Privacy Policy (v2)

Effective from: 3 August 2026

HUB3 Privacy Policy

Version: 2 · Effective from: 3 August 2026

The Dutch-language version of this Privacy Policy ("Privacybeleid") is the authentic and governing version. This English translation is provided for convenience only; in case of any discrepancy, the Dutch text prevails. This policy should be read together with the Terms of Service, the Cookie Policy and, for Organisers, the Data Processing Agreement.

1. Introduction

HUB3 values the protection of your personal data and respects your privacy. This Privacy Policy explains how we collect, use, store and share your data when you use the HUB3 platform, in accordance with the General Data Protection Regulation (GDPR) and Belgian data protection law.

2. Who we are

The HUB3 platform is provided by Dries Verstreepen, with registered office at Stallestraat 290b bus62, 1180 Ukkel, registered with the Belgian Crossroads Bank for Enterprises under number 0677955962, VAT BE0677955962 ("HUB3", "we", "us", "our").

  • Privacy contact: info@hub3.be (subject: "Privacy")
  • Data Protection Officer (DPO): not appointed. Given the nature and scale of the processing, this is not currently legally required (Art. 37 GDPR). This will be reassessed if processing expands, in particular in the case of large-scale processing of health data through care records.

HUB3 connects dancers, participants, parents or guardians, Organisers, studios, teachers and independent providers. HUB3 acts as a platform provider. Unless expressly stated otherwise, HUB3 is not the provider of the classes, events, memberships or services offered by Organisers on the platform.

3. Our role: when controller, when processor

HUB3 has two distinct roles, depending on which data is involved. This matters, because it determines where you should direct your questions and requests.

3.1 HUB3 as controller

For data we process for our own purposes, we are the controller. This covers: creating and managing your account, authentication, security and fraud prevention, invoicing and accounting, measuring and improving the platform, managing HUB3 Credits and the affiliate programme, and our own communications with you.

For that processing, this Privacy Policy applies and you can exercise your rights directly with us (Section 13).

3.2 HUB3 as processor

When an Organiser uses the platform for its own membership administration and services — member profiles, enrolments, attendance, evaluations, forms and records — that Organiser is the controller and HUB3 acts as a processor within the meaning of Article 28 GDPR. We then process that data solely on the Organiser's instructions and in order to deliver the platform.

Those arrangements are set out in the Data Processing Agreement.

What this means for you as a member. If your question concerns your membership, your enrolment, your evaluation or your care record at a particular studio, address it to that studio in the first instance. If it concerns your HUB3 account itself, you can come to us. If you are unsure, contact us anyway — we will point you in the right direction.

3.3 Each on their own account

For some processing, HUB3 and the Organiser each act as an independent controller, each for their own purposes. An Organiser may, for example, keep enrolment, accounting or insurance records separately from HUB3 for its own legal obligations. Each party is then responsible for that processing itself.

4. What data we collect

4.1 Data you provide

We collect personal data when you: create an account; complete or update your profile; enrol in programmes, classes, workshops, camps or events; create or manage an Organiser or studio profile; make purchases or payments; contact support; submit forms, feedback or requests; accept or confirm legal documents; or activate or use affiliate, referral or HUB3 Credits features.

This may include: name and email address; telephone number; date of birth; profile information (such as photo, bio, preferences or account settings); emergency contact details; parent or guardian information where relevant; enrolment, attendance and purchase information; payment-related information; studio or Organiser information; and support messages and communication history.

Payment card details are processed by Stripe. HUB3 does not store full payment card details.

4.2 Care records and health-related information

HUB3 allows users, parents, guardians or Organisers to share information through a care record or participant file. This may include sensitive or health-related data, such as: allergies; injuries or physical limitations; mental health information; medication; emergency instructions; and notes relevant to safe participation. An Organiser may additionally add its own studio notes to a record.

This is a special category of personal data (Art. 9 GDPR).

How access is arranged. A studio only gains access to a care record where an explicit, non-withdrawn consent exists for that enrolment, and that access expires automatically when the programme ends. Access is limited to studio administrators; teachers see only the studio notes.

What we do not do. We do not currently maintain an access log recording who has viewed a care record. Nor is a care record automatically deleted when you withdraw your consent or when the programme ends — in those cases the studio's access lapses, but the record itself continues to exist until deleted. If you want it actually erased, request this under Section 13.

Absence documentation. Where you substantiate an absence with a document (for example a doctor's note), it is stored in a protected storage area accessible only through temporary, personal links. This too may contain health data.

