Snapshot 51366
Normalized text
Scripts and page chrome removed; this is what change detection compares.
UHUBS POLICY Data Security, Privacy Lifecycle Management & Sub-Processors Policy Last reviewed on 5 August 2026 This document outlines the key aspects of data security and privacy lifecycle management. It covers robust data governance, key data protection processes such as data classification, encryption, and data minimization, documentation and data pipelines, the responsibilities of the Data Protection Officer (DPO), GDPR obligations, types of data stored, data protection impact assessment (DPIA) criteria and framework, and working with sub-processors. 1. Robust Data Governance: 1.1 Established Policies and Procedures: Uhubs maintains a comprehensive set of data governance policies and procedures. These documents cover all aspects of data management, ensuring alignment with applicable laws such as GDPR. Policies are established, documented, approved, communicated, enforced, evaluated, and maintained to meet high standards of data protection. 2. Key Data Protection Processes: 2.1 Data Classification: Use our robust data classification system to categorize data based on sensitivity and importance. This process ensures appropriate protection measures are applied to different data types. 2.2 Encryption and Access Controls: Customer data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. This applies to the primary database, file storage, and backups. Access to production data is restricted to named staff whose role requires it, under the least-privilege model set out in our Identity & Access Management Policy. 2.3 Data Minimization Policy: Adopt a 'data-minimization' policy, storing the minimum amount of personal data necessary for service operation. Utilize techniques such as hashing, anonymization, and pseudo-anonymization to mitigate the impact of potential breaches. 3. Documentation and Data Pipelines: 3.1 Technical Documentation: Maintain internal, technical documentation for all key systems and data pipelines (i.e. in JIRA). Regular updates to this documentation ensure a current and accurate understanding of our data architecture. 4. Data Protection Officer (DPO) Responsibilities: 4.1 Ultimate Responsibility for Data Governance: Uhubs's Data Protection Officer (DPO) holds ultimate responsibility for data governance. The DPO ensures compliance with relevant data protection laws, oversees data protection impact assessments, and acts as a central point for data-related matters. 5. GDPR Obligations: 5.1 Data Retention and User Rights: Under GDPR, Uhubs acknowledges users' rights, including data retention policies. Users can request a copy of their data or request deletion by emailing support@uhubs.co.uk. We commit to prompt and compliant responses to such requests. 6. Types of Data Stored: 6.1 Personal Data Categories: Uhubs stores personal data, including but not limited to names, emails, job titles, performance reviews, manager, and business metrics including but not limited to sales metrics, CRM data, sales activity data, call data, deal data, and calendar data. This data is vital for enhancing the user experience and improving sales team performance. 7. Data Protection Impact Assessment (DPIA) Criteria: 7.1 Uhubs's DPIA Criteria: Our DPIA considers the following criteria: Data Sensitivity: Assessing the sensitivity of the data processed. Volume of Data: Evaluating the scale of data processing activities. Data Sharing: Identifying instances where data is shared with third parties. Data Processing Technology: Assessing the technology used for data processing. Data Security Measures: Evaluating the security measures in place to protect data. Impact on Individuals: Considering the potential impact on individuals' rights and freedoms. 8. DPIA Framework: 8.1 DPIA Process: Uhubs employs a systematic DPIA framework involving: Identification of Processing: Identify and describe the processing activities. Assessment of Necessity and Proportionality: Evaluate the necessity and proportionality of the processing. Risk Assessment: Conduct a risk assessment to identify and mitigate potential risks. Consultation with Stakeholders: Engage with relevant stakeholders during the DPIA process. Documentation: Maintain detailed documentation of the DPIA process and outcomes. Review and Update: Regularly review and update DPIAs in response to changes in processing activities. 9. Working with Sub-Processors: 9.1 Sub-Processor Engagement: Uhubs engages with sub-processors based on principles of transparency, security, and legal compliance. Sub-processors are selected following thorough assessments of their ability to meet our data protection standards. Clear contractual agreements outline responsibilities and compliance requirements for sub-processors. 9.2 Uhubs Sub-Processors Provider # Customers Globally SOC2 ISO27001 Industry Leader Google Cloud 1,100,000+ companies View SOC2 View ISO27001 Yes Supabase 250,000+ companies View SOC2 View ISO27001 Yes Vercel Not published View SOC2 View ISO27001 Yes Anthropic 300,000+ companies View SOC2 View ISO27001 Yes Portkey Not published View SOC2 View ISO27001 Yes Sentry 150,000+ companies View SOC2 View ISO27001 Yes Datadog Not published View SOC2 View ISO27001 Yes PostHog 60,000+ companies View SOC2 Available on Request Yes Amplitude Not published View SOC2 View ISO27001 Yes Intercom (now "Fin") 30,000+ companies View SOC2 View ISO27001 Yes Trigger.dev 30,000+ companies View SOC2 Available on Request No Auth0 19,650+ companies Available on Request Available on Request Yes Customer.io 2,900+ companies Available on Request View Certificate Yes 10. Regular Policy Review and Updates: Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence. No items found.