Third Party Index

Snapshot 44505

Document
Subprocessor list
URL
https://rehnable.com/privacy#subprocessors
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
29405 bytes
SHA-256 (raw)
9094a5f4f01772ee1a7e1c835454b9887cd4117e34cbf60db45f78d1cd19aa5d
SHA-256 (normalized text)
0b2973b29bd320fbc49099fe04d0121a4c19187f6c6171da4438566a5253f1c9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Legal
Privacy Policy
What personal data we handle, in which role, and why the answer for your CRM data is "we read it and never keep it".
Version 1.3 · In force from 3 October 2026.
The short version
We do not store your CRM data. Contacts, companies, deals and activity are read on demand and discarded when you close the chart.
What we store about your organisation is an encrypted access token, your portal's configuration, the HubSpot user ID of the person who installed Rehnable, who holds a seat, and subscription status.
To manage our customer relationship we keep the name and email address of the person who installed Rehnable and of the person who bought the subscription, with your HubSpot account's name and our licence status for it, in our own HubSpot CRM (EU data centre). Nothing from your CRM goes there.
Our systems run in the EU (Azure, Sweden Central). Billing runs through Stripe.
This website sets no cookies, runs no analytics and loads nothing from a third party.
We do not sell personal data, and we do not use your data to train AI models.
1. Who is responsible
Legal entity	Lucas Rehn (sole trader, enskild firma), trading as Rehnable
Organisation number	199905287398
VAT number	SE990528739801
Address	Hagarydsvägen 41, 586 63 Linköping, Sweden
Privacy contact	hello@rehnable.com
We act in two different roles, and the distinction matters for your rights:
As controller for the personal data we handle to run our own business — the people who contact us, administrators of customer accounts, and billing contacts. Sections 2–8 cover this.
As processor for the personal data in your HubSpot account that Rehnable reads and writes on your instruction. You are the controller of that data. Section 9 and the processing terms cover this.
2. What we process as controller
Category	Data	Source
Contact and correspondence	Name, email address, company, and the content of what you write to us	You, by emailing us
Account administration	HubSpot portal ID, the HubSpot user ID of the person who installed Rehnable, HubSpot user IDs of seat holders, and the name and email address shown for those users when an administrator assigns seats	Your HubSpot account, via the API
Customer relationship	Name, email address and HubSpot user ID of the person who installed Rehnable and of the person who bought the subscription; your HubSpot account's name and domain; and our licence status for it — install status, trial end, plan, seats in use and the subscription's value. Kept in our own HubSpot CRM, not in our application database	Your HubSpot account's user directory and account details, via the API, and our own billing records
Billing	Billing contact, company details, VAT number, subscription status and invoice history. Card details are handled by Stripe and never reach us	You, through Stripe checkout
Technical logs	Request metadata, timestamps, error information, portal ID. Logs do not contain CRM record content	Generated when the service runs
3. Why, and on what legal basis
Purpose	Legal basis (GDPR Art. 6)
Providing the service, authenticating users, managing seats	Performance of a contract (Art. 6.1 b), or our legitimate interest in serving our business customer (Art. 6.1 f)
Support and correspondence	Legitimate interest in answering the people who contact us (Art. 6.1 f)
Managing our customer relationship — knowing who installed and who bought, so that we can support, inform and invoice our customers	Performance of a contract (Art. 6.1 b) and our legitimate interest in managing that customer relationship (Art. 6.1 f)
Billing and payment	Performance of a contract (Art. 6.1 b) and legal obligation (Art. 6.1 c)
Accounting records	Legal obligation — Swedish Bookkeeping Act (Art. 6.1 c)
Security, error diagnosis, abuse prevention	Legitimate interest in a secure and functioning service (Art. 6.1 f)
Service announcements to administrators	Legitimate interest in informing customers of changes that affect them (Art. 6.1 f)
We do not use your data for advertising, we do not profile you, and we do not make automated decisions with legal effect about anyone.
4. What we never store
This list is part of the architecture, not a policy promise that could quietly change — the application has no database table for any of it:
Contact records, names or email addresses from your CRM
Company records and their properties
Deals, amounts, stages or forecasts
Emails, calls, meetings or any activity content
The org chart structure itself — it lives in your HubSpot account as associations
Team assignments — they live on your contacts as a property
Payment card details
If our database were fully compromised, an attacker would learn which HubSpot accounts use Rehnable, which user installed it, and which user IDs hold seats. They would not obtain your customers' records.
5. Recipients and subprocessors
Provider	Purpose	Location
Microsoft Azure (Microsoft Ireland Operations Ltd)	Hosting of the application, database and encryption keys	Sweden Central, EU
Stripe	Payment processing and subscription management	EU/US, under the safeguards described below
For the data in your HubSpot account, HubSpot is not our subprocessor: it is your provider under your contract, and Rehnable accesses your account with the authorisation you grant at installation.
For our own records, HubSpot is our processor for one thing only: the customer-relationship records described in section 2, kept in Rehnable's own HubSpot account. We are the controller of those records; HubSpot processes them on our behalf under its data processing agreement, in its EU data centre. Nothing from your CRM is copied into ours.
Otherwise we disclose personal data only where required by law, or to professional advisers under a duty of confidentiality. We do not sell personal data, and we do not use it to train AI models.
6. Transfers outside the EU/EEA
Our own infrastructure is in the EU. Payment processing through Stripe may involve processing outside the EU/EEA; where it does, transfers rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR. No CRM data is transferred to Stripe under any circumstances — Stripe receives billing data only. Our customer-relationship records are hosted in HubSpot's EU data centre; where HubSpot processes them outside the EU/EEA, transfers rely on the mechanisms in HubSpot's data processing agreement.
