Privacy Policy
Last updated: 7 August 2026
At MeigaHub, S.L. (hereinafter, «the Controller»), we respect your privacy and are committed to protecting your personal data in accordance with Regulation (EU) 2016/679 General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018, of December 5, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).
1. Data Controller
The data controller's details are:
- Identity: MeigaHub, S.L.
- Data protection contact: [email protected]
- Address: Lugar Tecnópole I, Local 12, 32900, San Cibrao das Viñas (Ourense), España
2. Data We Collect and Purposes
We collect and process the following personal data, with the indicated purposes and legal bases (Art. 6 GDPR):
| Data | Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|---|
| Name, email, password (bcrypt hash) | Account management, authentication, and 2FA | Art. 6.1.b — Contract performance |
| Agent conversation history | Agent memory, chat context, and service improvement | Art. 6.1.f — Legitimate interest |
| Registered LLM server IPs | Connection, health checks, and endpoint routing | Art. 6.1.b — Contract performance |
| Aggregated usage statistics (no content) | Service improvement, monitoring, and abuse detection | Art. 6.1.f — Legitimate interest |
| Contact book: name in plaintext; email and phone encrypted (AES-256-CBC) | Sending messages and reminders to third parties at user request | Art. 6.1.a — Explicit consent |
| Subscription and billing data | Payment processing, plan management, and billing | Art. 6.1.b — Contract performance |
| TOS violation records (type, severity, evidence, appeals) | Terms of Service enforcement and platform security | Art. 6.1.f — Legitimate interest |
| Page visits (path, referrer, UTMs — no IP, no cookies, no fingerprinting, GDPR-safe). Automatically deleted every 90 days | 100% server-side internal traffic analytics. No Google Analytics, Meta Pixel, or any third-party service. No anonymous visitor tracking | Art. 6.1.f — Legitimate interest |
| Business profile data: Tax ID (NIF/CIF), company name, address, city, postal code, contact phone (AES-256-CBC encrypted), website, business sector and business description | Invoicing in accordance with Spanish tax law, AI assistant personalization and service adaptation to the user's business profile | Art. 6.1.b — Performance of contract |
2 bis. Shared structural knowledge (anonymized)
MeigaHub shares anonymized technical structures of your automation rules and skills across accounts (trigger type, action sequence, delivery channels and technical tags) so the agent can suggest proven skeletons when creating new rules or skills. Before any structure is shared, an automatic process strips all private or identifiable data: names, URLs, identifiers, emails, phone numbers, keys, free-form content, channel IDs and any reference to people or companies. Only the generic technical structure is kept. This structural information does not allow identification and, under Article 4.1 of the GDPR, does not constitute personal data. You can request exclusion of your structures from the shared catalogue by writing to the contact below.
3. User LLM Servers
When you connect your own LLM server:
- Messages you send to the chat are transmitted to YOUR server to generate responses through an encrypted tunnel (WireGuard, managed with Tailscale).
- MeigaHub acts as a technical intermediary: it does not store responses generated by your server beyond the conversation history.
- If you enable the option to share your server with administrators, administrator messages may also be processed on your server.
Important: You are responsible for the data processed on your own LLM server. MeigaHub has no control over how your server processes the data.
3 bis. Specialist Access to User Accounts
When the user purchases a specialist hour pack, an authorized MeigaHub worker (specialist) may access the user's account in a limited capacity to deliver the contracted service.
Legal basis: Contract performance (Art. 6.1.b GDPR) — access is strictly necessary to fulfil the contracted service.
- The specialist only accesses account sections that the administrator has expressly authorized in the assignment.
- All access is automatically logged (date, time, section, action) in an unalterable activity log.
- The specialist signs a digital confidentiality agreement before accessing each assigned account.
- The user can view the complete specialist access history in their "My Services" section (GDPR Art. 15 — right of access).
- Additionally, the user receives a daily email digest summarizing the specialist's recorded actions.
Retention: Activity logs are retained for 2 years and automatically deleted after that period (GDPR Art. 5.1.e).
4. Third-Party Cloud APIs
The user may optionally configure third-party cloud APIs with their own key. The supported providers, with their country and the safeguard applying to each transfer, are set out in the sub-processor list. In that case:
- Chat messages are sent to the selected cloud provider. These providers act as independent data controllers with their own privacy policies.
- API keys are stored encrypted (AES-256-CBC) and are never visible to MeigaHub administrators.
Important: Using cloud APIs means your data may leave the European Economic Area if the provider has servers outside the EU. Please consult the relevant provider's privacy policy.
4 bis. Payment data
MeigaHub never sees, receives or stores your card details at any point. When you pay you are taken to the gateway's own environment and the details are entered there. We only keep the outcome of the operation —whether it was authorised, the amount and an internal order reference— and the billing details you filled in yourself.
