Privacy Policy - Hubflo

Home/Privacy Policy

At Hubflo, the protection of your personal data is a priority.

Use of Google User Data: Hubflo uses Google user data to provide an integrated email and calendar experience. Specifically: We use Gmail scopes to allow users to read, compose, send, and organize their emails directly from Hubflo. We use Calendar scopes to sync, create, and modify events to help users manage their schedule. We do not use this data for advertising, and we do not sell it to third parties.

When you use the https://www.hubflo.com/ and https://www.app.hubflo.com website (hereinafter the "website"), we may collect personal data about you.

The purpose of this policy is to inform you about the ways in which we process this data in compliance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR").

Who is the data controller?

The data controller is Hubflo, SAS, registered in the Paris Trade and Companies Register under number 909 078 263 and whose registered office is located at 49 rue de Ponthieu 75008 PARIS (hereinafter "We"), when you browse our Site or in the context of managing our contractual relations.

On the other hand, when our customers use our services, we collect and process personal data on their behalf and for their account. Our customers are therefore data controllers in accordance with Article 4 of the GDPR. We act as a processor, as a service provider.

What data do we collect?

Personal data is data that identifies an individual directly or by cross-referencing with other data.

We collect data that falls into the following categories:

  • Identification data (last name, first name, email address, phone number);
  • Data relating to your company (company name, SIRET number, position held);
  • Browsing data (e.g. IP address, pages viewed, date and time of connection, browser used, operating system, user ID, IFA);
  • Economic and financial data (data relating to your bank cards, data necessary for invoicing);
  • Any information that you wish to send us as part of your contact request.

For data collected specifically through Inbox by Hubflo, please refer to the dedicated section below.

Mandatory data are indicated when you provide us with your data. They are indicated by an asterisk and are necessary to provide you with our services.

On what legal grounds, for what purposes and for how long do we keep your personal data?

Carrying out operations relating to the management of our customers concerning contracts, orders, invoices and follow-up of the contractual relationship with our customers.

Execution of the contract that you or your company have signed with us.

Personal data are kept for the duration of the contractual relationship.

Inbox by Hubflo

Inbox by Hubflo is an AI-powered email and calendar management product. This section describes how we collect, store, process, and protect your data when you use Inbox by Hubflo. If you do not use Inbox by Hubflo, this section does not apply to you.

Data collected

When you connect your email account (Gmail or Outlook) to Inbox by Hubflo, we collect and store:

  • Email data: subject lines, email body text, sender and recipient information, attachments, headers, metadata, thread identifiers, labels, and read/unread status.
  • Calendar data: event titles, descriptions, dates, times, participant information, location, and recurrence rules.

We sync and store a complete copy of this data on our servers, encrypted at rest using AES-256 and protected in transit using TLS 1.2 or higher. We store this data to enable faster loading and a seamless user experience.

AI processing

Inbox by Hubflo uses artificial intelligence to provide the following features:

  • Auto-labeling: Automatic categorization and labeling of incoming emails.
  • Auto-draft responses: AI-generated draft replies for your review. The AI never sends an email on your behalf - you always review and confirm before sending.
  • Auto-task creation: Automatic creation of tasks within Hubflo based on email content.
  • Auto-reschedule (calendar): Automatic rescheduling of calendar events based on AI analysis. This feature operates autonomously and may modify your calendar events without manual confirmation. It is opt-in and can be disabled at any time from your dashboard.

To deliver these features, email and calendar data may be shared with our AI service providers: OpenAI and Google. We maintain zero data retention agreements with both providers, meaning your data is not stored on their servers after processing. Neither provider uses your data to train their AI models. Your data is never used by these providers for any purpose other than delivering the features described above, including advertising.

Consent and control

You consent to AI processing when you connect your email account to Inbox by Hubflo. You retain full control and can disable some or all AI features at any time from your dashboard.

When you disable all AI features, we immediately stop sending your data to our AI service providers. Your stored email and calendar data remains on our servers for the non-AI functionality of the product but is no longer transmitted to any third-party AI provider.

Data retention

Email and calendar data is retained for a maximum of one (1) year from the date it was synced to our servers. Data older than one year is automatically purged.

Upon account deletion, all stored email and calendar data is permanently purged from our production systems within thirty (30) days. This grace period exists solely to allow for technical cleanup of backup systems.

We never use your email or calendar data to train any machine learning or AI model, whether our own or those of any third party.

Microsoft Outlook

If you connect your Microsoft Outlook account, the same data handling, AI processing, storage, retention, and security practices described in this section apply. Hubflo's use of Microsoft data complies with the Microsoft APIs Terms of Use.

Additional Limitations on the Use of Your Gmail User Data

If you provide Hubflo access to your Google data, Hubflo's use of that data will be subject to these additional restrictions:

  • Hubflo will only use access to read, write, modify or control Gmail message bodies (including attachments), metadata, headers, and settings to provide a web email client that allows users to compose, send, read and process emails and will not transfer this Gmail data to others unless doing so is necessary to provide and improve these features, comply with applicable law, or as part of a merger, acquisition, or sale of assets.
  • Hubflo will not use this Gmail data for serving advertisements.
  • Hubflo will not allow humans to read this data unless we have your affirmative agreement for specific messages, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or for Hubflo's internal operations and even then only when the data have been aggregated and anonymized.
  • Hubflo's use of information received, and Hubflo's transfer of information to any other app, from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Services User Data Policy (Limited Use)

Hubflo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. To protect your sensitive data, we implement the following specific restrictions:

  • Purpose Limitation: We only access your Gmail and Google Calendar data to provide and improve our AI inbox and calendar features (composing, sending, reading, organizing emails, and managing calendar events).
  • No Advertising: Your Google data is never used for serving advertisements or for any marketing purposes.
  • Data Minimization: We only request the minimum permissions necessary to provide the service.
  • Human Access Restriction: Our staff does not have access to your Gmail or calendar data unless you provide explicit consent for a specific support request, or if it is strictly necessary for security investigations or to comply with applicable law. In such cases, data is accessed following the principle of least privilege.
  • Technical Protection: All Google user data is encrypted at rest using industry-standard AES-256 encryption and is protected during transit using TLS 1.2 or higher.

