01Who is responsible
The controller for Huberway’s own business-contact, website and administrative processing is Huberway LLC, a Wyoming limited liability company, with its registered office at 1309 Coffeen Avenue, Suite 1200, Sheridan, WY 82801, United States; EIN 35-2903558.
For privacy questions or rights requests, email hello@huberway.com with “Privacy request” in the subject, or write to the registered office. This notice covers the Huberway corporate website, this legal portal, account administration and service relationships across Huberway LLC platforms. The product schedules describe additional processing and distinguish customer-controlled records and independent merchant sales: https://legal.huberway.com/product-schedules. An independent merchant or customer must supply its own controller notice for the processing it determines.
When a customer uploads its own end-customer, workforce, supplier or prospect information and directs its use, that customer normally determines the purpose and Huberway acts on its behalf under a data processing agreement. This notice does not turn customer-controlled data into data Huberway may use for any purpose.
02Information and sources
Information supplied by users includes names, business roles, work contacts, account and organisation details, correspondence, billing details and support material. Do not send passwords, complete card details or unnecessary sensitive data through ordinary enquiries.
Serving and securing a page involves IP address, request time, resource, browser and server/security records. On www.huberway.com the Huberway Analytics pixel is loaded only after an analytics choice. The legal portal has no analytics or advertising pixel. Optional browser measurement is distinct from server request logs.
Depending on the enabled service, entrusted data includes CRM contacts and communications, ERP products/stock/orders, documents and files, calendar/meeting records, prompts and outputs, integration records and website visitor events. Replay or visitor identification requires its specific configuration and notice; an analytics choice does not itself authorise identifying an individual or sending marketing.
Data may come from an employer, authorised integration, a referring person or a business research source. Expandigo can collect business information from public or licensed sources. Personal contact data remains personal data: source, date, reliability and usage rights matter. The controller providing data must meet applicable indirect-notice duties, including GDPR Article 14 where applicable.
03Purposes and lawful grounds
Where the GDPR or equivalent rules apply, the legal ground depends on the processing and relationship. For an individual professional who is party to an agreement, processing necessary to respond to a request or supply the service may be based on contractual necessity. For employees acting for a corporate customer, the usual ground for ordinary business correspondence is our legitimate interest in managing that relationship, subject to their rights.
- Business enquiries and service administration: respond to requests, prepare orders and manage the commercial relationship; contractual necessity where applicable or legitimate interests in ordinary B2B administration.
- Security and reliability: deliver pages, investigate abuse and protect accounts and systems; legitimate interests in secure operation and applicable legal duties.
- Billing and compliance: process agreed charges, maintain accounting records and meet applicable legal obligations; contract, relevant legal duties or legitimate interests as appropriate.
- Support and claims: resolve issues, preserve evidence and establish, exercise or defend legal claims; contractual necessity or legitimate interests subject to applicable law.
- Marketing: send business communications only where permitted, relying on consent when required or another lawful basis where legally available. You may object or unsubscribe without losing unrelated service access.
- Optional tracking: where installed, use only under the applicable notice and consent requirements. Continuing to browse does not itself grant consent.
04Recipients and service providers
Information is disclosed only to people and organisations relevant to the applicable purpose, which may include authorised Huberway personnel, hosting and security providers, communication and support providers, payment and accounting providers, professional advisers and authorised integration providers. A provider processing on our behalf must be subject to appropriate contractual and security obligations. Some providers, such as a payment provider for its own regulatory functions, may act independently.
The actual supplier list, processing countries, purposes and relevant contractual roles must be documented for each deployed service and made available where required before that processing begins. The categories listed here are not a named subprocessor register and do not imply that every category is used by every product.
Information may be disclosed in response to a valid legal obligation, to protect lawful rights or in connection with a genuine business reorganisation, subject to applicable safeguards and notice duties. A transaction does not automatically authorise materially incompatible uses of information.
05AI and business context
Enabled AI functions process the selected prompt and permitted business context to generate suggestions or assist a workflow. The applicable service arrangement must identify provider, data sent, processing countries, retention and transfer safeguards. A logo or available adapter does not establish that a provider receives your data.
These terms grant no permission to train general models on entrusted customer data. Retrieval context and stored interaction history are separate processing purposes. Any training arrangement requires separate explicit agreement and an appropriate legal basis; a customer instruction cannot waive another person’s rights. See https://legal.huberway.com/ai-policy.