Depending on the gateway active at the time, which you are told during checkout, the following parties take part:
- Comercia Global Payments Entidad de Pago, S.L. (Spanish tax ID B65466997, Madrid), a Spanish payment institution supervised by the Bank of Spain, as the acquirer of the bank card terminal. CaixaBank, S.A. acts as its agent and holds the settlement account, and Redsys Servicios de Procesamiento, S.L. is the technical platform the operation travels through.
- Stripe Payments Europe, Ltd. (Ireland), as an alternative.
These entities are not processors acting on MeigaHub's behalf: they determine their own purposes and means for payment data and answer for it directly to you. In particular, and as required by our contract with the acquirer, we inform you of the following:
Comercia Global Payments informs you that it also acts as controller of the data of cardholders carrying out operations at this establishment, by virtue of the contractual relationship between Comercia Global Payments and the Establishment. To execute the operation the following data is processed: i) bank card data (PAN, expiry, issuer, CVV); ii) cardholder data (first name and surname); iii) geolocation data at the time of payment. The legal basis is the legitimate interest of Comercia Global Payments in performing the aforementioned contract. Data will be communicated to banking entities in order to validate and execute the payment; on occasion this communication may entail an international transfer where one of the parties has engaged foreign banking entities, covered by the derogation in Article 49(1)(c) GDPR as necessary for the performance of a contract in the interest of the data subject. The retention period is 5 years in line with the limitation period for civil actions, and a minimum of 6 years in compliance with applicable payment services regulations.
Although Comercia Global Payments is a Spanish company supervised by the Bank of Spain, its majority shareholder belongs to the US group Global Payments. The data we keep about a purchase —amount, date, description and billing details— stays on our servers, is governed by this same policy and is retained for the period applicable to accounting records.
5. Data Retention
Retention periods are as follows:
- Account data: for as long as the account is active. If you request deletion from your profile, the data is erased immediately and irreversibly from the live system; encrypted backups that may still contain it are purged within a maximum of 30 days.
- Conversation history: until the user manually deletes it, with a maximum of 2 years from the last interaction in each conversation. Conversations without activity for more than 2 years may be automatically purged.
- Issued invoices: 5 years under Spanish tax law (Law 58/2003). Billing events: 12 months. Usage counters: 90 days.
- TOS violation records: 3 years from resolution, or as required by applicable law.
- Messaging channel records (Telegram, WhatsApp, Slack): 30 days. Automatically deleted.
- Page visit analytics: 90 days. Automatically deleted.
- Application errors: 90 days from resolution. Errors still open are kept while their diagnosis remains pending.
- Desktop Agent activity records: 90 days, after which they are deleted automatically.
6. Security Measures
MeigaHub implements appropriate technical and organizational measures proportionate to the risk, in accordance with Art. 32 GDPR and Art. 28 LOPDGDD:
- Encryption of sensitive data at rest (AES-256-CBC) and in transit (HTTPS/TLS 1.2+, WireGuard for LLM servers).
- Two-factor authentication (2FA/TOTP), mandatory for administrators, support staff and free-plan accounts, and available to all other users.
- Passwords stored with bcrypt hash (non-reversible). API keys encrypted and never exposed in the UI.
- Network isolation between users through deny-by-default ACLs. Users cannot access other users or the central infrastructure.
7. Your Rights (GDPR Arts. 15-22 and LOPDGDD)
You have the right to:
- Access (Art. 15): request a copy of your processed personal data.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): request deletion of your account and data («right to be forgotten»).
- Restriction of processing (Art. 18): request restriction of processing under certain circumstances.
- Portability (Art. 20): receive your data in a structured, commonly used, and machine-readable format.
- Objection (Art. 21): object to processing based on legitimate interest.
To exercise these rights, send an email to [email protected] indicating your full name, registered email, and the right you wish to exercise. We will respond within a maximum period of 30 days.
8. International Transfers
MeigaHub processes personal data with the safeguards required by Regulation (EU) 2016/679 (GDPR) and Spain's LOPDGDD. Below we detail the international data transfers that may occur and the legal bases that support them.
MeigaHub's core infrastructure is hosted on OVHcloud SAS (a French company) servers at their Beauharnois, Quebec (Canada) data center. This transfer is covered by European Commission Adequacy Decision 2002/2/EC, which recognizes that Canadian organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) provide an adequate level of personal data protection under Art. 45 GDPR. OVHcloud, as an entity subject to PIPEDA, meets this requirement. Additionally, OVHcloud provides a GDPR-compliant Data Processing Agreement (DPA).
If the user configures third-party cloud APIs, chat data is sent to whichever provider the system selects among those the user has enabled, and only among those. These providers are conditional sub-processors: they receive nothing unless the user actively configures them.
The sub-processors that may receive personal data outside the EEA, with the safeguard applying to each, are listed in the link below.
The complete, up-to-date list of processors and sub-processors —with their country, the function they perform and the safeguard applying to each transfer— is published in the sub-processor list, which is the document referenced by the Data Processing Agreement and is kept as the single source. Any change is announced there with at least 30 days' notice. Primary hosting is in OVH's Beauharnois data centre (Quebec, Canada) and traffic enters through Cloudflare, Inc. (United States).
