FAQ Hub helps organisations create and operate knowledge bases, help centres, documentation portals, search, and AI-assisted support. This policy applies when you visit faqhub.io, create or administer an FAQ Hub account, communicate with us, or use a portal or widget operated for FAQ Hub itself.
FAQ Hub is currently operated by Dane Hollenbach, trading as FAQ Hub, a UK sole trader (FAQ Hub, we, us, or our). We are the controller for the processing described below unless we say that we act for a customer.
1. Scope and our data-protection roles
We are a controller for data used to operate our website and business, administer accounts, bill customers, keep the Service secure, understand service use, and communicate about FAQ Hub.
When an FAQ Hub customer uses the Service for its staff, customers, or portal visitors, that customer normally decides why and how the personal data is used. The customer is the controller and FAQ Hub acts as itsprocessor. This can include customer-uploaded content, search queries, chat transcripts, lead details, feedback, support tickets, and contextual information supplied by an embedded widget. The customer's privacy notice governs that processing. Direct a request about that data to the relevant customer first; we will assist the customer as required by law and our agreement.
2. Personal data we collect
| Category | Examples |
|---|---|
| Account and organisation | Name, work email, organisation, role, user and tenant identifiers, invitations, account settings, and authentication records. |
| Billing | Plan, billing status, transaction references, and Stripe customer and subscription identifiers. Stripe handles full payment-card details. |
| Customer content | Articles, files, URLs, branding, product details, prompts, instructions, and material submitted for publication, retrieval, or AI assistance. |
| Portal and support | Search queries, chat messages, contact details, host-page URL, embedder-supplied role, feedback, tickets, comments, escalation context, and AI summaries. |
| Usage, device, and security | Feature events, article interactions, result counts, AI-token use, timestamps, IP address, browser and device details, referral source, logs, and identifiers used to protect the Service. |
| Communications and leads | Sales forms, support requests, name, work email, company, website, message, consent time, survey responses, and correspondence. |
| Browser storage | Analytics consent, session event queues, language and theme choices, chat state, and feedback history. |
Do not place sensitive personal data in free-text fields, uploads, or AI prompts unless it is necessary, lawful, and expressly supported by the agreement with the relevant controller.
3. How we obtain data
We collect personal data:
- directly from you when you register, subscribe, submit content, chat, give feedback, or contact us;
- from the organisation that creates your account, invites you, or deploys an FAQ Hub portal or widget;
- automatically from your browser, device, and use of our website or Service;
- from services that you or a customer connect; and
- from providers for identity, payments, cloud infrastructure, analytics, and security.
4. How and why we use personal data
Our main purposes and UK GDPR lawful bases are:
| Purpose | Lawful basis |
|---|---|
| Create accounts; provide plans, support, and billing | Contract or steps requested before a contract. |
| Operate content, search, chat, AI, feedback, tickets, integrations, and portals | Contract for our customer; the customer's documented instructions where we are processor. |
| Authenticate users, prevent abuse, investigate incidents, and protect tenants | Legitimate interests in a secure and reliable service; legal obligation where applicable. |
| Measure usage, enforce plan limits, diagnose faults, and improve usability | Legitimate interests; consent where analytics or device storage requires it. |
| Keep financial, contractual, audit, and compliance records | Legal obligation and legitimate interests in establishing and defending legal rights. |
| Answer enquiries and manage customer relationships | Contract, pre-contract steps, and legitimate interests in operating the business. |
| Send service notices and permitted marketing | Contract or legitimate interests for service messages; consent where required for marketing. |
Where we rely on legitimate interests, we consider whether the processing is necessary and proportionate, its effect on you, and available safeguards. You may object as described in section 11. We do not sell personal data.
5. AI-assisted processing
FAQ Hub may send relevant prompts, customer content, retrieved passages, and conversation context to contracted Microsoft Azure AI services to generate draft content, embeddings, or support answers. Automated safety filtering may also process inputs and outputs. AI output can be inaccurate and should be reviewed before publication or use in an important decision.
We do not use Customer Data to train our own general-purpose AI model. Microsoft states that prompts and generated content submitted to Azure-hosted models are not used to train its foundation models without permission or instruction. We do not use the Service to make solely automated decisions about people that produce legal or similarly significant effects.