7. How long we keep things
CRM data	Not retained at all — read on demand, held in the browser while the chart is open
Access token for your account	Deleted when we see the uninstall in HubSpot's app-lifecycle journal, normally within about a minute; if that check fails, at the next refusal to renew the credential instead
Portal configuration, seats and the installer's user ID	While you are installed, and afterwards so a reinstall works — deleted on request
Customer-relationship records in our HubSpot CRM	While you are installed or subscribed, and deleted 24 months after you uninstall or your subscription ends, whichever is later
Correspondence	Up to 24 months after the last message, unless it is part of a contractual record
Accounting records	Seven years, as required by the Swedish Bookkeeping Act
Technical logs	Short-lived operational retention, normally under 90 days
8. Security
Access tokens are encrypted at rest (AES-GCM) with keys held in Azure Key Vault, and are never sent to the browser.
All traffic runs over TLS.
Authentication is delegated to HubSpot: the editor session starts from a request HubSpot itself signed, validated on our servers.
Access to production systems is limited to the personnel who operate the service, which at present means one person.
We do not hold ISO 27001 or SOC 2 certification, and we say so rather than implying otherwise. The primary control is architectural: the sensitive data never arrives.
Report a suspected vulnerability to hello@rehnable.com. We will confirm receipt, work the issue, and tell you what we did.
9. Cookies and tracking
This website sets no cookies, runs no analytics, embeds no fonts, scripts or images from third parties, and does not track you across sites. There is no consent banner because there is nothing to consent to.
The application itself uses two strictly necessary mechanisms, and nothing else:
a short-lived cookie during the installation flow, to protect that flow against cross-site request forgery;
a session token that authenticates your editor session while it is open.
10. Your rights
Where we are the controller, you may request access to your personal data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Contact hello@rehnable.com and we will respond within one month.
If your data is in a customer's HubSpot account — for example if you are a contact belonging to a company that uses Rehnable — that company is the controller. Direct your request to them; we will assist them, but we cannot act on their data without their instruction, and we hold no copy of it.
You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, or with the supervisory authority in your own country.
11. Data processing terms (GDPR Article 28)
These terms apply where we process personal data on behalf of a customer, and form part of the terms of service. A separate signable data processing agreement with the same content is available on request.
11.1 Subject matter and duration
Processing consists of reading personal data from the customer's HubSpot account to render an org chart, and writing changes to that account when a user of the customer performs an action. Processing lasts for as long as Rehnable is installed.
11.2 Nature, purpose and scope
Reading, structuring and displaying contact, company and deal data; writing associations, property values, lists and tasks. No storage of customer personal data takes place on the processor's systems. Data is retrieved for a request, delivered to the authorised user's browser, and not persisted.
11.3 Categories of data subjects and data
Data subjects: the customer's business contacts, and the customer's own users. Data: name, job title, business email and phone as present in the customer's CRM, buying role, activity timestamps, deal associations, deal names and stages, reporting relationships, team assignment, and HubSpot user identifiers. The customer determines what its CRM contains and must not use Rehnable to process special categories of personal data (Art. 9).
11.4 Instructions
We process personal data only on the customer's documented instructions, of which these terms and the customer's use of the application are the instruction, unless required otherwise by EU or member state law — in which case we inform the customer before processing, unless that law forbids it. We will inform the customer if we consider an instruction to infringe data protection law.
11.5 Confidentiality
Personnel authorised to process personal data are bound by confidentiality and are limited to those who need access to operate the service.
11.6 Security
We implement appropriate technical and organisational measures under Article 32, including encryption of stored credentials, TLS in transit, signed-request authentication, least-privilege API permissions, and — most significantly — an architecture that does not persist customer personal data.
11.7 Subprocessors
The customer gives general authorisation for the subprocessors listed in section 5. We will give at least 30 days' notice before adding or replacing a subprocessor, during which the customer may object on reasonable data protection grounds; if the objection cannot be resolved, the customer may terminate the affected service without penalty. We impose data protection obligations on each subprocessor equivalent to those in these terms and remain liable for their performance.
11.8 Assistance
Taking into account the nature of the processing, we assist the customer with data subject requests, with security, breach notification and impact assessments under Articles 32–36. In practice, because we hold no copy of the customer's data, requests are fulfilled by the customer inside HubSpot.
11.9 Personal data breach
We notify the customer without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds. Notification goes to the account administrators and to any security contact the customer has given us.
11.10 Deletion and return
On termination we delete the customer's stored access token. Since no customer personal data is stored, there is nothing further to return or delete; portal configuration is deleted on request. The customer's own data remains in the customer's HubSpot account, under the customer's control.
11.11 Audit
We make available the information necessary to demonstrate compliance with Article 28, and we allow for and contribute to audits conducted by the customer or an auditor it mandates.
In the first instance an audit is satisfied by documentation: written answers to a security questionnaire, a description of the measures in place, and the information on our security page. Where the customer can reasonably show that this is not sufficient to demonstrate compliance, an inspection may be conducted — on at least 30 days' written notice, no more than once a year unless a personal data breach or a supervisory authority requires otherwise, during normal working hours, without disrupting the service, and subject to confidentiality. The customer bears its own costs for an inspection.
12. Changes to this policy
We may update this policy. Material changes are notified by email to account administrators or in the application at least 30 days in advance. The version and date at the top of this page identify what is in force.
13. Contact
hello@rehnable.com — privacy questions, data subject requests, DPA requests and security reports all reach the same place, and a person reads them.