Legal and Trust

OneHub Data Processing Addendum (DPA)

This Data Processing Addendum ("DPA") forms part of the agreement between OneHub ("Processor," "we," "our," or "us") and the customer ("Controller," "you," or "your") governing the use of OneHub's services.

This DPA applies where OneHub processes Personal Data on behalf of the Controller and is intended to satisfy the requirements of applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar privacy laws.

Last updated: July 20, 2026

Definitions

Controller means the entity that determines the purposes and means of processing Personal Data.

Processor means OneHub when processing Personal Data on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person.

Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

Scope

This DPA applies whenever OneHub processes Personal Data solely to provide the Services requested by the Controller.

Where the customer uses third-party AI providers or integrations, those providers may act as independent controllers or processors under their own terms.

Nature of Processing

Processing may include:

  • storing account information
  • processing authentication requests
  • processing support requests
  • transmitting prompts to AI providers selected by the customer
  • processing files intentionally submitted by the customer

providing software licensing and updates.

OneHub does not intentionally process customer content for purposes unrelated to providing the Services unless expressly authorized.

Categories of Data

Depending on how the Services are used, Personal Data may include:

  • names
  • email addresses
  • account identifiers
  • billing information
  • support communications
  • uploaded documents
  • prompts
  • files submitted by the customer

technical device information.

Categories of Data Subjects

Personal Data may relate to:

  • customers
  • employees
  • contractors
  • end users
  • business contacts

other individuals whose information the customer chooses to process through the Services.

Customer Responsibilities

The Controller is responsible for:

  • ensuring it has a lawful basis for processing Personal Data
  • providing required privacy notices
  • obtaining any necessary consents

ensuring the legality of information submitted to OneHub.

OneHub Responsibilities

OneHub agrees to:

  • process Personal Data only on documented instructions from the Controller, except where otherwise required by law
  • implement appropriate technical and organizational security measures
  • ensure personnel handling Personal Data are subject to confidentiality obligations
  • assist the Controller, where reasonably possible, in responding to data subject requests

notify the Controller without undue delay if legally required following a confirmed Personal Data breach affecting data under OneHub's control.

Security Measures

OneHub maintains reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, and destruction.

Security measures are described in the OneHub Security Policy and may be updated over time.

Subprocessors

OneHub may engage trusted third-party subprocessors to provide portions of the Services, including hosting, authentication, payment processing, customer support, analytics, and AI infrastructure.

Current subprocessors may include, depending on customer configuration:

  • Vercel
  • Clerk
  • Stripe
  • PayPal
  • OpenAI
  • Anthropic
  • Google
  • xAI
  • OpenRouter
  • Fal
  • Replicate

OneHub remains responsible for ensuring subprocessors are contractually obligated to protect Personal Data to an appropriate standard.

International Transfers

Where Personal Data is transferred across international borders, OneHub will use appropriate safeguards where required by applicable law.

Data Subject Rights

To the extent legally required and reasonably feasible, OneHub will assist the Controller in responding to requests relating to:

  • access
  • correction
  • deletion
  • restriction of processing
  • objection

data portability.

Data Retention and Deletion

Upon termination of the Services, OneHub will retain or delete Personal Data in accordance with applicable law, contractual obligations, and operational requirements.

Data stored solely on the customer's local devices remains under the customer's control.

Audits

Upon reasonable written request and subject to appropriate confidentiality obligations, OneHub may provide information reasonably necessary to demonstrate compliance with this DPA.

OneHub is not required to disclose confidential security information, trade secrets, or information that could compromise the security of other customers.

Limitation of Liability

The liability of each party under this DPA is subject to the limitation of liability provisions contained in the applicable Terms of Service, unless prohibited by applicable law.

Governing Law

This DPA shall be governed by the same governing law specified in the applicable Terms of Service unless otherwise required by mandatory data protection legislation.

Contact

Questions regarding this DPA may be directed to:

  • OneHub Privacy Team
  • Email: privacy@onehub.design
  • Website: https://onehub.design