Legal

Privacy Policy

What personal data we handle, on whose behalf, where it lives, how long we keep it, and the rights you have over it.

Last updated: 4 September 2026 · Effective: 4 September 2026

Salex Hub Commercial Brokers L.L.C (“SalexHub”, “we”, “us”), registered in Dubai, United Arab Emirates, operates salexhub.ai and the SalexHub platform. This policy explains how we handle personal data.

It covers two different relationships, and which one applies changes your rights and who you exercise them against:

  • We are the controller for data about our own visitors, prospects, account holders and their users, billing and support — described in sections 2 to 12.
  • We are a processor for the data our customers store in their workspace (their contacts, deals, emails, form submissions, website telemetry). The customer decides why and how that data is processed; we act on their instructions under our Data Processing Agreement — described in section 13.

1Scope

This policy applies to salexhub.ai and its subdomains, to the SalexHub platform at app.salexhub.ai, to our APIs and connectors, and to our sales, support and marketing activity. It does not apply to third-party sites we link to, nor to a customer's own website, even where that website runs SalexHub tracking or forms.

Where a customer runs the software on their own infrastructure, that customer operates the deployment and this policy does not apply to data held there.

2Data we collect as controller

CategoryWhat it includesWhere it comes from
Account dataName, business email, password hash, workspace name, role, language and locale preference, workspace settings, invitation records.You, when registering or being invited.
Billing dataCompany name, billing contact, purchase and credit-transaction history, invoices, the last four digits and brand of a card, and the payment processor's transaction identifiers. We never receive or store full card numbers.You, and our payment processor.
Usage and diagnostic dataPages and features used in the product, actions taken, agent runs and the credits they consumed, API calls, error and performance logs, and the audit trail of changes made in a workspace.Automatically, as you use the Service.
Device and connection dataIP address, browser and operating system, and approximate country, used for security, abuse prevention and diagnostics.Automatically, from your requests.
Support and communicationsMessages you send us, their attachments, and our replies; call or meeting notes where we take them.You.
Marketing and prospect dataBusiness contact details of people who ask for a demo, subscribe, or whose company we contact; the content of that correspondence; and, where you consent to it, whether our emails were opened.You, or public and commercially available business sources.
Website dataPages viewed on our marketing site and the referring source, in aggregate. Our marketing site sets no analytics or advertising cookies and loads no third-party trackers or fonts.Automatically.

We do not deliberately collect special categories of personal data (health, biometrics, political or religious views) about our own users, and we ask you not to send them to us in support correspondence.

3Why we use it, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Providing the Service — creating workspaces, authenticating users, running features you invokeAccount, usage, devicePerformance of a contract
Billing, credits and collectionsBilling, account, usagePerformance of a contract; legal obligation for tax and accounting records
Security, abuse prevention, rate limiting and fraud detectionDevice, usage, accountLegitimate interests — keeping the Service and its users safe
Support and service communications (outages, security notices, changes to terms)Account, supportPerformance of a contract; legitimate interests
Improving and developing the product — aggregate statistics, diagnostics, adoption analysisUsage, diagnostic, de-identified statisticsLegitimate interests — improving a service our customers pay for
Marketing to businesses and prospectsMarketing, accountConsent where required; otherwise legitimate interests in business-to-business marketing, with an opt-out in every message
Complying with law, responding to lawful requests, establishing or defending legal claimsAny of the above, as neededLegal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed them against your rights and freedoms; you can ask us for that assessment, and you can object at any time (section 10).

We do not make decisions producing legal or similarly significant effects about you solely by automated means.

4AI processing

The Service includes AI features. When a feature runs, the parts of the workspace needed to answer — the prompt, the records in scope, retrieved documents and the conversation so far — are sent to a model provider acting as our subprocessor, or to a provider whose key the customer supplied.

  • Our providers are contractually barred from training on data we send them on a customer's behalf.
  • Content is sent only as needed to produce the result asked for, and only within the permissions of the person or key the agent acts for.
  • Prompts, results, tool calls and the credits consumed are recorded in the workspace so a run can be audited; those transcripts are retained as set out in section 8.
  • Where a customer configures their own provider key, that provider's terms govern the processing, and our no-training commitment may not apply.

The AI Terms describe how agents work, what they may act on, and the limits of model output. Current providers are listed on the Subprocessors page.

5Cookies and similar technologies

Our marketing site sets no analytics or advertising cookies. The application uses strictly necessary cookies for sign-in, session security and language preference. The website analytics we offer to customers is cookieless by design.

Full detail is in the Cookie Policy.

6Who we share data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it only in these cases:

  • Subprocessors and service providers — hosting, database, storage, email delivery, payment processing and model providers, each bound by written terms limiting them to our instructions. The current list is at /legal/subprocessors.
  • Within your organisation — administrators of a workspace can see the users in it, their activity, and the audit trail.
  • Professional advisers — lawyers, accountants and auditors, under confidentiality.
  • Legal and safety — where required by law or valid legal process, or to establish, exercise or defend legal claims. We assess every request, refuse those that are overbroad or unlawful, and where permitted notify the affected customer before disclosing.
  • Corporate transactions — in a merger, acquisition or sale of assets, under confidentiality, with notice to affected customers and this policy continuing to apply until replaced.