6. Who receives personal data
We disclose data only where needed for the purposes above, including to:
- Microsoft Azure for application hosting, databases, storage, identity, email, monitoring, search, and AI services;
- Stripe for checkout, recurring billing, payment records, fraud prevention, and the billing portal;
- Cloudflare for marketing-site hosting, content delivery, security, DNS, and request logs;
- PostHog and Google Analytics for consent-based marketing-site analytics, including masked session replay through PostHog;
- communications and integration providers selected by us or enabled by a customer;
- professional advisers, auditors, insurers, courts, regulators, and public authorities where reasonably necessary; and
- a buyer, investor, incorporated successor, or other party to a business transaction, subject to confidentiality and applicable law.
Providers acting for us are bound by contractual privacy and security duties. Some providers, including Stripe, may also act as controllers for parts of their processing. A current list of material service providers is available by emailing us.
7. International transfers
FAQ Hub's core production application, database, and Azure AI resources are hosted in Microsoft's West Europe region. Global providers may process data elsewhere, and resilience services may replicate it to another region. Where UK personal data is transferred to a country without UK adequacy regulations, we use an applicable safeguard such as the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful transfer mechanism. Contact us for information about safeguards relevant to your data.
8. How long we keep data
We retain personal data only as long as reasonably needed to provide the Service, follow customer instructions, meet legal and accounting duties, resolve disputes, and enforce agreements. The period depends on the data, account status, customer settings, sensitivity, contractual requirements, backup cycle, and applicable limitation periods.
- Account and operational data is generally kept while an account is active and for a limited period afterwards.
- Customer Data is kept for the subscription term and then deleted or anonymised in line with the customer agreement and backup cycle, unless law requires retention.
- Billing, tax, and contract records are kept for statutory and accounting periods.
- Security and audit records are kept for a proportionate period based on risk and investigation needs.
- Sales enquiries are kept while relevant to the enquiry and a potential business relationship, then deleted or minimised.
- Browser session data ends with the session; persistent storage remains until cleared, replaced, or removed by the application.
Data subject to a legal hold is retained until the hold ends. Data that has been irreversibly anonymised may be kept longer.
9. Cookies, analytics, and browser storage
Our marketing site uses browser storage to remember your analytics choice. Before you consent, optional analytics providers do not load. If you choose Allow analytics, Google Analytics and EU-hosted PostHog may collect page views, navigation, interactions, device details, performance data, IP-derived location, and identifiers. PostHog session replay masks all form inputs and text within forms and dialogs. We do not intentionally send form values to analytics providers.
You can reject optional analytics when first asked. After rejection, use the Privacy choices button to reconsider. You can also clear site data in your browser. The Service separately uses necessary cookies and storage for authentication, security, requested preferences, and active support sessions. Removing them may sign you out or reset a feature.
Customers that deploy FAQ Hub widgets and add their own tracking remain responsible for their notices, lawful basis, and consent controls.
10. Security
We use technical and organisational measures designed to protect personal data, including access controls, tenant separation, encryption in transit, secret management, logging, and monitoring. Access is limited to people and providers who need it for authorised purposes. No online system can be guaranteed completely secure. Protect your credentials and tell us promptly if you suspect unauthorised access.
11. Your rights
Subject to legal conditions and exemptions, UK data-protection law may give you rights to:
- be informed and access your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- receive certain data in a portable format;
- object to processing based on legitimate interests and always object to direct marketing;
- withdraw consent at any time without affecting earlier processing; and
- complain to the Information Commissioner's Office.
Email us to exercise a right relating to our controller activities. We may need to verify your identity. If the request concerns data controlled by an FAQ Hub customer, contact that customer first. The UK Information Commissioner's Office can be contacted through ico.org.uk.
12. Marketing choices
You can unsubscribe from a marketing email through its unsubscribe link or by contacting us. You will still receive necessary account, billing, security, and service communications. We do not sell personal data or use Customer Data for third-party behavioural advertising.
13. Children's privacy
FAQ Hub is a business service and accounts are not intended for people under 18. Customers must not use the Service to intentionally collect children's personal data without an appropriate lawful basis, notices, safeguards, and any required parental authorisation. Contact us if you believe a child supplied data improperly.
14. Business transfer and policy changes
FAQ Hub may move from its current sole-trader structure to a UK limited company. If that company becomes the controller or receives personal data with the business, we will identify it, update this policy, and notify affected customers as required. The successor will be required to protect the data consistently with applicable law.
We may also update this policy when the Service, providers, or legal duties change. We will publish the revised policy, update its date, and provide additional notice where a change is material or legally required.
15. Contact us
Dane Hollenbach, trading as FAQ HubData controller
England, United Kingdom
[email protected]
Postal correspondence: request the current service address by email.