Hubionis Logo
  • Main page
  • Events
  • Hub
  • Login
  • Join us for free
πŸ‡΅πŸ‡± Polski πŸ‡¬πŸ‡§ English

Privacy Policy

Version: 1.0 | Effective Date: January 29, 2026
Compliant with GDPR (Regulation EU 2016/679)

πŸ“§ Data Protection Contact: privacy@hubionis.com

🏒 Data Controller: Cryptionis sp. z o.o., ul. Narwik 8/35, 01-471 Warsaw, Poland

πŸ” Tax ID (NIP): 5223241648 | KRS: 0001024788

Β§ 1. Data Controller

The Data Controller within the meaning of Art. 4(7) GDPR is:

Cryptionis sp. z o.o.
ul. Narwik 8/35, 01-471 Warsaw, Poland
Tax ID (NIP): 5223241648 | KRS: 0001024788
Email: contact@hubionis.com
Phone: +48 22 XXX XX XX

Data Protection Officer (DPO):
Status: Not appointed (no obligation under Art. 37 GDPR)
Note: A DPO will be appointed if the platform exceeds 50,000 active users or processes sensitive data on a large scale.

Data Protection Contact:
πŸ“§ Email: privacy@hubionis.com
πŸ“¬ Mail: Cryptionis sp. z o.o., ul. Narwik 8/35, 01-471 Warsaw (marked "GDPR")

Β§ 2. Categories of Personal Data Processed

2.1. Mandatory Data (Required for Registration)

  • First and last name
  • Email address (login + identity verification)
  • Password (encrypted with bcrypt algorithm, 12 rounds)
  • User role (Attendee, Speaker, Organizer, Admin)
  • Registration date

2.2. Optional Data (Voluntarily Provided)

  • Country of residence
  • Phone number (for Organizers – required for verification)
  • Date of birth (age verification 13-17 years)
  • Profile photo
  • Biography (for Speakers and Organizers)
  • Website/social media links
  • Event type preferences (technology, business, arts, sports, other)

2.3. Automatically Collected Data

  • IP address
  • User Agent (browser type, operating system)
  • Timestamps (login time, actions)
  • Activity logs (browsed events, bookings, clicks)
  • Geolocation (approximate, based on IP – for local event suggestions)
  • Session data (refresh token, access token – stored in Redis, expire after 7 days)
  • Cookies (details in Cookie Policy)

2.4. Financial Data (for Organizers and Paid Event Attendees)

  • Bank account number/IBAN (only for Organizers – for payouts)
  • Credit card data (NEVER stored on our servers – processed by Stripe PCI-DSS Level 1)
  • Transaction history (amount, date, payment status)
  • VAT invoices (stored for 5 years per tax law)

2.5. Sensitive Data (Art. 9 GDPR)

We DO NOT process sensitive data (racial, ethnic, political, religious, health, sexual orientation), unless a User voluntarily provides such information in their biography (in which case it constitutes explicit consent under Art. 9(2)(a) GDPR).

Β§ 3. Legal Bases for Processing (Art. 6 GDPR)

Processing purpose Legal basis GDPR Article
Registration and account management Contract performance (Terms) Art. 6(1)(b)
Bookings and event participation Contract performance Art. 6(1)(b)
Payment processing Contract performance + legal obligation (invoices) Art. 6(1)(b) + (c)
Newsletter and marketing Consent (can be withdrawn) Art. 6(1)(a)
Push notifications Consent (can be withdrawn) Art. 6(1)(a)
Analytics and cookies (Google Analytics) Consent (cookie banner) Art. 6(1)(a)
Security (logs, fraud detection) Legitimate interest of the Controller Art. 6(1)(f)
Complaint handling and GDPR rights Legal obligation + contract performance Art. 6(1)(c) + (b)

Β§ 4. Data Recipients

4.1. Data Processors (Art. 28 GDPR)

Personal data may be shared with the following processors (acting under Data Processing Agreement - DPA):