Security of Your Data

We implement robust technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption: All sensitive data, including OAuth tokens, email content, and calendar data, is encrypted at rest using AES-256 and in transit using Secure Socket Layer (SSL/TLS) technology.
  • Access Control: We use strict identity and access management (IAM) policies. Only authorized personnel can access our production environment.
  • Infrastructure: Our services are hosted on Heroku (Salesforce) and AWS, which maintain world-class security certifications (SOC 2, ISO 27001).
  • Monitoring: We perform regular security audits and monitoring to detect and prevent unauthorized access.
  • Breach Notification: We have procedures in place to deal with any suspected personal data breach. In the event of a breach affecting your personal data, we will notify you and any applicable supervisory authority without undue delay and in accordance with applicable law.

Who are the recipients of your data?

Will have access to your personal data:

  • Our company staff;
  • Our AI service providers: OpenAI and Google (for Inbox by Hubflo AI features only, under zero data retention agreements);
  • Our subcontractors: hosting provider, newsletter provider, audience measurement and analysis provider, personalized advertising provider, email provider, secure payment provider, accounting provider, data consolidation provider, integration management provider, electronic signature provider, document management provider, customer service provider;
  • Where applicable: public and private bodies, exclusively to meet our legal obligations.

Is your data likely to be transferred outside the European Union?

Your data is kept and stored for the duration of the processing on Heroku and AWS servers located in Europe.

In the context of the tools we use (see article on the recipients concerning our subcontractors), your data may be transferred outside the European Union. In particular, data processed by our AI providers (OpenAI and Google) as part of Inbox by Hubflo may be transferred to servers located in the United States.

The transfer of your data in this context is secured by means of the following tools:

  • Either the data is transferred to a country that has been the subject of an adequacy decision by the European Commission, in accordance with Article 45 of the GDPR: in this case, this country ensures a level of protection deemed sufficient and adequate to the provisions of the GDPR;
  • Or the data is transferred to a country whose level of data protection has not been recognized as adequate to the GDPR: in this case these transfers are based on appropriate safeguards indicated in Article 46 of the GDPR, adapted to each provider, including but not limited to the conclusion of standard contractual clauses approved by the European Commission, the application of binding corporate rules or under an approved certification mechanism;
  • Or the data is transferred on the basis of one of the appropriate safeguards described in Chapter V of the GDPR.

What are your rights to your data?

You have the following rights with respect to your personal data:

  • Right to information: this is precisely the reason why we have drafted this policy. This right is provided for in Articles 13 and 14 of the GDPR.
  • Right of access: you have the right to access all your personal data at any time, in accordance with Article 15 of the GDPR.
  • Right of rectification: you have the right to rectify your inaccurate, incomplete or obsolete personal data at any time pursuant to Article 16 of the GDPR.
  • Right to limitation: you have the right to obtain the limitation of the processing of your personal data in certain cases defined in Article 18 of the GDPR.
  • Right to erasure: you have the right to demand that your personal data be erased, and to prohibit any future collection of your personal data on the grounds set out in Article 17 of the GDPR. For Inbox by Hubflo users, all stored email and calendar data will be permanently purged from our production systems within thirty (30) days of your request.
  • Right to lodge a complaint: with a competent supervisory authority (in France, the CNIL), if you consider that the processing of your personal data constitutes a violation of the applicable texts (Article 77 of the GDPR).
  • Right to define directives: regarding the retention, deletion and communication of your personal data after your death.
  • Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the GDPR provides that you may withdraw your consent at any time. Such withdrawal will not affect the lawfulness of the processing carried out before the withdrawal. For Inbox by Hubflo, you may withdraw consent to AI processing at any time by disabling AI features from your dashboard or by disconnecting your email account.
  • Right to portability: under certain conditions specified in Article 20 of the GDPR, you have the right to receive the personal data you have provided to us in a standard machine-readable format and to require its transfer to the recipient of your choice.
  • Right to object: under Article 21 of the GDPR, you have the right to object to the processing of your personal data. Please note, however, that we may continue to process your personal data despite this objection, for legitimate reasons or to defend legal rights.

You can exercise these rights by writing to us at the address below. We may ask you to provide us with additional information or documents to prove your identity.

What cookies do we use?

To learn more about how we manage cookies, please see our Cookie Policy.

Contact point for personal data

Contact email: data@hubflo.com

Contact address: 49 rue de Ponthieu 75008 PARIS

Changes

We may modify this policy at any time, in particular to comply with any regulatory, legal, editorial or technical developments.

These modifications will apply on the date the modified version comes into force. You are therefore invited to regularly consult the latest version of this policy.

Nevertheless, we will keep you informed of any significant changes to this Privacy Policy.

Effective date: 02/01/2026