GDPR Compliance
Last updated: 2026-06-16
Our Commitment to GDPR
TCX Hub is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). We process personal data lawfully, fairly, and transparently. This page describes how we meet our obligations under the GDPR.
Legal Basis for Processing
We process personal data under the following legal bases:
- Contract Performance (Art. 6(1)(b)) - Processing necessary to provide the Service you subscribed to, including account management, telemetry monitoring, and billing. - Legitimate Interest (Art. 6(1)(f)) - Security monitoring, fraud prevention, and service improvement. - Consent (Art. 6(1)(a)) - Marketing communications (opt-in only). - Legal Obligation (Art. 6(1)(c)) - Tax and financial record-keeping requirements.
Data Subject Rights
Under GDPR, you have the following rights:
Right of Access (Art. 15) - Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16) - Request correction of inaccurate personal data.
Right to Erasure (Art. 17) - Request deletion of your personal data ("right to be forgotten").
Right to Data Portability (Art. 20) - Receive your data in a structured, machine-readable format.
Right to Restriction (Art. 18) - Request that we limit processing of your data.
Right to Object (Art. 21) - Object to processing based on legitimate interest.
Right to Withdraw Consent (Art. 7(3)) - Withdraw consent at any time for consent-based processing.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
Data Processing Agreement
When you use TCX Hub to manage 3CX systems on behalf of your customers, we act as a Data Processor on your behalf (you are the Data Controller). A Data Processing Agreement (DPA) is available upon request. Contact [email protected] to obtain a signed copy. Personal data and telemetry are kept according to your plan — 90 days on paid tiers, and not retained at all on the free tier — and are deleted when your account is closed.
Sub-Processors
We rely on the sub-processors listed below. Wherever possible we keep processing within the EU; where a sub-processor falls back to the United States, those transfers are safeguarded by Standard Contractual Clauses and the EU-US Data Privacy Framework.
| Sub-Processor | Purpose | Location | Status | |---|---|---|---| | Hetzner Online GmbH | Infrastructure hosting | Germany (EU) | Active | | Cloudflare, Inc. | DNS, CDN, DDoS protection, encrypted backup storage | EU / Global | Active | | Functional Software, Inc. (Sentry) | Error monitoring | EU (EU region) | Active | | Stripe, Inc. | Payment processing | EU (US fallback) | Active | | Twilio Inc. (SendGrid) | Transactional email | EU (US fallback) | Active | | Twilio Inc. | SMS verification | EU (US fallback) | Active | | Meta Platforms, Inc. | WhatsApp notifications | EU (US fallback) | Not yet enabled | | Slack, Telegram, Microsoft Teams, PagerDuty, Zapier | Optional notification delivery | Various | Optional — only when you enable it |
We will give you at least 30 days' notice before adding any new sub-processor.
International Data Transfers
Your data is stored and processed in the European Union (Hetzner, Germany), and we keep processing within the EU wherever we can. On the occasions a sub-processor falls back to the United States, those transfers are safeguarded by the EU-US Data Privacy Framework and Standard Contractual Clauses, in line with Chapter V of the GDPR.
Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and affected data subjects without undue delay, as required by Articles 33 and 34 of the GDPR.
Data Protection Contact
For GDPR-related inquiries, contact our data protection team at [email protected].