Entity Purpose Location DPA Status
Amazon Web Services (AWS) Database hosting (PostgreSQL RDS), storage (S3) πŸ‡ͺπŸ‡Ί eu-central-1 (Frankfurt, Germany) βœ… Signed (AWS Customer Agreement)
Stripe Payment processing πŸ‡ΊπŸ‡Έ USA (+ EU data residency) ⏳ In progress (deadline: Feb 15, 2026)
SendGrid (Twilio) Transactional and marketing emails πŸ‡ΊπŸ‡Έ USA βœ… Signed
Google Analytics Traffic analytics (with cookie consent) πŸ‡ΊπŸ‡Έ USA ⚠️ Google Measurement Controller-Controller Data Protection Terms
OneSignal Push notifications (with consent) πŸ‡ΊπŸ‡Έ USA ⏳ Planned (Q2 2026)

4.2. Data Transfers Outside EEA

Some processors (Stripe, SendGrid, Google Analytics, OneSignal) are based in the USA. Data transfers are based on:

  • EU-US Data Privacy Framework (for certified entities);
  • Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914);
  • Binding Corporate Rules (BCR) – for companies with such rules.

Note: Transfer to the USA involves risk of US security agency access to data (FISA, CLOUD Act). If you do not consent to the transfer, you may:

  • Disable Google Analytics (cookie settings);
  • Unsubscribe from the newsletter (no transfer to SendGrid);
  • Not use card payments (Stripe) – choose traditional bank transfer.

Β§ 5. Data Retention Period

Data category Retention period Legal basis
Account data (active) Until account deletion by user Contract performance (Art. 6(1)(b))
Account data (after deletion) 30 days (complete deletion) Contract + right to be forgotten (Art. 17)
Booking history (anonymized) 5 years (for accounting purposes) Legal obligation (Accounting Act)
VAT invoices 5 years Legal obligation (Art. 6(1)(c) – tax ordinance)
Marketing consents (newsletter) Until consent withdrawal Consent (Art. 6(1)(a))
Security logs (IP, user agent) 12 months Legitimate interest (Art. 6(1)(f))
Analytics cookies (Google Analytics) 14 months Consent (Art. 6(1)(a))
Complaints 3 years (limitation of claims) Legal obligation (Civil Code)

Β§ 6. Data Subject Rights (Art. 15-22 GDPR)

6.1. Right of Access (Art. 15)

You have the right to obtain confirmation of whether we process your data and receive a copy.

How to exercise:

  • Dashboard β†’ Settings β†’ Privacy β†’ Download My Data (JSON export);
  • Email: privacy@hubionis.com (response within 30 days).

6.2. Right to Rectification (Art. 16)

You can correct inaccurate or incomplete data.

How to exercise:

  • Dashboard β†’ Settings β†’ Edit Profile (immediate changes);
  • Email: privacy@hubionis.com (for data not visible in the panel).

6.3. Right to Erasure (Art. 17 – "Right to be Forgotten")

You may request deletion of your data if:

  • Data is no longer necessary for the purposes for which it was collected;
  • You have withdrawn consent (e.g., for newsletter);
  • You have objected to processing (Art. 21);
  • Data was processed unlawfully.

How to exercise:

  • Dashboard β†’ Settings β†’ Delete Account;
  • Email: privacy@hubionis.com.

Exceptions: We cannot delete data if:

  • Required to fulfill a legal obligation (e.g., invoices – 5 years);
  • Necessary for establishing, exercising, or defending legal claims (e.g., in ongoing litigation).

6.4. Right to Restriction of Processing (Art. 18)

You may request "freezing" of your data (storage without processing) if:

  • You contest the accuracy of data (pending verification);
  • Processing is unlawful but you don't want data deleted;
  • Data is needed for legal claims (even though we no longer need it for other purposes).

How to exercise: Email: privacy@hubionis.com (processing: 30 days).

6.5. Right to Data Portability (Art. 20)

You may receive your data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller.

How to exercise: Dashboard β†’ Settings β†’ Privacy β†’ Download My Data (JSON).

6.6. Right to Object (Art. 21)

You may object to processing based on legitimate interest (Art. 6(1)(f)), e.g.:

  • IP logging for security;
  • Profiling for event recommendations.