7Where data is stored and international transfers

The primary database holding workspace data is located in the European Union (Frankfurt, Germany). Files are stored in object storage in the European Union. Application compute runs on globally distributed infrastructure, including edge regions in Frankfurt, Dubai and Washington, D.C., so a request is served near the person making it.

Some subprocessors — notably model providers and our payment processor — process data in the United States or other countries. We are established in the United Arab Emirates. This means personal data may be transferred outside the country where it was collected.

For transfers of data protected by European, UK or Swiss law we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and we assess each transfer for the protection actually available in the destination. Copies are available on request at start@salexhub.ai.

8How long we keep data

We keep personal data only as long as needed for the purpose it was collected for, then delete or de-identify it. Defaults for the Service, which a customer may shorten in their workspace configuration:

DataDefault retention
Workspace records and files (customer-controlled content)For the life of the workspace, then as in section 9
Deleted records and files (recycle bin)30 days, then permanently deleted
Field-level change history24 months
Website analytics events13 months
Behavioural signals about known contacts90 days
AI prompts, results and run transcripts90 days
In-product notifications, once read180 days
Outbound event and webhook delivery logs30 days (14 days for undeliverable events)
Security and access logs12 months
Billing records, invoices and tax documentationAs required by law, typically 5–7 years
Support correspondence24 months after the case closes
Marketing contact recordsUntil you object or unsubscribe, then a minimal suppression record so we do not contact you again

Backups follow their own cycle and are overwritten on a rolling basis; data deleted from the live system disappears from backups as those backups age out. Where we must keep something for a legal claim or obligation, we isolate and restrict it rather than continue using it.

9Account closure and deletion

You can export workspace data from the product at any time. When a workspace is closed, we make an export available for thirty (30) days and then delete workspace data, except records we must retain by law (billing and tax documentation) and minimal suppression records that exist precisely so a deletion is not silently undone by a future import.

Individual erasure requests inside a workspace are handled by the customer using the erasure tools we provide; the effect is immediate in the product, and the physical removal, including from derived stores and search indexes, completes asynchronously.

10Your rights

Subject to your local law, you can ask us to: give you a copy of your personal data; correct it; delete it; restrict or object to processing; port it to another provider; and withdraw consent where we relied on consent. You will not be treated differently for exercising a right.

To exercise a right, write to start@salexhub.ai with the subject “Privacy”. We answer within thirty (30) days, or sooner where the law requires, and may ask for information to verify your identity — used only for that purpose.

European Economic Area, United Kingdom and Switzerland

You have the rights in Articles 15–22 GDPR (and the UK and Swiss equivalents), including the right to lodge a complaint with your supervisory authority. We ask that you contact us first so we can put things right.

United Arab Emirates

Where Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies, you have rights of access, correction, erasure, restriction, portability, and objection to processing, and may complain to the UAE Data Office.

California

If you are a California resident, you may request the categories and specific pieces of personal information we collected, the purposes, and the categories of recipients; request deletion or correction; and limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months.

Other regions

Where local law grants rights beyond those listed here — for example in Brazil, Canada, Saudi Arabia or Australia — we honour them for people in those places.

11Security

We encrypt data in transit with TLS and at rest, isolate tenants at the data-access layer, encrypt stored third-party credentials with an envelope key, restrict production access to those who need it, and log administrative actions. Details are in the Security Overview.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and, where required, the competent authority, without undue delay.

To report a vulnerability, write to start@salexhub.ai with the subject “Security”. We will not pursue good-faith researchers who follow the guidance in the Security Overview.

12Children

The Service is a business tool, not directed to children, and we do not knowingly collect personal data from anyone under 18 as a user. If you believe a child has provided us personal data, write to us and we will delete it.

13Data our customers store in the product

For personal data our customers put into their workspace — their contacts, the recipients of their emails, visitors to their websites, people who submit their forms — the customer is the controller and we are the processor. We process it only on their instructions, under the Data Processing Agreement.

This includes data reaching us through features the customer switches on:

  • Mailbox connection. Where a customer connects a mailbox over IMAP/SMTP, we synchronise messages so that correspondence appears against records. The customer is responsible for having the right to do so and for informing the people concerned.
  • Website analytics. Our tracker is cookieless: a visitor is identified by a hash computed from a daily rotating salt, so the identifier cannot be linked across days, and it stores no IP address — only an approximate country derived at the edge. The customer decides what to track and must publish their own notice.
  • Forms and embedded components. What a visitor submits is stored verbatim for the customer, and may become a contact record in their workspace.
  • Documents and quotes shared by link. Views of a shared document are recorded for the customer who shared it.

If you want your data accessed, corrected or deleted by such a customer, contact them directly. We will assist them in responding, and will forward a request to them where you cannot identify who they are.

14Changes to this policy

We update this policy as the product and the law change. The date at the top always reflects the current version. For material changes we give at least thirty (30) days' notice by email to account administrators or by notice in the product before the change takes effect.

15Contact

Salex Hub Commercial Brokers L.L.C, Dubai, United Arab Emirates.

Privacy enquiries and rights requests: start@salexhub.ai with the subject “Privacy”.

We have not appointed a statutory data protection officer, and we will do so if the law requires it. Requests reach the people responsible for privacy at the address above.