Last updated: 3 September 2026.
This Addendum is part of the Terms of Service between Digidom Studios Limited (trading as Hubdash) and the Customer (a company registered in the United Kingdom).
It applies when we process Customer Data (personal data the Customer or its Authorised Users submit to the Service) as processor. The Customer is the controller. UK GDPR and the Data Protection Act 2018 apply.
Authorised User account data (login, billing) is covered by our Privacy Policy, not this Addendum.
We process Customer Data to provide the Service: CRM and contact records, messages, form responses, calendar bookings, files, tracking events, and Authorised User identity needed to operate the account.
We process it only for that purpose, for the life of the account, and then as set out in section 11.
The Customer's use of the Service is our documented instruction. We will not use Customer Data for our own purposes, sell it, or use it to train models.
We will tell the Customer if we think an instruction breaks UK GDPR, unless the law forbids us from saying so.
If UK law requires us to process Customer Data other than on the Customer's instructions, we will tell the Customer unless the law prohibits that.
The Customer must have a lawful basis to collect and use Customer Data, and must publish its own UK privacy notice. The Customer is responsible for PECR compliance for marketing it sends through the Service.
We ensure people who process Customer Data for us are bound by confidentiality.
We will take appropriate technical and organisational measures, including encryption in transit, access control, logging, and hosting in AWS eu-west-2 (UK), including Amazon DocumentDB.
The Customer authorises us to use the providers listed on our Subprocessors page.
We will post material additions there. The Customer has 30 days from the post to object on reasonable data-protection grounds. If we cannot accommodate the objection, either party may terminate the affected Service.
Each subprocessor is bound to data-protection terms no less protective than this Addendum.
Customer-connected integrations (for example the Customer's own SendGrid, Mailgun, Twilio, or WhatsApp credentials) are the Customer's processors, not ours. This Addendum does not apply to those providers.
We send Hubdash transactional and platform email through Mailgun and Postmark on our own accounts. Those providers are our subprocessors and appear on the Subprocessors page.
We will help the Customer meet its UK GDPR duties for Customer Data, including data-subject requests, security, breach notification, and data-protection impact assessments, taking into account the nature of the processing.
We will not respond to requests from the Customer's contacts ourselves, other than to direct them to the Customer, unless the law requires us to.
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information the Customer reasonably needs to notify the ICO or affected people.
On written request we will provide information reasonably necessary to show we meet this Addendum.
The Service is hosted in the United Kingdom (AWS eu-west-2).
Where we transfer Customer Data out of the UK, or a subprocessor does, we will use the UK International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. We do not rely on EU standard contractual clauses alone as the transfer tool.
Within 10 days after the account ends, we will delete Customer Data or return it in a reasonable format, at the Customer's written choice, then delete remaining copies unless UK law requires us to keep them.
If this Addendum and the Terms conflict on Customer Data, this Addendum prevails.