Our commitment to GDPR
Hubro, operated by Aevo Group Limited, is fully committed to compliance with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. As a platform serving international residents in Ireland, we take data protection extremely seriously.
Our database and infrastructure are hosted in the EU (Frankfurt, Germany) — ensuring your data never leaves the European Economic Area without appropriate safeguards.
Your rights under GDPR
As a user of Hubro, you have the following rights under GDPR. You can exercise any of these rights by contacting us at info@gethubro.app:
📋 Right of Access (Article 15)
Request a copy of all personal data we hold about you. We will respond within 30 days.
✏️ Right to Rectification (Article 16)
Correct any inaccurate or incomplete personal data we hold about you.
🗑️ Right to Erasure (Article 17)
Request deletion of your personal data — the "right to be forgotten". You can also delete your account directly from your profile settings.
📦 Right to Data Portability (Article 20)
Receive your personal data in a structured, machine-readable format (JSON or CSV).
🚫 Right to Object (Article 21)
Object to processing of your personal data based on legitimate interests.
⏸️ Right to Restriction (Article 18)
Restrict how we process your personal data in certain circumstances.
↩️ Right to Withdraw Consent (Article 7)
Withdraw consent for marketing communications at any time by clicking unsubscribe in any email.
How we protect your data
- Encryption in transit — all data is encrypted using HTTPS/TLS
- Encryption at rest — all stored data is encrypted
- Row Level Security — users can only access their own data
- EU hosting — all data stored in Frankfurt, Germany
- Access controls — strict limits on who can access personal data
- Regular security reviews — ongoing assessment of security measures
- Minimal data collection — we only collect what is necessary
Data Processing Agreements
We have Data Processing Agreements (DPAs) in place with all third-party processors:
- Supabase — EU hosting, GDPR compliant DPA
- Stripe — PCI DSS compliant, Standard Contractual Clauses
- Mailchimp — GDPR compliant email processing
- Google — Google Workspace and OAuth, GDPR compliant
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Irish Data Protection Commission (DPC) within 72 hours of becoming aware of the breach.
We will also notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
How to exercise your rights
To exercise any of your GDPR rights, contact our Data Protection contact:
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC):
- Website: dataprotection.ie
- Phone: +353 57 868 4800
- Email: info@dataprotection.ie