AI output requires human evaluation proportionate to its consequences. This notice does not authorise solely automated decisions with legal or similarly significant effects. Profiling, sensitive data and high-risk intended uses require their applicable assessments and safeguards before activation.
06International processing
Huberway is established in the United States. Its registered address does not by itself identify where a particular service stores data or backups. Access by personnel or providers in another country can also be an international transfer.
For data subject to transfer restrictions, a valid mechanism must be in place before a restricted transfer occurs. Depending on the destination and recipient, this may involve an applicable adequacy decision or approved contractual clauses with completed annexes, transfer assessment and supplementary measures where required. Any UK-specific requirements must be addressed separately.
We do not claim that Huberway is certified under the EU–US Data Privacy Framework or that an unverified provider qualifies under an adequacy mechanism. Ask hello@huberway.com for the destinations and safeguards applicable to the service you use and for an available copy or description of the relevant safeguards.
07Retention and deletion
Retention is tied to purpose and applicable law. Enquiries are retained while a response or continuing business relationship requires them; account records while needed to operate and secure the account; support records while resolving the issue and relevant claims; financial records for applicable tax/accounting periods; security records for detection, investigation and evidence. Longer legal holds must identify their basis and restrict further use.
Customer-controlled service data follows the return/deletion instructions and the applicable processing agreement. Expiry or cancellation does not mean immediate erasure of every backup. Backup cycles, restoration handling and any legal hold must be identified for the deployment. A browser reset does not erase server records. Contact hello@huberway.com for the service-specific retention criteria and your rights request.
Privacy-choice storage expires in the application after 180 days on the corporate site. Product-specific configurable retention does not prove that a job has run or every copy has been deleted. The version archive retains published legal text, rather than customer prompts or contact databases.
08Your choices and rights
Depending on applicable law and processing, you may request access, correction, erasure, restriction and portability, object to legitimate-interest processing and withdraw consent. Objection to direct marketing is available at any time; withdrawal does not affect previous lawful processing.
Contact hello@huberway.com with the service and request. Verification must be proportionate. For data controlled by a customer, that customer addresses the request and Huberway assists as processor. Do not attach a full identity document unless a secure, proportionate verification procedure actually requires it.
Where GDPR applies, a response is generally due within one month. A permitted extension of up to two further months requires reasons and notice during the first month. You may complain to a competent supervisory authority, including the authority where you live or work, the Italian Garante or the UK ICO where applicable. Other laws can provide additional deadlines, exceptions and appeals.
US state privacy rights and opt-outs for sale, sharing, targeted advertising and certain profiling depend on the applicable law and activity. A paid supply of personal business-contact information can require separate analysis from a processor service; this notice does not make an enterprise-wide no-sale claim or certify data-broker registration. Contact hello@huberway.com to exercise applicable rights.
09Security and sensitive information
We must apply safeguards appropriate to the nature and risks of the processing and the commitments in the relevant agreement. Access restrictions, secure transmission and incident handling must be implemented and maintained according to the actual service design. No internet service can promise absolute security, and no certification or independent audit is asserted here.
Our services are marketed to businesses and professionals, not to children. Do not provide children’s information or regulated sensitive data through general enquiries. A business customer’s status does not remove the privacy rights of individuals whose information it supplies.
10Notice changes and related documents
Material changes require an updated version and appropriate notice. If a new purpose requires consent or another legal ground, publishing a new notice alone does not provide it. The version date records the current revision; it does not retroactively validate past processing.
The Cookie Policy describes browser storage. The Terms and Conditions address the B2B relationship and the data-processing schedule. Product-specific notices and accepted processing agreements describe additional deployment details. Contact hello@huberway.com if you need the documents relevant to a particular configuration.
11Named providers
OVHcloud — hosting/infrastructure supplier; Stripe — payment services where enabled; OpenAI — model services for enabled AI requests. The provider brands identify confirmed suppliers, not every contracting legal entity, region or product entitlement. The relevant order and provider account determine the actual entity and configuration.
For supplier disclosures see https://www.ovhcloud.com/en/terms-and-conditions/, https://stripe.com/legal/privacy-center and https://openai.com/policies/data-processing-addendum/. These public provider documents do not themselves prove Huberway’s signed agreement, selected processing region, backup location or special retention setting. A customer-selected integration is assessed separately.