4.3 Automatically collected data

When you use HUB3, we may collect: IP address; device and browser information; log data; pages visited; clicks, interactions and usage data; session, security and authentication data; and technical error and performance data.

4.4 Visit and usage statistics

We record which pages are visited. In doing so we process:

  • Aggregate visit counts per page and per day, not linked to you personally.
  • Platform visit notifications to our administrators. For these we process a pseudonym derived from your IP address and browser details (or, if you are signed in, your user ID), the device type, and a city-level location we receive from our hosting provider. Your exact IP address is not retained, but the derived value is still personal data.
  • Visits to public studio pages. After you consent to analytics, the web app uses a first-party, HttpOnly visitor cookie (hub3_anon_visitor) valid for one year. The mobile app uses a random installation pseudonym in protected local storage. HUB3 stores a server-side pseudonym so a studio can count visits and unique visitors. If you are signed in, the visit is linked to your account instead.
  • Interactions with programmes, such as which programmes you open, in order to show recommendations and overviews.

More about cookies can be found in the Cookie Policy.

4.5 Messages and content you create

The platform includes chat features per programme and per team, polls, announcements, notes and forms. The content you place there — messages, answers, votes and attachments — is stored and visible to the other participants of that chat or group, and to the studio concerned.

Messages are not automatically deleted when a programme ends. A studio can manually clear a programme chat.

To prevent abuse, we check new chat content using automated, rules-based safety filters. Users can report a message and block its sender. When a report is submitted, we retain the reported message, selected reason, any additional explanation, the account IDs involved, and the status and internal notes of the follow-up. The reported user is not told who submitted the report. Reports are accessible only to authorised HUB3 administrators and are used for safety, abuse prevention, dispute handling and enforcing our terms. A personal block hides messages from the blocked user for the blocking user; it does not remove the underlying messages for other participants.

4.6 Photos and uploaded imagery

Profile photos, participant photos, programme imagery and studio logos are stored in storage areas configured such that a file is retrievable by anyone who knows the exact link, even without signing in. The links are not guessable and are not published publicly, but they are not protected by authentication. Bear this in mind when uploading photos, including when you as a parent add a photo of your child to a participant profile.

Absence documentation (Section 4.2) is an exception: those files are protected.

4.7 Push notifications

If you consent to push notifications, we store your device's technical address (the "endpoint"), the associated keys, your user ID and the description of your browser or device. You can disable push notifications at any time through your browser or device settings; the stored registration is removed once it is no longer usable.

4.8 Affiliate and HUB3 Credits data

If you activate the affiliate programme, we may process data about your affiliate profile, including: user ID; activation status; personal referral code or link; referred studio registrations; referral status and reward eligibility; HUB3 Credits balance; ledger entries; redemptions; and checkout data showing whether HUB3 Credits were used.

When a studio registers via an affiliate link, we also process data about that studio: the referral code, the studio ID, the contact email address, the enterprise number and the VAT number, and indicators to detect duplicates and fraud. That data is stored with the referring user's referral record, which they do not see in full themselves.

We use this information to verify referrals, prevent duplicate or fraudulent rewards, grant HUB3 Credits, maintain accurate credit records and operate the affiliate programme. HUB3 Credits are internal platform credit and not a cash payout.

4.9 Feedback and support

You can report feedback or a problem through the platform. Those reports contain a free-text field and the location in the app where you submitted them, and can also be sent without signing in. Do not include data you would rather not share: the reports are readable by our administrators.

4.10 Records of legal consent and administrative actions

We record when you accept, confirm or re-accept current legal documents (such as the Terms of Service, this Privacy Policy or other policy documents). This may include: user ID; document type; document version; time of acceptance; and related technical metadata where necessary for audit, compliance, security or dispute handling.

We also keep a log of certain administrative actions on the platform (for example deactivating or deleting an account), recording who performed the action, which account it concerned and when.

4.11 Feature flags, App Modes, testing and early access

HUB3 may use feature flags, App Modes, allowlists and testing/early-access settings to determine which features are available. In doing so we may process related technical and account data (user ID, studio ID, role/permission level, feature access status, App Mode, testing/early-access status and usage interactions) in order to operate HUB3, test features, manage access, prevent misuse, provide support and maintain stability and security.

4.12 Data we receive from others

In certain cases we receive personal data not directly from you but from another source, such as: an Organiser enrolling you or entering participant details; a parent or guardian providing a minor's data; or a user referring you through the affiliate programme. We process that data in accordance with this policy.