How to exercise:

  • Dashboard β†’ Settings β†’ Privacy β†’ Disable Personalization;
  • Email: privacy@hubionis.com.

Note: Objection to processing based on contract (Art. 6(1)(b)) may result in inability to use the platform (e.g., you cannot opt out of storing your email, as it's necessary for login).

6.7. Right to Withdraw Consent (Art. 7(3))

You may withdraw consent at any time for:

  • Newsletter: Click "Unsubscribe" in email or Dashboard β†’ Settings β†’ Privacy β†’ Unsubscribe Newsletter;
  • Push notifications: Dashboard β†’ Settings β†’ Notifications β†’ Disable Push;
  • Analytics cookies: Cookie Banner β†’ Manage Cookies β†’ Disable "Analytics".

Effect: Withdrawal does not affect the lawfulness of processing before withdrawal.

6.8. Right to Lodge a Complaint with Supervisory Authority

If you believe we process your data unlawfully, you may file a complaint with:

President of the Office for Personal Data Protection (UODO)
ul. Stawki 2, 00-193 Warsaw
πŸ“§ Email: kancelaria@uodo.gov.pl
🌐 Online form: www.uodo.gov.pl

Β§ 7. Data Security

7.1. Technical Measures

  • Data encryption:
    • Passwords: bcrypt (12 rounds, salt per-user);
    • Data in transit: TLS 1.3 (HTTPS);
    • Database: Encryption at rest (AWS RDS KMS).
  • Access tokens:
    • JWT (access token: 15 min, refresh token: 7 days);
    • Refresh token stored in Redis (automatic expiration).
  • Rate limiting: Maximum 100 requests/minute (brute-force protection).
  • Firewall: AWS Security Groups (database accessible only from backend).
  • Backups: Daily database backups (30-day retention, encrypted).

7.2. Organizational Measures

  • Data access: Only authorized employees (need-to-know principle);
  • Training: Annual GDPR training for team (planned: Q2 2026);
  • Audits: Annual security audit (ISO 27001 certification planned for 2027);
  • Breach response procedure: Data Breach Procedure (UODO notification within 72h per Art. 33 GDPR).

Β§ 8. Cookies

The Platform uses cookies to ensure proper operation and traffic analysis. Detailed information can be found in the Cookie Policy.

8.1. Cookie Types

Type Purpose Requires consent?
Necessary Login, session, cart ❌ NO (Art. 6(1)(f) – legitimate interest)
Functional Language, display preferences ❌ NO
Analytics Google Analytics (statistics) βœ… YES (cookie banner)
Marketing Remarketing (Google Ads, Facebook Pixel) βœ… YES

Β§ 9. Children's Data (Under 16 Years)

9.1. Minimum Age

The Platform requires users to be at least 13 years old (per Art. 8 GDPR – Poland lowered the limit to 13 years).

9.2. Users Aged 13-17

Persons aged 13-17 may use the platform with parental/guardian consent. Required actions:

  • Providing parent's email address during registration;
  • Sending verification email to parent (parent must click "Confirm Consent");
  • Parent may request account deletion at any time (email: privacy@hubionis.com).

Β§ 10. Changes to Privacy Policy

10.1. Right to Update

The Controller reserves the right to update this Privacy Policy for important reasons (legal changes, new features, new processors).

10.2. Notification of Changes

We will notify Users of significant changes with 14 days' notice via:

  • Email to the account-associated address;
  • Main page announcement;
  • Push notification (if consented).

Β§ 11. Privacy Contact

πŸ“§ Email: privacy@hubionis.com
πŸ“¬ Mailing address: Cryptionis sp. z o.o., ul. Narwik 8/35, 01-471 Warsaw (marked "GDPR")
πŸ“ž Phone: +48 22 XXX XX XX (weekdays, 9:00-17:00)
⏱️ Response time: Within 30 days (per Art. 12(3) GDPR)

For urgent matters (data breach, suspected account compromise):
πŸ“§ Email: security@hubionis.com (24-hour response)

Last updated: January 29, 2026

Document version: 1.0

Home | Terms | Privacy Policy | Cookies

Β© 2026 Cryptionis sp. z o.o. All rights reserved.

Home Events Hub Account