Skip to content
Hubify Solutions
Last updated July 26, 2026

Privacy Policy

This policy explains how Hubify Solutions Inc. handles personal information across everything we do — our website, our consulting and development work, our products, and the platforms and messaging services we operate for client businesses. It covers information we hold about our own contacts and customers, and information we process on behalf of clients, including data accessed through connected systems such as CRMs, mailboxes, and business messaging platforms. We collect as little as we can, we use it only for the purposes described here, and we do not sell it.

01Scope of this policy

This policy applies to Hubify Solutions Inc. as a company. It covers this website, our consulting and development services, our products including the Keylid family, and any API, integration, automation, or messaging service we operate. It is not limited to website visitors. Where a specific product or engagement has additional or differing privacy terms, those are provided to the customer directly and are read together with this policy.

02Our role: controller and processor

We act in two distinct roles. We are the controller of personal information we collect for our own purposes — enquiries, prospective and current client contacts, supplier relationships, recruitment, and the administration of our business. We are a service provider and data processor for personal information we process on a client's behalf when delivering our services, including data accessed from that client's connected systems and data relating to their customers. In that second role the client is the controller: they determine why and how the data is processed, we act on their documented instructions, and questions from individuals about that data are properly directed to the client, whom we will assist.

03Definitions

"Personal Information" means information about an identifiable individual. "Client Data" means data a client provides or authorises us to access in order to deliver a service. "End User" means an individual who interacts with one of our clients through a service we operate for them, including a person who exchanges messages with that client. "Platform Data" means data we obtain from a third-party platform, such as Meta's WhatsApp Business Platform, on a client's authorisation.

04Information you give us directly

When you submit our contact form, email us, or speak with us about work, we receive what you choose to provide — typically your name, email address, phone number, company, and the details of your enquiry. If we go on to work together we also hold the contract and billing information needed to administer the relationship. We use this information to respond to you, to provide our services, and to meet our legal and accounting obligations.

05Information collected automatically on this website

Our hosting infrastructure records standard technical information such as IP address, browser type, referring page, and pages visited. This is used to keep the site secure and to understand aggregate traffic. We do not use it to build advertising profiles, and we do not run third-party advertising trackers on this site.

06Cookies

We use only the cookies necessary to operate the site and remember basic preferences. We do not use advertising cookies. If we introduce analytics or other non-essential cookies in future, we will request consent before setting them and update this policy.

07Data we process on behalf of clients

When a client connects a system to one of our services — a CRM, a mailbox, a calendar, a document store, or a messaging account — we access only what is needed to deliver the agreed functionality. Depending on the service this can include contact records, message and email content, calendar entries, attachments, and activity history, which may contain personal information about the client's own customers and contacts. We process this data solely to provide the service, under the client's instructions and the terms of their agreement with us. We do not use it for our own purposes, we do not share it with other customers, and we do not sell it.

08Business messaging platforms

Where a client instructs us to operate business messaging on their behalf — including through the WhatsApp Business Platform operated by Meta Platforms, Inc., and comparable channels such as SMS or email — we process the data required to send, receive, and manage those conversations. This typically includes the recipient's phone number or address, the display name made available by the platform, message content and any attachments, message templates, and delivery, read, and error metadata. We use this data only to deliver the messaging service the client has asked for and to support, secure, troubleshoot, and bill for it. We do not use it for advertising, we do not build profiles from it, we do not sell or rent it, and we do not disclose it to anyone other than the client, the platform provider as required to deliver the message, and service providers acting on our behalf. Our handling of data obtained from these platforms also follows the platform provider's own terms, including Meta's Platform Terms and Developer Policies where the WhatsApp Business Platform is involved, and we honour any deletion or restriction requirement those terms impose.

10Artificial intelligence and automated processing

Some of our products use large language models to summarise information and draft communications. Where this happens, data is processed only to produce output for the client who supplied it. We do not use Client Data or Platform Data to train general-purpose or foundation models, and we do not permit our AI service providers to do so; where a provider's default terms would allow training on submitted data, we disable it or do not use that provider for this purpose. AI-generated drafts are intended for human review before they are sent. We do not use automated processing to make decisions producing legal or similarly significant effects about individuals.

