Legal
Data Processing Agreement.
The UK GDPR Article 28 terms under which we process personal data on your organisation’s behalf. Part of every subscription — and readable on purpose.
What this is and how it applies
This is the Data Processing Agreement (DPA) between N Six Studios Ltd (company number 16428711, registered at 1364a London Road, Norbury, London, England, SW16 4DE) and each organisation that subscribes to N Six Hub. It exists because UK GDPR Article 28 requires a written agreement whenever one business processes personal data on another’s behalf — and because your own compliance depends on being able to show one.
It forms part of your subscription agreement automatically: it applies from the moment your organisation subscribes, and you don’t need to sign anything separately. If you need a countersigned copy for your records, email privacy@nsixhub.com and we’ll provide one. Like the rest of the subscription agreement, it’s governed by the laws of England and Wales.
Who is who
For the business data your organisation puts into N Six Hub — customer records, staff information, files, messages and everything else you create — your organisation is the controller and we are the processor. You decide what goes in and why; we process it to run the service for you.
For the small amount of data we hold for our own purposes — your billing relationship with us, and visits to our marketing website — we act as controller, and our Privacy Policy at nsixhub.com/legal/privacy covers that instead. N Six Studios Ltd is registered with the Information Commissioner's Office.
Subject matter, duration, nature and purpose
Subject matter: the personal data your organisation stores and handles in N Six Hub. Duration: the life of your subscription, plus the time needed to return or delete data afterwards. Nature and purpose: hosting, storing, displaying, transmitting, organising, analysing (where you invoke an AI feature) and deleting that data — in short, running the platform you subscribed to, and nothing else.
We don’t use your organisation’s data for our own purposes beyond running and safeguarding the service, we don’t sell it, and we don’t train AI models on it.
Types of data and who it’s about
Because you design your own modules, your organisation controls what personal data the platform holds. Typically that includes: names and contact details; account and profile data; employment and payroll data (including, for UK payroll, National Insurance numbers and tax codes); location data where you use field-staff features; messages, call recordings and transcripts; documents and images; and anything else your organisation chooses to store.
The people this data is about are typically your staff, your customers and clients, your suppliers, and anyone who submits one of your public forms.
The platform’s fields can hold special category data — a clinic storing patient notes is storing health data. If your organisation does that, you are responsible for having a lawful basis under Article 9; the platform gives you field-level sensitivity controls, but it can’t supply the legal basis for you.
Our instructions
We process your organisation’s data only on your documented instructions. This agreement, your subscription agreement, and the way your administrators configure and use the platform are those instructions. If a law we’re subject to requires us to process differently, we’ll tell you before we do — unless that law forbids us from telling you.
If an instruction looks to us like it would break data protection law, we’ll say so rather than quietly follow it.
Confidentiality and our staff
Everyone at N Six Studios Ltd who can access personal data is bound by confidentiality obligations. When our support staff need to access your workspace to help you, they do it through an audited impersonation mechanism: each support session is tied to a named member of our staff, time-limited, and logged.
Security
Connections to the platform are encrypted in transit with TLS. Passwords are hashed with Argon2id. Sign-in sessions use short-lived signed tokens, refresh tokens are stored only as hashes, and multi-factor authentication is available to every user.
Every request to the platform is scoped to your organisation based on its authentication token, and access inside your organisation is governed by role, record-level and field-level permissions — fields tagged as sensitive (financial, health, personal) are masked from users who haven’t been granted access to them.
Team chat message content is stored end-to-end encrypted, and chat attachments are encrypted on your device before upload. Credentials we hold for connected services — third-party access tokens, signing keys, connected-mailbox passwords — are encrypted with AES-256-GCM, and the platform refuses to start in production without its field-encryption key.
Consequential actions are written to audit trails, and your administrators can review record-level activity from inside the platform. Uploads are screened for malicious file types. Internal databases sit on internal-only networks with no public ports and authenticated access.
We improve these measures over time; changes will never materially reduce the overall level of protection.
