notify the Customer or individual unless prohibited or unsafe.
34. Changes to this Notice
We may update this Notice to reflect changes in law, Service features, providers or practices. We will post the new version with an updated date and keep prior versions at https://hub4ai.com/AI4Business_Privacy_Notice/achive/
For a material change, we will provide a prominent notice through the Service or contract email before it takes effect where practicable. If a change introduces a new purpose incompatible with the original purpose, we will identify a valid legal basis and obtain consent where required. Continued use is not treated as blanket consent.
35. Contact
Questions or requests about this Notice may be sent to:
HUB4AI S.R.L.
Registered office: 4-8 Nicolae Titulescu Ave., America House, West Wing, Bucharest, Romania
Privacy & support email: support@hub4ai.com
General email: contact@hub4ai.com
If your question concerns Customer-controlled content or a workplace decision, please identify the relevant Customer so the request can be directed appropriately.
