HUB3 Data Processing Agreement
Version: 1 · Effective from: 18 July 2026
The Dutch-language version of this Data Processing Agreement ("Verwerkersovereenkomst") is the authentic and governing version. This English translation is provided for convenience only; in case of any discrepancy, the Dutch text prevails.
⚠️ Not yet legally validated. This text has been prepared as a basis for review by a Belgian lawyer and/or DPO. See the review points in
README.md.
1. Parties and subject matter
1.1. This Data Processing Agreement (the "DPA") is entered into between:
- the Organiser — the studio, teacher or independent provider using the HUB3 platform for its membership administration and services, hereinafter the "Controller"; and
- HUB3 — Dries Verstreepen, Stallestraat 290b bus62, 1180 Ukkel, enterprise number 0677955962, hereinafter the "Processor".
1.2. This DPA forms an integral part of HUB3's Terms of Service (the "Terms") and implements Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). It applies as soon as the Organiser uses the Platform to process personal data.
1.3. Capitalised terms used in this DPA and not defined here have the meaning given to them in the Terms. The terms "personal data", "processing", "data subject", "personal data breach" and "sub-processor" have the meaning given to them in the GDPR.
1.4. In the event of a conflict between this DPA and the Terms, this DPA prevails in respect of the processing of personal data.
2. Allocation of roles
2.1. HUB3 as Processor. For the personal data the Organiser processes through the Platform in the context of its own membership administration and services, the Organiser is the controller and HUB3 processes that data solely on behalf of and on the instructions of the Organiser.
2.2. HUB3 as controller. For the processing HUB3 carries out for its own purposes — including creating and managing user accounts, authentication, security and fraud prevention, invoicing and accounting, measuring and improving the Platform, managing HUB3 Credits and the affiliate programme, and its own communications with users — HUB3 acts as an independent controller. Those processing activities fall outside this DPA and are governed by HUB3's Privacy Policy.
2.3. Separate relationship with the Member. A Member who creates a HUB3 account also enters into a separate relationship with HUB3. HUB3 is the controller for that account data. The same data point may therefore fall under the Organiser's responsibility in one context and under HUB3's in another.
3. Subject matter, nature and duration of the processing
3.1. Nature and purpose. HUB3 processes the personal data solely in order to make the Platform available and to deliver the related services to the Organiser: hosting and storing data, managing members and enrolments, recording attendance, facilitating payments, sending messages on the Organiser's instructions, generating reports and exports, and providing support.
3.2. Duration. The processing continues for as long as the Organiser uses the Platform and ends in accordance with Section 11.
3.3. Categories of data subjects. Including: members and dancers; parents, guardians or legal representatives of underage members; teachers and staff of the Organiser; contacts and prospects.
3.4. Categories of personal data. Including:
- identification and contact details (name, email address, telephone number, address, date of birth);
- account data and roles within the studio;
- enrolment, attendance and participation data;
- payment and transaction data (excluding full card details, which remain with Stripe);
- data from enrolment forms composed by the Organiser itself;
- evaluations, assessments and progress information;
- photographs and imagery, to the extent uploaded by the Organiser;
- communications between the Organiser and its members through the Platform.
3.5. Special categories. The Platform offers functionality allowing the Organiser to maintain a care record or participant file. This may include health-related data (for example injuries, allergies, medication, points of attention or emergency contact information). These are special categories of personal data within the meaning of Article 9 GDPR. The Organiser:
- decides whether to use this functionality and what data to include in it;
- warrants that it has a valid legal basis within the meaning of Article 9(2) GDPR (typically explicit consent) and that it can demonstrate this;
- limits itself to what is necessary and informs data subjects properly;
- takes account of the fact that this data is accessible to the persons it has authorised within its studio.
HUB3 applies to this data the same and, where possible, additional technical and organisational measures as described in Section 6.
3.6. Minors. A significant proportion of data subjects may be minors. The Organiser is responsible for ensuring a valid legal basis and, where required, the consent or authorisation of the parent or legal guardian.
4. Instructions
4.1. HUB3 processes the personal data solely on the documented instructions of the Organiser, unless required to process by law. In the latter case, HUB3 informs the Organiser in advance, unless that law prohibits this on important grounds of public interest.
4.2. The Terms, this DPA and the Organiser's normal use of the Platform's features constitute the Organiser's complete instructions.
4.3. HUB3 informs the Organiser where, in its view, an instruction infringes the GDPR or other applicable data protection law. HUB3 may suspend performance of such an instruction.
4.4. HUB3 does not sell the personal data, does not use it for its own advertising purposes and does not enrich profiles with it beyond delivery of the Service. Where HUB3 uses data to improve the Platform, it does so in aggregated or anonymised form.
5. Confidentiality
5.1. HUB3 ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.2. Access is limited to those persons for whom such access is necessary for the delivery of the Service, in accordance with Section 30 of the Terms.
6. Security
6.1. HUB3 implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures include:
- encryption of data in transit (TLS) and encryption of data at rest with the hosting partner;
- user authentication and role-based access rights management;
- access restrictions at database level, so that users in principle only see the data of the studios to which they belong;
- logging of administrator actions;
- separate development and production environments;
- periodic back-ups and recovery procedures;
- secure payment processing via Stripe, with HUB3 not storing full card details.
