GDPR Compliance #
Effective Date: July 2026
Version: 1.0
1. Purpose #
This document explains how XAR Hub complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Our objective is to process personal data lawfully, fairly and transparently while protecting the rights and freedoms of individuals.
2. Scope #
This policy applies to:
- Users located in the European Union.
- Businesses using XAR Hub within the European Economic Area (EEA).
- Any processing activities subject to the GDPR.
Where local privacy laws provide greater protection, those laws will also apply.
3. Data Controller #
Unless otherwise specified, XAR Hub acts as the Data Controller for personal information collected through its platform. Where customers process personal data through XAR Hub for their own purposes, they may act as the Data Controller while XAR Hub acts as a Data Processor.
4. GDPR Principles #
XAR Hub processes personal data according to the following principles:
- Lawfulness, fairness and transparency.
- Purpose limitation.
- Data minimization.
- Accuracy.
- Storage limitation.
- Integrity and confidentiality.
- Accountability.
These principles guide every feature of the platform.
5. Lawful Bases for Processing #
Personal data is processed only where a lawful basis exists, including:
- Performance of a contract.
- User consent.
- Compliance with legal obligations.
- Legitimate interests.
- Protection of vital interests where applicable.
6. Categories of Personal Data #
Depending on platform usage, we may process:
Identity Data #
- Name
- Username
- Email Address
Business Data #
- Company Name
- Business Address
- Contact Information
- Website
- Social Media Links
Technical Data #
- IP Address
- Browser Information
- Device Information
- Operating System
- Session Logs
Usage Data #
- Login History
- Dashboard Activity
- Feature Usage
- Published Projects
- Error Reports
7. Data Minimization #
We collect only information necessary to:
- Operate the platform.
- Authenticate users.
- Provide requested services.
- Maintain security.
- Improve functionality.
We avoid collecting unnecessary personal information.
8. Data Accuracy #
Users may review and update their information through their account settings. We encourage users to keep personal information accurate and up to date.
9. Data Retention #
Personal data is retained only for as long as necessary to:
- Provide services.
- Meet legal obligations.
- Resolve disputes.
- Protect legal rights.
Data is securely deleted or anonymized when no longer required.
10. International Transfers #
Because XAR Hub operates globally, personal data may be transferred outside the European Economic Area. Where required, appropriate safeguards are implemented, including:
- Standard Contractual Clauses (SCCs).
- Adequacy Decisions.
- Other lawful transfer mechanisms recognized under the GDPR.
11. Data Security #
XAR Hub implements appropriate technical and organizational measures, including:
- HTTPS/TLS encryption.
- Password hashing.
- Role-based access controls.
- Secure cloud infrastructure.
- Continuous monitoring.
- Security logging.
- Regular software updates.
- Backup procedures.
Security measures are reviewed regularly.
12. Data Subject Rights #
Users may exercise the following rights where applicable:
Right of Access #
Request a copy of personal information.
Right to Rectification #
Correct inaccurate or incomplete information.
Right to Erasure #
Request deletion of personal data.
Right to Restrict Processing #
Request temporary restriction of processing.
Right to Data Portability #
Receive personal data in a structured, commonly used and machine-readable format.
Right to Object #
Object to processing based on legitimate interests.
Right to Withdraw Consent #
Withdraw previously given consent at any time.
Right to Lodge a Complaint #
Submit a complaint to the competent supervisory authority.
13. Automated Decision-Making #
XAR Hub does not make legally significant decisions based solely on automated processing unless explicitly disclosed and permitted by law.
14. Privacy by Design #
Privacy considerations are integrated into the development lifecycle. Every new feature is designed with:
- Minimal data collection.
- Secure defaults.
- Appropriate access controls.
- Risk assessment.
- Privacy review where necessary.
15. Privacy by Default #
Default settings are configured to maximize user privacy whenever reasonably possible. Users remain in control of optional data sharing.
16. Data Breach Response #
If a personal data breach occurs, XAR Hub will:
- Investigate the incident.
- Mitigate the impact.
- Notify affected users where legally required.
- Notify supervisory authorities within applicable legal deadlines.
- Document the incident and corrective actions.
17. Third-Party Processors #
XAR Hub works only with trusted service providers that implement appropriate security and privacy measures. Where required, Data Processing Agreements are executed with processors.
18. Children's Data #
XAR Hub is not intended for children where processing would violate applicable law. Where required, parental or guardian consent must be obtained.
19. Accountability #
XAR Hub maintains internal procedures to demonstrate compliance with GDPR requirements. Documentation may include:
- Processing records.
- Security procedures.
- Risk assessments.
- Vendor reviews.
- Policy documentation.
20. Changes #
This document may be updated to reflect:
- Regulatory developments.
- Platform improvements.
- Operational changes.
- Security enhancements.
The latest version will always be published on the XAR Hub website.
21. Contact #
Questions regarding GDPR or personal data may be submitted using the official contact information published by XAR Hub.
Related Documents #
This document should be read together with:
Conclusion #
Protecting personal data is a core principle of XAR Hub. We are committed to operating transparently, securely and in accordance with the GDPR and other applicable privacy laws.
End of Document