GDPR Compliance

Last updated: 2026-06-16

Our Commitment to GDPR

TCX Hub is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). We process personal data lawfully, fairly, and transparently. This page describes how we meet our obligations under the GDPR.

Data Processing Agreement

When you use TCX Hub to manage 3CX systems on behalf of your customers, we act as a Data Processor on your behalf (you are the Data Controller). A Data Processing Agreement (DPA) is available upon request. Contact [email protected] to obtain a signed copy. Personal data and telemetry are kept according to your plan — 90 days on paid tiers, and not retained at all on the free tier — and are deleted when your account is closed.

Legal Basis for Processing

We process personal data under the following legal bases:

- Contract Performance (Art. 6(1)(b)) - Processing necessary to provide the Service you subscribed to, including account management, telemetry monitoring, and billing. - Legitimate Interest (Art. 6(1)(f)) - Security monitoring, fraud prevention, and service improvement. - Consent (Art. 6(1)(a)) - Marketing communications (opt-in only). - Legal Obligation (Art. 6(1)(c)) - Tax and financial record-keeping requirements.

Data Subject Rights

Under GDPR, you have the following rights:

Right of Access (Art. 15) - Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16) - Request correction of inaccurate personal data.

Right to Erasure (Art. 17) - Request deletion of your personal data ("right to be forgotten").

Right to Data Portability (Art. 20) - Receive your data in a structured, machine-readable format.

Right to Restriction (Art. 18) - Request that we limit processing of your data.

Right to Object (Art. 21) - Object to processing based on legitimate interest.

Right to Withdraw Consent (Art. 7(3)) - Withdraw consent at any time for consent-based processing.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

Data Protection Officer

TCX Hub has designated a data protection point of contact responsible for overseeing GDPR compliance. The DPO's responsibilities include:

- Monitoring compliance with GDPR and other data protection laws - Advising on data protection impact assessments (DPIAs) - Cooperating with supervisory authorities - Serving as the contact point for data subjects exercising their rights

You can reach our data protection team at [email protected]. We aim to respond to all inquiries within 5 business days.

Data Breach Procedures

TCX Hub maintains a comprehensive data breach response procedure in accordance with Articles 33 and 34 of the GDPR.

Detection & Assessment: All potential breaches are logged and assessed within 24 hours of discovery. We evaluate the nature, scope, and potential impact of the breach.

Supervisory Authority Notification: If a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it.

Data Subject Notification: If a breach is likely to result in a high risk to individuals, we will notify affected data subjects without undue delay, providing clear information about the nature of the breach and recommended protective measures.

Documentation: All breaches are documented regardless of severity, including the facts, effects, and remedial actions taken.

International Data Transfers

Your primary data is stored in the European Union on Hetzner servers located in Germany. We minimize international data transfers wherever possible.

Where data is transferred outside the EU/EEA, we ensure adequate protection through:

EU-US Data Privacy Framework: Stripe, Inc. and Functional Software, Inc. (Sentry) are certified under the EU-US Data Privacy Framework, providing an adequate level of data protection as recognized by the European Commission.

Standard Contractual Clauses (SCCs): Where the Data Privacy Framework does not apply, we use the European Commission's Standard Contractual Clauses as the legal mechanism for data transfers.

Transfer Impact Assessments: We conduct transfer impact assessments for all international transfers to evaluate the legal framework of the recipient country and implement supplementary measures where necessary.

You may request details of the specific safeguards applied to your data by contacting [email protected].

Contact

For any GDPR-related questions, concerns, or requests, contact us at:

Email: [email protected]

Response Time: We aim to acknowledge all requests within 5 business days and provide a substantive response within 30 days, as required by the GDPR.

Supervisory Authority: If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority.

GDPR Compliance | TCX Hub