Salex Hub Commercial Brokers L.L.C (“SalexHub”, “we”, “us”), registered in Dubai, United Arab Emirates, operates salexhub.ai and the SalexHub platform. This policy explains how we handle personal data.
It covers two different relationships, and which one applies changes your rights and who you exercise them against:
- We are the controller for data about our own visitors, prospects, account holders and their users, billing and support — described in sections 2 to 12.
- We are a processor for the data our customers store in their workspace (their contacts, deals, emails, form submissions, website telemetry). The customer decides why and how that data is processed; we act on their instructions under our Data Processing Agreement — described in section 13.
1Scope
This policy applies to salexhub.ai and its subdomains, to the SalexHub platform at app.salexhub.ai, to our APIs and connectors, and to our sales, support and marketing activity. It does not apply to third-party sites we link to, nor to a customer's own website, even where that website runs SalexHub tracking or forms.
Where a customer runs the software on their own infrastructure, that customer operates the deployment and this policy does not apply to data held there.
2Data we collect as controller
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, business email, password hash, workspace name, role, language and locale preference, workspace settings, invitation records. | You, when registering or being invited. |
| Billing data | Company name, billing contact, purchase and credit-transaction history, invoices, the last four digits and brand of a card, and the payment processor's transaction identifiers. We never receive or store full card numbers. | You, and our payment processor. |
| Usage and diagnostic data | Pages and features used in the product, actions taken, agent runs and the credits they consumed, API calls, error and performance logs, and the audit trail of changes made in a workspace. | Automatically, as you use the Service. |
| Device and connection data | IP address, browser and operating system, and approximate country, used for security, abuse prevention and diagnostics. | Automatically, from your requests. |
| Support and communications | Messages you send us, their attachments, and our replies; call or meeting notes where we take them. | You. |
| Marketing and prospect data | Business contact details of people who ask for a demo, subscribe, or whose company we contact; the content of that correspondence; and, where you consent to it, whether our emails were opened. | You, or public and commercially available business sources. |
| Website data | Pages viewed on our marketing site and the referring source, in aggregate. Our marketing site sets no analytics or advertising cookies and loads no third-party trackers or fonts. | Automatically. |
We do not deliberately collect special categories of personal data (health, biometrics, political or religious views) about our own users, and we ask you not to send them to us in support correspondence.
3Why we use it, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service — creating workspaces, authenticating users, running features you invoke | Account, usage, device | Performance of a contract |
| Billing, credits and collections | Billing, account, usage | Performance of a contract; legal obligation for tax and accounting records |
| Security, abuse prevention, rate limiting and fraud detection | Device, usage, account | Legitimate interests — keeping the Service and its users safe |
| Support and service communications (outages, security notices, changes to terms) | Account, support | Performance of a contract; legitimate interests |
| Improving and developing the product — aggregate statistics, diagnostics, adoption analysis | Usage, diagnostic, de-identified statistics | Legitimate interests — improving a service our customers pay for |
| Marketing to businesses and prospects | Marketing, account | Consent where required; otherwise legitimate interests in business-to-business marketing, with an opt-out in every message |
| Complying with law, responding to lawful requests, establishing or defending legal claims | Any of the above, as needed | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and freedoms; you can ask us for that assessment, and you can object at any time (section 10).
We do not make decisions producing legal or similarly significant effects about you solely by automated means.
4AI processing
The Service includes AI features. When a feature runs, the parts of the workspace needed to answer — the prompt, the records in scope, retrieved documents and the conversation so far — are sent to a model provider acting as our subprocessor, or to a provider whose key the customer supplied.
- Our providers are contractually barred from training on data we send them on a customer's behalf.
- Content is sent only as needed to produce the result asked for, and only within the permissions of the person or key the agent acts for.
- Prompts, results, tool calls and the credits consumed are recorded in the workspace so a run can be audited; those transcripts are retained as set out in section 8.
- Where a customer configures their own provider key, that provider's terms govern the processing, and our no-training commitment may not apply.
The AI Terms describe how agents work, what they may act on, and the limits of model output. Current providers are listed on the Subprocessors page.
7Where data is stored and international transfers
The primary database holding workspace data is located in the European Union (Frankfurt, Germany). Files are stored in object storage in the European Union. Application compute runs on globally distributed infrastructure, including edge regions in Frankfurt, Dubai and Washington, D.C., so a request is served near the person making it.
Some subprocessors — notably model providers and our payment processor — process data in the United States or other countries. We are established in the United Arab Emirates. This means personal data may be transferred outside the country where it was collected.
For transfers of data protected by European, UK or Swiss law we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we assess each transfer for the protection actually available in the destination. Copies are available on request at start@salexhub.ai.