Sub-processors
You give us general authorisation to use the sub-processors listed at nsixhub.com/legal/sub-processors. That page names every one — what it does, what data it receives, and where it processes it.
Before we add or replace a sub-processor, we’ll update that page and email the owner of every subscribed organisation, at least 30 days before the change takes effect. If you object on reasonable data-protection grounds and we can’t resolve the objection — by not routing your data to that sub-processor, or another fix — you may terminate the affected service or your subscription, and export your data first.
We only engage sub-processors bound by written terms imposing data protection obligations equivalent to this agreement, and we remain fully responsible to you for their performance.
International transfers
The platform itself is hosted in the United Kingdom. Some sub-processors process data in the EU — covered by the UK’s adequacy regulations, so no extra mechanism is needed — and five process data in the United States: OpenAI, Google, ElevenLabs, Stripe and Twilio. For those transfers the safeguard we rely on is the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, and we require it of each provider in its data-processing terms. The sub-processor list shows where each one processes.
Helping you with rights requests
When someone exercises a data protection right against your organisation — access, correction, erasure and the rest — the request is yours to answer, and we help. The platform includes an export of your organisation’s records you can run yourself — that export excludes stored files, chat and meeting data, and billing ledgers, each available separately — and an erasure function that anonymises a person’s account in place (name, contact details and profile cleared; sign-in permanently disabled), deletes their staff documents, notifications and registered devices, and ends their sessions. Operational records that referenced them keep only the anonymised identifier, and audit trails retain their own entries until they expire on their retention schedules.
If a request needs something the built-in tools don’t cover, email privacy@nsixhub.com and we’ll assist directly, taking into account the nature of the processing and the information available to us.
If something goes wrong
If we become aware of a personal data breach affecting your organisation’s data, we will notify your organisation’s owner without undue delay — and in any case within 72 hours of becoming aware. The notification will say what happened, what data and roughly how many people are involved so far as we then know, what we’re doing about it, and who to talk to. We won’t hold back an initial notification because the picture is incomplete; we’ll tell you what we know and follow up as we learn more.
Deciding whether to report to the Information Commissioner's Office or to affected individuals is your call as controller; we’ll give you what you need to make it within your own 72-hour window. Where you need help with a data protection impact assessment, or a prior consultation with the Information Commissioner's Office about your use of N Six Hub, we’ll provide the information about the platform’s processing that you reasonably need.
When you leave
You can export your organisation’s records at any time during the subscription — no exit fee, no request queue. That export excludes stored files, chat and meeting data, and billing ledgers — each is available separately, so if you need those returned too, email privacy@nsixhub.com. When the subscription ends, tell us whether you want your data returned (a final export) or deleted. On a deletion request we run a purge that permanently removes your organisation’s records from the primary database and every file in your organisation’s storage area.
Two honest caveats. First, some data survives the purge by design or by law: billing and invoice records (statutory retention), and audit trails, which expire on their own schedules — two years for activity and security logs, longer for permission-change records. Second, encrypted chat message data, meeting records and voice and video call history live in a separate datastore that the automated purge does not yet reach; when you ask for deletion we remove them too, as a manual step in the same process — you don’t need to ask separately.
Audits and information
We’ll give you the information you need to demonstrate that the obligations in this agreement — and in Article 28 — are being met: answering security questionnaires, providing the documentation behind the measures above, and contributing to audits and inspections. That right is yours under Article 28(3)(h); it doesn’t depend on our agreement, on a breach, or on a regulator asking.
The practical arrangements are the usual ones: reasonable notice, audits no more than once a year unless something has actually gone wrong or a regulator requires it, an independent auditor bound by confidentiality if you appoint one, remote access where that genuinely answers the question, and the cost of an on-site audit borne by you. Those arrangements shape how an audit runs — never whether it happens.
Precedence, changes and contact
This agreement is part of your subscription agreement; if the two conflict on data protection, this agreement wins. If we change it materially, we’ll say so on this page and email organisation owners — silent edits don’t count as agreement.
Questions, signed copies, anything unclear: privacy@nsixhub.com (or hello@nsixhub.com for general queries). Last updated: 3 September 2026.