4.13 Do you have to provide your data?

Some data is required to use HUB3: without a name, email address and password we cannot create an account, and without enrolment details an Organiser cannot process your enrolment. If you do not provide these, we cannot perform the agreement.

Other data is entirely optional — for example a profile photo, a bio, or the information in a care record. You can use HUB3 without providing these; some features will then work in a more limited way, or an Organiser may not be able to offer you the support you would otherwise be entitled to.

Payment, accounting and tax data is processed on the basis of a legal obligation.

5. How we use your data

We use your data to: provide and operate HUB3; create, manage, suspend, deactivate, reactivate and secure accounts; process enrolments, bookings, purchases, payments and refunds; facilitate communication between users and Organisers; share necessary enrolment and participant information with Organisers; send service-related notifications; provide support; improve functionality, performance and user experience; measure use of the platform; manage feature access, App Modes, testing, beta, early access and maintenance; operate the affiliate programme and HUB3 Credits; verify referred studio registrations and prevent duplicate or fraudulent referrals; maintain credit balances, ledger entries and checkout records; record acceptance of legal documents; prevent fraud, misuse, unauthorised access and security incidents; handle disputes, enforcement and legal claims; comply with legal, tax, accounting and regulatory obligations; and process care record and health data where necessary for safe participation, participant support, emergencies, safeguarding and communication with Organisers.

6. Legal basis for processing

We process personal data on one or more of the following legal bases (Art. 6 GDPR):

  • Contract (Art. 6(1)(b)): to provide HUB3, manage accounts, process enrolments and purchases, make checkout work, provide support and deliver requested features.
  • Legal obligation (Art. 6(1)(c)): for tax, accounting, regulatory, consumer protection and data protection obligations.
  • Legitimate interests (Art. 6(1)(f)): for security, fraud prevention, account management, operational continuity, feature access management, product improvement, misuse prevention, dispute handling, legal claims, measuring use of the platform and maintaining accurate platform records.
  • Consent (Art. 6(1)(a)): where required, such as for push notifications, certain marketing communications and non-essential cookies/analytics (see the Cookie Policy). You may withdraw consent at any time.

For special categories (including health-related care record data) we rely on an applicable exception under Art. 9 GDPR, in particular: your explicit consent (Art. 9(2)(a)); the protection of vital interests in emergencies (Art. 9(2)(c)); or the establishment, exercise or defence of a legal claim (Art. 9(2)(f)). Where the Organiser is the controller (Section 3.2), it is for the Organiser to secure that legal basis.

For the affiliate programme and HUB3 Credits we rely on contract (for the features you choose to use), legitimate interests (fraud prevention, platform integrity, accounting) and legal obligation (retaining records for tax/accounting purposes). For records of legal consent we rely on legal obligation, legitimate interests and contract.

7. Sharing of data

7.1 With Organisers

When you enrol through HUB3 in a programme, class, event, workshop, camp, membership or other service of an Organiser, your data is shared with that Organiser. This may include: your name; contact details; enrolment information; participant profile; parent or guardian information where relevant; attendance or booking information; payment or purchase status; and emergency contact details where relevant.

Where a care record or health-related information is shared for a participant, this happens within the limits described in Section 4.2.

For that data the Organiser is the controller and HUB3 is the processor (Section 3.2). Organisers are responsible for the proper use of this information and for complying with their own obligations under data protection law.

7.2 With service providers (processors)

We share data with service providers who help us operate HUB3:

Service provider Purpose Data involved
Supabase database, storage and authentication all platform data
Vercel application hosting and usage statistics technical data, log data, derived city-level location
Stripe payment processing, payouts and Organiser identity verification payment and transaction data; for Organisers also identity and verification data (KYC)
Resend sending emails, including when an Organiser writes to its members email addresses and the content of those messages
DeepL automatic translation of the user interface see below
Browser vendors' push services (Google, Apple, Mozilla) delivering push notifications your device's technical address and the notification content

About automatic translation. If you use HUB3 in a language other than Dutch, the interface text is sent to DeepL for translation. We deliberately exclude the parts that display personal content — chat messages, notes, care records, evaluations, form submissions and member lists are not translated and are therefore not sent to DeepL. Translations are stored by us and in your browser to avoid repeated traffic.

These service providers may process personal data only to the extent necessary to deliver their services to HUB3, and must protect that data in accordance with applicable law, where relevant under a data processing agreement pursuant to Art. 28 GDPR.