When the user connects their own LLM server, data travels through an encrypted tunnel (WireGuard/Tailscale) to the user's server; the location of said server and regulatory compliance in its jurisdiction are the user's responsibility. MeigaHub will periodically review the validity of adequacy decisions and adopt additional safeguards (Standard Contractual Clauses or other Art. 46 GDPR mechanisms) if any decision is revoked.
Cloud usage audit log
To ensure traceability and comply with the accountability principle (Art. 5.2 GDPR), MeigaHub maintains two technical logs of the calls sent to cloud AI providers. The first (cloud_usage_audit table) stores only metadata: user, conversation, provider, model, task type, timestamp, number of characters sent and received, tokens consumed, success or error indicator and whether pseudonymisation was applied; the content of prompts and responses is never stored in this log, which is kept for 13 months. The second (cloud_egress_audits table) exists so that pseudonymisation can actually be verified: it keeps a sample of the text AS IT LEFT for the provider, that is, with masking already applied, capped at 4,000 characters. That sample is stored for 5% of calls, chosen at random, and for those where the system itself detects a possible residual identifier; it is automatically deleted after 30 days. Access to both logs is restricted to administrators.
9. AI Processing and Automated Decisions
MeigaHub uses artificial intelligence models (LLMs) to deliver its features. It is important that you understand how your data is processed in this context:
- AI models run on the user's own servers, on the cloud APIs the user has configured or, where the user has enabled them, on AI servers operated by MeigaHub. MeigaHub does not train or fine-tune AI models with your data. It does keep internally, without leaving its servers, examples of correct tool usage and anonymised automation patterns for the purpose of improving the service; should these ever be used to fine-tune a model, notice will be given beforehand.
- Some features involve automated processing with scoring: opportunity matching (SearchCases), content performance evaluation (blog), and violation detection (TOS). These processes are auxiliary and subject to human oversight.
- Automated decisions (Art. 22 GDPR): MeigaHub does not make fully automated decisions producing legal or similarly significant effects on you, with a single exception: the immediate suspension of an account when the system detects illegal content, where waiting for a prior review would cause harm to third parties. In every other case the response to a breach of the Terms is graduated by severity —warning, restriction or suspension— and no suspension is carried out without a person confirming it first. The logic applied is the comparison of detected usage against the conduct prohibited in the Terms. You have the right to obtain human intervention, to express your point of view and to contest the decision through the appeals procedure available in your dashboard, which is always resolved by a person.
- You have the right to obtain human intervention, express your point of view, and contest any automated decision, in accordance with Art. 22.3 GDPR. Contact [email protected].
- Pseudonymisation before sending to cloud AI: before transmitting text to a cloud-hosted AI model —in chat, when indexing documents for search, and when generating images— MeigaHub automatically replaces direct identifiers (email addresses, phone numbers, national ID numbers, IBANs and card numbers) with placeholders, restoring them only within your own environment when the response is received. This protection is on by default; you can switch it off from your profile, in which case text is sent as-is at your own responsibility. The contact data you manage is stored and processed internally for the sole purpose of providing you the service (B2B prospecting and sales management on professional data) and is not disclosed to third parties for their own purposes. MeigaHub logs and periodically reviews these transmissions to verify that no direct identifiers are sent in clear text and to adjust the system when necessary.
- Images and documents you send for analysis: when you attach an image, an invoice or a scanned document for the assistant to read, the file is transmitted as-is to the AI provider you configured. Its contents cannot be masked beforehand because they are precisely what you are asking about. This only happens when you send the file, never automatically, and any text accompanying the image is masked just as in chat.
- Web search and contact enrichment: when you ask the assistant to search the internet or to complete a professional contact's details, the query terms and the domain or company you are asking about are sent to the search and enrichment providers you configured with your own key. These transmissions do not go through the masking described above, because the very data being searched is the object of the query and masking it would render it useless. The specific providers, with their country and safeguard, appear in the sub-processor list. Any professional data you receive from them is processed by you as controller, and MeigaHub stores it on your behalf to provide the service.
10. Minors
You must be at least 14 years old to create an account, the age from which Article 7 of the Spanish LOPDGDD allows a minor to consent on their own behalf. Verification is by declaration: when registering you expressly confirm that you meet that requirement, and no date of birth is collected. Paid plans additionally require legal capacity to contract (adulthood or emancipated minor). If we detect or are told that an account belongs to someone under 14 without the consent of a parent or guardian, we will delete it along with the associated data. If you believe a child under 14 has provided us with personal data, write to [email protected] and we will act immediately.
11. Privacy Contact
MeigaHub, S.L. is not legally required to appoint a Data Protection Officer (Art. 37 GDPR), as it does not process data on a large scale. However, you may direct any queries regarding the processing of your personal data to [email protected].
12. Contact and Complaints
To exercise your rights, submit a query, or file a complaint:
You may also file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es if you believe your rights have not been properly addressed.