1. Introduction
AppHub LLC, doing business as AppHub (hereafter referred to as the Company, we, us, or our), is committed to protecting the privacy and security of personal information entrusted to us by visitors to our website, clients, and users of our services. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your personal data when you visit our website at https://www.apphub.hair or engage with our computer systems design and related professional services.
The developer of this website and its associated digital properties is AppForges, who has worked with our team to build a secure and privacy-conscious online presence. Our company operates within the Computer Systems Design and Related Services industry under the broader Professional, Scientific, and Technical Services sector, with a focus on computer integrated systems design, enterprise architecture, and technology consulting.
By accessing or using our website and services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any provision described herein, we respectfully ask that you discontinue use of our website and refrain from providing personal information to us. This policy applies solely to information collected through our website and in the course of delivering our professional services and does not extend to any third-party platforms that may be linked from our pages.
We encourage you to read this document in its entirety. It is designed to be transparent, comprehensive, and compliant with applicable data protection regulations including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant frameworks. Should you have any questions after reviewing this policy, please contact us using the details provided in the Contact section at the end of this document.
↑ Back to top2. Information We Collect
We collect several categories of information to deliver and improve our services. The types of data we may gather depend on your interactions with our website and services. We classify collected information into the following categories.
Personal Identification Information: When you fill out our contact form, request a consultation, subscribe to communications, or engage our services, we may collect your full name, email address, phone number, company name, job title, and mailing address. This information is necessary for us to respond to your inquiries, deliver contracted services, and manage our business relationship with you.
Technical and Usage Data: Our servers automatically record certain information when you visit our website. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type, referring URL, pages visited, time spent on each page, and the date and time of your visit. This data is aggregated and analyzed to understand how visitors interact with our site and to identify areas for improvement.
Project and Service Data: When we engage in a client project, we may receive technical specifications, system architecture diagrams, source code repositories, database schemas, API documentation, and other engineering artifacts. This information is handled under strict confidentiality agreements and used exclusively for the purpose of delivering the contracted services.
Communication Records: We retain copies of correspondence exchanged with you, including emails, contact form submissions, support tickets, and meeting notes. These records help us maintain continuity of service and provide accurate historical context for ongoing engagements.
↑ Back to top3. How We Collect Information
We obtain information through multiple channels, each of which is described below. We are committed to using fair and lawful means of collection and to being transparent about our practices.
Direct Collection: Most personal information is provided directly by you when you fill out forms on our website, send us an email, call our office, attend a meeting, or sign a service agreement. In each of these scenarios, you voluntarily and knowingly supply the data, and we collect only what is necessary for the stated purpose.
Automated Collection: As you navigate our website, certain technical data is collected automatically through cookies, web beacons, and similar technologies. These tools help us analyze traffic patterns, detect and prevent security threats, and deliver a more personalized browsing experience. Detailed information about our use of cookies is provided in Section 12 of this policy.
Third-Party Sources: In limited circumstances, we may receive information about you from third-party services, such as analytics providers, advertising platforms, or professional networking sites. We only engage with reputable providers who comply with applicable privacy laws and contractual confidentiality obligations. Any data obtained from third parties is handled in accordance with this Privacy Policy.
Publicly Available Information: For business development and due diligence purposes, we may access publicly available information about organizations and their representatives from sources such as corporate registries, industry publications, and professional profiles. This practice supports our ability to tailor our outreach and services to relevant prospects.
↑ Back to top4. Use of Collected Information
The information we collect serves multiple legitimate business purposes. We process your data only when we have a valid legal basis to do so, such as performance of a contract, compliance with a legal obligation, protection of vital interests, consent, or our legitimate business interests that do not override your fundamental rights and freedoms.
Service Delivery: We use personal and project-related information to perform the services you have requested, including systems design, architecture consulting, software development, cloud infrastructure deployment, cybersecurity assessments, and data engineering projects. This processing is necessary for the performance of our contractual obligations to you.
Communication: Your contact details enable us to respond to your inquiries, provide project updates, deliver technical documentation, issue invoices, and share relevant information about our services. We may also send periodic newsletters or industry insights if you have opted in to receive such communications.
Website Improvement: Aggregated usage data helps us understand which pages are most visited, how users navigate our site, and where they encounter friction. These insights drive continuous improvement of our online presence and user experience. No personally identifiable information is used in these aggregated analyses.