7.3 Payments and Stripe

Payments are processed through Stripe. HUB3 does not store full payment card details. On a payment, Stripe may process payment, billing, fraud prevention and transaction data. Where HUB3 Credits are used, HUB3 may store the credit amount applied, the remaining amount payable, transaction fees, payment status and related checkout metadata. If no external payment is needed after applying HUB3 Credits, the transaction may be settled internally without sending card details to Stripe.

Organisers wishing to receive payments complete a verification procedure with Stripe, providing identity and business details directly to Stripe. Please consult Stripe's privacy policy for more information.

7.4 Legal obligations and protection

We may disclose data where legally required, on the basis of legal proceedings or a request from an authority, or where necessary to protect rights, safety, security, users, Organisers, HUB3 or the public, or to prevent fraud, misuse, unauthorised access, payment disputes or abuse of the platform.

7.5 Business transfers

If HUB3 is involved in a merger, acquisition, financing, restructuring, sale or transfer of assets, your data may be transferred as part of that transaction, with appropriate safeguards.

8. Access by HUB3 staff

Authorised HUB3 staff may access data entered through the platform, including personal data. Such access is limited to what is necessary for support and troubleshooting, security and fraud prevention, operational continuity, complying with legal obligations, and handling reports and complaints.

The number of people with such access is limited and they are bound by a duty of confidentiality. Where HUB3 acts as a processor (Section 3.2), such access takes place within the instructions of the Organiser concerned and in accordance with the Data Processing Agreement.

9. International transfers

Your data is processed primarily within the European Economic Area (EEA):

  • Supabase — the HUB3 database runs in the eu-west-1 (Ireland) region, within the EEA.
  • DeepL — established in Germany, within the EEA.
  • Stripe — processes data partly outside the EEA, on the basis of the European Commission's standard contractual clauses (SCCs).
  • Browser vendors' push services — depending on your browser and device, these may be established outside the EEA.
  • Vercel — [hosting region to be confirmed before publication: the project does not currently pin a region, so the account default applies. If that is a region outside the EEA, the transfer mechanism (SCCs) must be stated here.]

Where data is processed outside the EEA, we use appropriate safeguards such as the European Commission's standard contractual clauses or another legally recognised transfer mechanism.

10. Retention periods

We do not retain personal data longer than necessary for the purposes described in this policy, including providing HUB3, security, fraud prevention, compliance with legal obligations, dispute resolution and enforcement.

Deactivation and deletion of your account. If you request deletion or use a self-service deletion feature, your account is first deactivated rather than immediately permanently deleted. During deactivation, access is disabled and account data is retained for up to 90 days for the purposes of operational recovery, reactivation, fraud prevention, security, dispute handling and compliance with legal or accounting obligations. If you request reactivation within that period, we can restore access. After the period expires, we permanently delete the account, unless further retention is legally required or necessary for the establishment, exercise or defence of a legal claim.

Deactivation may be refused while you still have active enrolments; complete those first or contact the Organiser concerned.

Studio emails. For an Organiser's email campaigns, we retain the full campaign content, sender and recipient snapshot, and technical delivery statuses for no more than 12 months after creation. We then automatically erase or anonymise the subject, message content and personal data in the delivery history; only anonymised totals, message type, language and dispatch date remain. Evidence of marketing consent and unsubscribe events is outside this automatic clean-up and is retained separately for as long as reasonably necessary to demonstrate that consent was validly obtained or withdrawn and in accordance with applicable statutory retention duties.

Data that persists as long as your account or the studio exists. We would rather be honest here than reassuring: for the following data there is currently no automatic clean-up. It is retained until the account or the studio is deleted, or until you ask us to erase it:

  • chat messages, polls, notes and announcements;
  • visit and usage statistics and interactions with programmes;
  • notifications and push registrations;
  • care records (see Section 4.2);
  • feedback reports;
  • the log of administrative actions.

We are reviewing this and will introduce concrete retention periods; until then you can request deletion under Section 13.

Data we retain longer. Certain data is retained longer where legally required or permitted, including: payment, tax and accounting records (in Belgium typically 7 years); refund and dispute records; affiliate and referral records; the HUB3 Credits ledger and redemptions; fraud prevention and security records; audit and legal consent records; and evidentiary records relating to disputes, complaints, misuse or legal claims.

After deletion, data may remain present in back-ups for a limited period, until overwritten in accordance with the usual cycle. It is no longer actively used at that point.

