Legal
Data Processing Agreement
The agreement that governs how Huble processes personal data on behalf of customers (GDPR-compliant). Available on all paid plans.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Devntech LLC ("Huble", "Processor", "we", "us") and the customer ("Customer", "Controller", "you") that uses the Huble time tracking, project management, and invoicing service (the "Service"). It reflects the parties' agreement on the processing of personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Where you use the Service to process personal data of your team members or other individuals, you act as the Controller and Huble acts as the Processor. Terms not defined here have the meaning given in the Terms of Service.
1. Scope and roles
You determine the purposes and means of processing personal data through the Service and are the Controller. Huble processes personal data on your documented instructions as the Processor. Your use of the Service, together with your configuration and instructions given through it, constitutes your documented instructions.
2. Nature and purpose of processing
Huble processes personal data to provide, maintain, secure, and support the Service. This includes hosting and storing data, tracking time and activity that you enable, managing projects and tasks, generating invoices and reports, and providing account and support functions.
3. Categories of data and data subjects
Personal data processed may include account and profile data (such as name and email), workspace and usage data (such as time entries, project metadata, and activity capture you enable), and technical data (such as browser, operating system, and error diagnostics). Data subjects may include your team members, contractors, and other users you invite to your workspace.
4. Duration
Huble processes personal data for the duration of the Service and until data is deleted or returned in accordance with the Terms of Service and this DPA.
5. Processor obligations
Huble will:
- Process personal data only on your documented instructions, including for international transfers, unless required to do otherwise by law, in which case we will inform you unless the law prohibits it.
- Ensure that persons authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational security measures as described in Section 7.
- Respect the conditions in Section 6 for engaging sub-processors.
- Assist you, taking into account the nature of processing, in responding to requests from data subjects exercising their rights.
- Assist you in ensuring compliance with your obligations relating to security, breach notification, data protection impact assessments, and consultation with supervisory authorities, taking into account the information available to us.
- At your choice, delete or return personal data at the end of the Service, and delete existing copies unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and allow for and contribute to audits as described in Section 8.
6. Sub-processors
You provide general authorization for Huble to engage sub-processors to process personal data. Our current sub-processors are listed at https://gethuble.com/legal/sub-processors.
Huble will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for the performance of each sub-processor's obligations. We will update the sub-processors page before engaging a new sub-processor that processes customer personal data, and you may object on reasonable grounds relating to data protection by contacting us at support@gethuble.com
7. Security
Huble implements appropriate technical and organizational measures to protect personal data, including encryption of data in transit, access controls, tenant isolation, secure hosting, and regular review of our security practices. We take steps to ensure that anyone acting under our authority who has access to personal data processes it only on your instructions.
8. Audits
Huble will make available information reasonably necessary to demonstrate compliance with this DPA. Where you reasonably require further information, you may request an audit, subject to reasonable notice, confidentiality, and frequency limits, and conducted in a manner that does not disrupt the Service or compromise the data of other customers.
9. Personal data breach
Huble will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and will provide information reasonably available to us to help you meet your notification obligations.
10. International transfers
Where personal data is transferred to a country outside the European Economic Area that is not subject to an adequacy decision, the parties will rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable. Our hosting infrastructure is located in the United States, as described on our sub-processors page.
11. Deletion and return
On termination of the Service, Huble will make customer data available for export for a limited period, then delete or anonymize personal data, unless retention is required by law.
12. General
This DPA is incorporated into and subject to the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA governs. This DPA is governed by the same law as the Terms of Service.
For questions about this DPA, you may contact us at: support@gethuble.com