8How long we keep data
We keep personal data only as long as needed for the purpose it was collected for, then delete or de-identify it. Defaults for the Service, which a customer may shorten in their workspace configuration:
| Data | Default retention |
|---|---|
| Workspace records and files (customer-controlled content) | For the life of the workspace, then as in section 9 |
| Deleted records and files (recycle bin) | 30 days, then permanently deleted |
| Field-level change history | 24 months |
| Website analytics events | 13 months |
| Behavioural signals about known contacts | 90 days |
| AI prompts, results and run transcripts | 90 days |
| In-product notifications, once read | 180 days |
| Outbound event and webhook delivery logs | 30 days (14 days for undeliverable events) |
| Security and access logs | 12 months |
| Billing records, invoices and tax documentation | As required by law, typically 5–7 years |
| Support correspondence | 24 months after the case closes |
| Marketing contact records | Until you object or unsubscribe, then a minimal suppression record so we do not contact you again |
Backups follow their own cycle and are overwritten on a rolling basis; data deleted from the live system disappears from backups as those backups age out. Where we must keep something for a legal claim or obligation, we isolate and restrict it rather than continue using it.
9Account closure and deletion
You can export workspace data from the product at any time. When a workspace is closed, we make an export available for thirty (30) days and then delete workspace data, except records we must retain by law (billing and tax documentation) and minimal suppression records that exist precisely so a deletion is not silently undone by a future import.
Individual erasure requests inside a workspace are handled by the customer using the erasure tools we provide; the effect is immediate in the product, and the physical removal, including from derived stores and search indexes, completes asynchronously.
10Your rights
Subject to your local law, you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to processing; port it to another provider; and withdraw consent where we relied on consent. You will not be treated differently for exercising a right.
To exercise a right, write to start@salexhub.ai with the subject “Privacy”. We answer within thirty (30) days, or sooner where the law requires, and may ask for information to verify your identity — used only for that purpose.
European Economic Area, United Kingdom and Switzerland
You have the rights in Articles 15–22 GDPR (and the UK and Swiss equivalents), including the right to lodge a complaint with your supervisory authority. We ask that you contact us first so we can put things right.
United Arab Emirates
Where Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies, you have rights of access, correction, erasure, restriction, portability, and objection to processing, and may complain to the UAE Data Office.
California
If you are a California resident, you may request the categories and specific pieces of personal information we collected, the purposes, and the categories of recipients; request deletion or correction; and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months.
Other regions
Where local law grants rights beyond those listed here — for example in Brazil, Canada, Saudi Arabia or Australia — we honour them for people in those places.
11Security
We encrypt data in transit with TLS and at rest, isolate tenants at the data-access layer, encrypt stored third-party credentials with an envelope key, restrict production access to those who need it, and log administrative actions. Details are in the Security Overview.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and, where required, the competent authority, without undue delay.
To report a vulnerability, write to start@salexhub.ai with the subject “Security”. We will not pursue good-faith researchers who follow the guidance in the Security Overview.
12Children
The Service is a business tool, not directed to children, and we do not knowingly collect personal data from anyone under 18 as a user. If you believe a child has provided us personal data, write to us and we will delete it.
13Data our customers store in the product
For personal data our customers put into their workspace — their contacts, the recipients of their emails, visitors to their websites, people who submit their forms — the customer is the controller and we are the processor. We process it only on their instructions, under the Data Processing Agreement.
This includes data reaching us through features the customer switches on:
- Mailbox connection. Where a customer connects a mailbox over IMAP/SMTP, we synchronise messages so that correspondence appears against records. The customer is responsible for having the right to do so and for informing the people concerned.
- Website analytics. Our tracker is cookieless: a visitor is identified by a hash computed from a daily rotating salt, so the identifier cannot be linked across days, and it stores no IP address — only an approximate country derived at the edge. The customer decides what to track and must publish their own notice.
- Forms and embedded components. What a visitor submits is stored verbatim for the customer, and may become a contact record in their workspace.
- Documents and quotes shared by link. Views of a shared document are recorded for the customer who shared it.
If you want your data accessed, corrected or deleted by such a customer, contact them directly. We will assist them in responding, and will forward a request to them where you cannot identify who they are.
14Changes to this policy
We update this policy as the product and the law change. The date at the top always reflects the current version. For material changes we give at least thirty (30) days' notice by email to account administrators or by notice in the product before the change takes effect.
15Contact
Salex Hub Commercial Brokers L.L.C, Dubai, United Arab Emirates.
Privacy enquiries and rights requests: start@salexhub.ai with the subject “Privacy”.
We have not appointed a statutory data protection officer, and we will do so if the law requires it. Requests reach the people responsible for privacy at the address above.