freehub · Legal

Privacy policy.

Version 1.0 · 11 July 2026 · Deutsche Version

freehub is a B2B project-reporting platform operated by Freelopers OÜ, Tornimäe tn 5, 10145 Tallinn, Estonia ("we"). Contact: serhat@freelopers.com. freehub is used by us and by partner agencies to report on client projects. It is not directed at consumers.

1. Roles

For user accounts (partner and team logins) we act as the data controller. For work content a partner agency brings into freehub (project cards, notes, meeting transcripts, items pulled from connected tools), the agency is the controller and we process on its behalf (Art. 28 GDPR — our data-processing agreement is ready to countersign).

2. What we process, and why

  • Account data — name, e-mail, salted password hash, session cookie. Purpose: authentication and attribution. Legal basis: contract (Art. 6(1)(b)).
  • Work content — project/card text and attached sources: notes, links, documents, meeting transcripts and, where an agency connects them, items from Trello/Asana and Google Drive/Gmail (read-only, per-user OAuth consent). Purpose: consolidated project reporting. Legal basis: performance of the agency's contract / legitimate interest (Art. 6(1)(b)/(f)).
  • Time entries — person, project, date, hours, optional note and task link. Purpose: effort reporting and billing. Access is minimized: team members see only their own entries; team-wide detail is restricted to named team leads and the administrator.
  • Technical data — server logs, an append-only audit trail of changes, rate-limit counters. Purpose: security, abuse prevention, accountability. Legal basis: legitimate interest (Art. 6(1)(f)).

3. Cookies

freehub sets only strictly necessary cookies: a signed session cookie (httpOnly, expiring) and a theme preference. No analytics, no advertising, no tracking — therefore no cookie banner is required.

4. AI processing

Some features send content you explicitly submit (a pasted note, a transcript, a question) to AI providers — Anthropic (classification, summaries, grounded Q&A) and OpenAI (semantic-search embeddings) — strictly to produce the requested output. These API providers do not use the data to train their models. AI runs only on explicit user actions, never in the background, and is rate-budgeted per person.

5. Subprocessors & international transfers

Our infrastructure runs in the EU by default: the database in Frankfurt (Supabase on AWS eu-central-1) and compute pinned to Frankfurt (Vercel, fra1). Where a provider is US-based (Vercel, Anthropic, OpenAI, Atlassian, Asana), transfers rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses under that provider's DPA. The maintained subprocessor list lives on our Trust page.

6. Retention

Account data lives for the account's lifetime; work content and time entries for the duration of the agency engagement (agencies can request deletion of their tenant at any time); audit events and logs are kept for security accountability and rotated. Backups follow the database provider's schedule and expire automatically.

7. Your rights

Under the GDPR you can request access, rectification, erasure, restriction, portability and object to processing (Art. 15–21), and lodge a complaint with a supervisory authority — in Estonia the Andmekaitse Inspektsioon (AKI), or the authority of your residence. For requests, e-mail serhat@freelopers.com — we answer within 30 days. If your data reached freehub through a partner agency, we will coordinate with that agency as its processor.

8. Security

TLS everywhere, tenant isolation enforced in the data layer and pinned by an automated test suite, encrypted credentials at rest (AES-256-GCM), hashed passwords and API tokens, 90-day token expiry, rate limits and audit logging. Details: Trust & Security.

9. Changes

This policy is versioned; material changes are announced to signed-in users. Current version: 1.0.

ImpressumTrust & Securityfreehub