6.2. HUB3 reviews these measures periodically and may adapt them, provided the level of protection is not reduced.
6.3. The Organiser implements appropriate measures within its own organisation, including: carefully managing user accounts and roles within its studio, immediately revoking access of departed staff, using strong and unique passwords, and securing its own equipment and exports.
7. Sub-processors
7.1. The Organiser grants HUB3 general authorisation to engage sub-processors for the delivery of the Service.
7.2. As at the date of this DPA, HUB3 uses the following sub-processors, among others:
| Sub-processor | Service | Data processed |
|---|---|---|
| Supabase | database, storage and authentication | all platform data |
| Vercel | application hosting and platform analytics | technical and log data |
| Stripe | payment processing and payouts | payment and transaction data |
| Resend | sending emails on behalf of Organisers and the Platform | email addresses and message content |
[List to be confirmed and kept current; processing and hosting regions per provider to be confirmed and aligned with Section 7 of the Privacy Policy.]
7.3. HUB3 imposes on each sub-processor, by contract, obligations no less onerous than those set out in this DPA. HUB3 remains fully liable to the Organiser for its sub-processors' compliance.
7.4. HUB3 informs the Organiser of intended changes to the list of sub-processors at least thirty (30) days before the change takes effect, via the Platform or by email. The Organiser may object on reasoned data protection grounds within that period. If the parties cannot reach a solution, the Organiser may cancel its Subscription in accordance with Section 11.4 of the Terms, without charge for the remaining period.
8. Transfers outside the EEA
8.1. HUB3 transfers personal data to a country outside the European Economic Area only where a valid mechanism exists, such as an adequacy decision of the European Commission or the standard contractual clauses (SCCs), supplemented by any necessary additional measures.
8.2. [The actual processing and hosting regions of the sub-processors listed in Section 7.2 to be confirmed, and the applicable transfer mechanism per provider to be documented.]
9. Assistance to the Organiser
9.1. Data subject rights. Taking into account the nature of the processing, HUB3 assists the Organiser in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). The Platform provides features allowing the Organiser to view, amend, export and delete data itself.
9.2. Where HUB3 receives a request directly from a data subject that relates to processing for which the Organiser is responsible, HUB3 does not respond substantively but refers the data subject to the Organiser and informs the Organiser without undue delay.
9.3. Other assistance. HUB3 provides the Organiser with reasonable assistance in complying with its obligations under Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to HUB3.
9.4. HUB3 may charge a reasonable fee for assistance that substantially exceeds normal service provision, subject to the Organiser's prior agreement.
10. Personal data breaches
10.1. HUB3 notifies the Organiser without undue delay, and in any event within forty-eight (48) hours of becoming aware of it, of a personal data breach affecting the Organiser's data.
10.2. The notification contains, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and contact details for further information. Missing information is provided in phases.
10.3. As controller, the Organiser assesses whether the breach must be notified to the supervisory authority and/or to data subjects, and is responsible for those notifications. HUB3 provides reasonable assistance.
10.4. HUB3 takes reasonable measures to limit and remedy the consequences of a breach, and documents every breach.
11. Return and deletion
11.1. On the end of the provision of services, HUB3 deletes or returns the personal data, at the Organiser's choice, and deletes existing copies, unless retention is required by law.
11.2. Export before termination. The Organiser may export its data at any time during the term of the Subscription using the Platform's export features. The Organiser is responsible for carrying out that export in good time.
11.3. Deletion of a studio. Where the Organiser deletes its studio through the Platform, the associated data is deleted immediately and irreversibly, in accordance with Section 23.6 of the Terms. In that case there is no recovery period and HUB3 can no longer make the data available.
11.4. Back-ups. After deletion, data may remain present in back-ups for a limited period, until overwritten in accordance with the usual back-up cycle. While that is the case, it remains subject to this DPA and is not actively processed.
11.5. HUB3 may retain certain data for longer to the extent required by law, in particular transaction and accounting data, or for the establishment, exercise or defence of legal claims.
12. Audit and information
12.1. On request, HUB3 makes available to the Organiser the information necessary to demonstrate compliance with Article 28 GDPR.
12.2. The Organiser may, no more than once per calendar year and subject to reasonable prior notice of at least thirty (30) days, carry out or contribute to an audit. An audit takes place during business hours, does not unnecessarily disrupt HUB3's operations and is subject to confidentiality. The costs of the audit are borne by the Organiser, unless the audit reveals a material failure by HUB3.
12.3. HUB3 may satisfy an audit request by providing a recent report or certificate from an independent third party, where this reasonably covers the information requested.
12.4. An additional audit is possible following a personal data breach or at the request of a supervisory authority.
13. Liability
13.1. Each party's liability under this DPA is governed by Section 25 of the Terms, without prejudice to the mandatory provisions of Article 82 GDPR in relation to data subjects.
13.2. The Organiser indemnifies HUB3 against claims by data subjects, third parties or supervisory authorities arising from processing for which the Organiser is responsible and which cannot be attributed to HUB3, in accordance with Section 26 of the Terms.
14. Final provisions
14.1. This DPA may be amended in accordance with Section 32 of the Terms, and will in any event be adapted where legislation or a decision of a supervisory authority so requires.
14.2. This DPA is governed by Belgian law. Disputes are resolved in accordance with Section 38 of the Terms.
14.3. The supervisory authority is the Belgian Data Protection Authority (Drukpersstraat 35, 1000 Brussels — gegevensbeschermingsautoriteit.be).
Contact: info@hub3.be