11How we use information

We use personal information to respond to enquiries; to provide, support, secure, and improve our services and products; to operate messaging and automation on our clients' instructions; to administer contracts, invoicing, and accounts; to comply with legal, tax, and regulatory obligations; and to establish, exercise, or defend legal claims. We do not sell personal information, we do not rent it, and we do not disclose it for anyone else's independent marketing purposes.

13Sharing and sub-processors

We share personal information only where necessary: with service providers who help us operate, such as cloud hosting, email delivery, error monitoring, AI model providers, and business and accounting systems; with third-party platforms, such as Meta, strictly to the extent needed to deliver a message or integration a client has instructed; with professional advisers under duty of confidence; with a successor in the event of a merger, acquisition, or asset sale, subject to this policy continuing to apply; and where disclosure is required by law or to protect rights and safety. Service providers are bound by contract to protect the information and may not use it for their own purposes. A current list of sub-processors used for a given service is available to that service's clients on request, and we give clients advance notice of material changes.

14International transfers

We and our service providers may store or process information in Canada, the United States, and other jurisdictions. Information stored outside Canada may be accessible to courts and authorities in the host jurisdiction under that jurisdiction's laws. Where information is transferred outside its country of origin we take reasonable steps to ensure it remains protected under comparable standards, including contractual protections such as standard contractual clauses where required.

15Retention

We keep personal information only as long as necessary for the purpose it was collected for, or as required by law. Enquiries that do not lead to an engagement are periodically removed. Contract, billing, and tax records are retained for the period required by Canadian law. Client Data and Platform Data are retained for the period agreed with the client and are deleted or returned on termination in accordance with our Data Deletion Policy. Message content and delivery metadata are retained only as long as needed to deliver, support, and account for the service, or for the shorter period a client specifies or a platform provider requires.

16Deleting your information

You can ask us to delete personal information we hold about you. Our Data Deletion Policy explains exactly what can be deleted, how to make a request, how long it takes, and what happens to backups and to data held on a client's behalf. Requests can be sent to [email protected]. Clients may also delete Client Data through the controls we provide, and may revoke any system or platform connection at any time, which stops further access immediately.

17Security

We apply access controls on a least-privilege basis, encryption in transit and, where appropriate, at rest, credential and secret management, environment separation, logging and monitoring, and regular review of access. Access to Client Data and Platform Data is restricted to personnel who need it to deliver or support a service and is subject to confidentiality obligations. No system is perfectly secure, but we take this seriously and will notify affected individuals, clients, regulators, and platform providers of any breach within the timeframes required by law and by our contracts.

18Your rights

Subject to applicable law you may request access to the personal information we hold about you, ask us to correct or delete it, object to or ask us to restrict certain processing, request a copy in a portable format, and withdraw consent where processing is based on consent. Under Canadian privacy legislation, including PIPEDA, you also have the right to complain to the Office of the Privacy Commissioner of Canada. Where the GDPR applies you may complain to your local supervisory authority. Send requests to [email protected]; we will verify your identity and respond within thirty days, or sooner where the law requires.

19If you are a customer of one of our clients

If you were contacted by, or hold an account with, a business that uses our software, that business is the controller of your information and decides how it is used. Please direct access, correction, deletion, and opt-out requests to them. If you contact us instead we will forward your request to the relevant client and support them in responding, and we will act on their instruction. We can also confirm whether we hold data relating to you on a client's behalf.

20Children

Our website, products, and services are directed to businesses and are not intended for children. We do not knowingly collect personal information from anyone under the age of majority in their jurisdiction. If we learn we have done so, we will delete it.

21Changes to this policy

We may update this policy as our practices, products, and obligations evolve. The effective date at the top of this page reflects the current version. Material changes will be highlighted here and, where they affect an active engagement, communicated to the client directly.

22Contact

For any privacy question, request, or complaint, contact our privacy contact at [email protected], or write to Hubify Solutions Inc. at the mailing address on our contact page. We respond to every request and will tell you the outcome and the reasons for it.

Hubify Solutions Inc. · Coquitlam, British Columbia, Canada · [email protected]