Legal · Stoj IT

Privacy Policy

How Stoj IT collects, uses, and protects personal data when you use HubOps.

Last updated: 15 August 2026

1. Who we are

Stoj IT ("we", "us") operates HubOps at hubops.net and portal.hubops.net. This Privacy Policy explains how we process personal data when you visit our marketing site, request access, sign in, or use the client portal and related services.

Privacy questions: privacy@hubops.net.

These documents apply to HubOps operated by Stoj IT. They are product policies for the HubOps platform, not legal advice. For a signed contract or enterprise DPA schedule, contact us.

2. Scope

This policy covers personal data we process as a controller for our own HubOps accounts, marketing leads, and platform administration.

When a HubSpot Implementation Partner or client organization uses HubOps to deliver work for their customers, that organization is typically the controller of customer CRM and delivery data. In that case we act as a processor under our Terms and Data Processing Addendum (DPA).

3. Data we collect

Depending on how you use HubOps, we may process:

  • Account data: name, email, role, organization, tenant slug, invite status.
  • Authentication data: password hashes (where used), OAuth identifiers (for example Google), session tokens.
  • Usage and security logs: IP address, user agent, approximate location from IP, timestamps, and actions for security and support.
  • Marketing / access requests: name, email, company, message content you submit.
  • Support and delivery content: messages, tickets, feedback, files, and notes you or your organization put into HubOps.
  • Integration metadata: HubSpot portal IDs, OAuth tokens (stored securely), connection status, and similar connector fields needed to run the product.

4. How we use data

We use personal data to:

  • Provide, secure, and improve HubOps.
  • Authenticate users and enforce access controls (including invites and impersonation for support).
  • Respond to access requests and support tickets.
  • Operate integrations you connect (for example HubSpot) on your instructions.
  • Send service emails (invites, password resets, security notices).
  • Comply with law and protect against abuse or fraud.

5. Legal bases (EEA/UK)

Where GDPR or UK GDPR applies, we rely on: contract (to provide the service you request), legitimate interests (secure the platform, improve product, B2B marketing where allowed), consent (where we ask for it), and legal obligation when required.

6. Sharing

We do not sell personal data. We share data with:

  • Infrastructure and subprocessors needed to run HubOps (hosting, database, email, auth). Current core stack includes Vercel (hosting), Supabase (database/auth), and email delivery for invites.
  • Your organization administrators and authorized partners when you are a member of their workspace.
  • Professional advisors or authorities when required by law or to protect rights and safety.

7. International transfers

HubOps may process data in the United States, European Economic Area, and other regions where our providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses with subprocessors.

8. Retention

We keep account and workspace data while your organization uses HubOps and for a reasonable period afterward for backups, disputes, and legal requirements. Marketing leads are kept until handled or you ask us to delete them. Security logs are retained for a limited period needed for incident response.

9. Security

We use industry-standard measures including encrypted transport (HTTPS), access controls, signed session cookies where applicable, and least-privilege service credentials. No method of transmission or storage is 100% secure.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Contact privacy@hubops.net. If we process data for your organization as a processor, we will route the request to that organization when appropriate.

You may lodge a complaint with your local supervisory authority.

11. Children

HubOps is a business platform and is not directed at children under 16. We do not knowingly collect children's data.

12. Changes

We may update this policy. The "Last updated" date at the top will change. Material changes may also be communicated in-product or by email where appropriate.