If an Organiser deletes its studio, the associated data is deleted immediately and irreversibly (see Section 23.6 of the Terms of Service).

11. Security

We use secure infrastructure and reasonable technical and organisational measures to protect personal data, including: encryption in transit and at rest where applicable; access controls at database level, so that users in principle only see the data of the studios to which they belong; authentication and authorisation controls; logging of administrative actions; separate development and production environments; back-ups and operational safeguards; and processes for security review and misuse prevention.

No system can guarantee absolute security; we continue to improve our measures. See also Section 4.6 on the accessibility of uploaded photos.

12. Automated decision-making and profiling

HUB3 does not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.

However, some features do operate automatically, without human intervention:

  • Affiliate rewards are granted automatically where the conditions are met. If a referral is identified as a duplicate or a self-referral, the reward is automatically refused. You do not currently receive a separate notice of this. If you believe a refusal is incorrect, you can raise it at info@hub3.be and we will review it manually.
  • Waitlists and capacity: whether you can enrol immediately, join a waitlist or move up is determined automatically on the basis of available places and the Organiser's settings.
  • Duplicate enrolments are automatically blocked.
  • Deactivation of your account is automatically blocked while you have active enrolments.

We also use automated processing for security, fraud prevention and the ranking of offerings. How that ranking works is described in Section 21 of the Terms of Service.

13. Your rights

If you are located in the EEA, the United Kingdom or another jurisdiction with comparable rights, you may have the right to: access your personal data; correct inaccurate data; request erasure; restrict processing; object to processing; request data portability; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority.

These rights are not absolute and may be subject to statutory exceptions, including where data must be retained for legal, tax, accounting, fraud prevention, security, dispute or evidentiary reasons.

Where to address your request. If it concerns data for which an Organiser is responsible (Section 3.2), address it to that Organiser. For your HUB3 account you can come to us. If we receive a request that belongs with an Organiser, we will refer you and notify the Organiser.

There is currently no self-service feature to download all of your data in one go. If you request a copy of your data, we will compile it and provide it within the statutory period.

To exercise your rights, contact us at info@hub3.be. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels, contact@apd-gba.bewww.gegevensbeschermingsautoriteit.be.

14. Children and minors

HUB3 may be used by minors. Where a minor uses HUB3, a parent or legal guardian may be responsible for creating or managing the account, providing the required consent, supervising use and managing enrolments, purchases and communications.

In Belgium, the age for valid consent to information society services is 13 (Art. 7 of the Act of 30 July 2018); below that age, parental or guardian consent is required. The contractual age limit for entering into agreements yourself through HUB3 is 18 (see the Terms of Service). We do not knowingly collect personal data from minors without the appropriate involvement or consent where the law requires it.

If, as a parent, you add a photo to your child's profile, please read Section 4.6 on how uploaded photos are accessible.

15. Direct marketing and communications

We may send service-related communications necessary for the operation of HUB3 (account, enrolment, payment, security or legal messages). We send marketing communications in accordance with applicable law; where required, on the basis of your consent. You may unsubscribe from marketing at any time. Service-related communications may still be sent if you have unsubscribed from marketing.

Messages from Organisers. Organisers may write to you through the platform about their classes and activities. They determine the content and the recipients; HUB3 only handles the technical delivery. If you wish to receive news or promotions, the Organiser asks for a separate, Organiser-specific choice that is not pre-ticked. An Organiser may also record demonstrable consent obtained elsewhere, including its date, source and an evidence note. Every marketing email contains a one-click unsubscribe link; the unsubscribe takes effect immediately for that Organiser's marketing. It does not block practical messages connected to a demonstrable active relationship, such as an ongoing enrolment. The Organiser remains your first point of contact for questions about content or legal basis; HUB3 provides technical delivery and preference recording as processor.

16. Testing, beta, early access and maintenance

HUB3 may operate in testing, beta, early access, sandbox, maintenance or other restricted-access modes. During these phases, features may change, be incomplete or unavailable, or be removed, and data may be incomplete, inaccurate, reset, migrated or deleted. Users should not treat test or beta data as permanent. Where such data contains personal data, we process it in accordance with this policy.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify users of material changes where appropriate. Where required, we may ask users to confirm the updated Privacy Policy or to re-accept the updated Terms of Service before continuing to use HUB3. Retention periods, processing purposes and feature descriptions may be updated where necessary to reflect legal, operational, security or platform requirements.

18. Contact

For privacy-related questions or requests:


Last updated: 3 August 2026