Security and Compliance: We process log data to monitor for malicious activity, investigate security incidents, enforce our Terms of Service, and comply with applicable legal and regulatory requirements. This processing is essential to protect the integrity of our systems and the confidentiality of client data.
Business Operations: Administrative functions such as accounting, tax reporting, legal claims management, and corporate governance may require the processing of certain personal and transactional data. Such processing is limited to what is strictly necessary and is conducted in accordance with applicable laws.
↑ Back to top6. Data Retention Policies
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. The specific retention period depends on the nature of the data and the context in which it was provided.
Contact and Inquiry Data: Information submitted through our contact form or direct correspondence is retained for a period of three years from the date of last communication, after which it is securely deleted or anonymized unless an ongoing business relationship necessitates longer retention.
Client Engagement Records: Data related to active and past client projects, including technical documentation, deliverables, invoices, and contractual records, is retained for a period of seven years following the conclusion of the engagement to comply with tax, audit, and professional liability requirements.
Website Usage Logs: Server logs and analytics data are retained for a maximum of 26 months. After this period, raw log files are purged, and only aggregated, anonymized statistical summaries may be preserved for long-term trend analysis.
Marketing Communications: If you have subscribed to our newsletter or marketing updates, your contact details are retained until you unsubscribe or request deletion. Every marketing email includes a clear unsubscribe mechanism that takes effect immediately.
Upon expiration of the applicable retention period, personal data is securely destroyed using methods appropriate to the medium: digital records are irreversibly deleted from active systems and backups, and physical documents are shredded. Where feasible, we anonymize data so that it can no longer be associated with an identifiable individual and may retain such anonymized data indefinitely for research and analytical purposes.
↑ Back to top7. Data Security Measures
We implement and maintain a comprehensive set of technical, administrative, and physical safeguards designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security program is regularly reviewed and updated to address emerging threats and evolving best practices.
Encryption: All data transmitted between your browser and our servers is protected by Transport Layer Security (TLS) encryption. Personal data stored on our systems is encrypted at rest using industry-standard AES-256 encryption. Encryption keys are managed through a dedicated key management service with strict access controls.
Access Controls: Access to personal data is restricted to authorized personnel who require it to perform their job functions. We enforce role-based access controls (RBAC), multi-factor authentication (MFA), and the principle of least privilege across all systems. Access logs are maintained and audited regularly.
Network Security: Our infrastructure is protected by enterprise-grade firewalls, intrusion detection and prevention systems (IDS/IPS), and continuous network monitoring. We conduct regular vulnerability scans and penetration tests to identify and remediate potential weaknesses before they can be exploited.
Incident Response: We maintain a documented incident response plan that outlines procedures for detecting, containing, and recovering from security incidents. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant supervisory authorities as required by applicable law and within the mandated timeframes.
Staff Training: All employees and contractors receive mandatory privacy and security training upon onboarding and at least annually thereafter. This training covers data handling procedures, phishing awareness, password hygiene, and incident reporting protocols.
↑ Back to top8. International Data Transfers
AppHub LLC is headquartered in the United States, and our primary data processing activities occur on servers located within the United States. However, as we serve clients globally and utilize certain cloud-based service providers, your personal information may be transferred to, stored in, or processed in countries other than your country of residence.
When we transfer personal data across international borders, we ensure that appropriate safeguards are in place to protect your information. For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on mechanisms such as Standard Contractual Clauses (SCCs) approved by the European Commission, binding corporate rules, or your explicit consent.
Our service providers who process data outside your home jurisdiction are contractually required to adhere to data protection standards at least as protective as those set forth in this Privacy Policy. We conduct due diligence on all sub-processors to verify their compliance with applicable privacy laws and contractual obligations.
By using our website and services, you understand that your information may be transferred to and processed in countries whose data protection laws may differ from those in your jurisdiction. We take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
↑ Back to top9. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding the personal information we hold about you. We respect these rights and provide mechanisms for you to exercise them. The rights described below apply to the fullest extent permitted by applicable law.
Right to Access: You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data in a structured, commonly used, and machine-readable format. We will provide this information within the timeframe required by applicable law, typically within 30 days of receiving a verified request.
Right to Rectification: If you believe that personal information we hold about you is inaccurate or incomplete, you may request that we correct or supplement it. We will promptly update our records upon verification of the requested changes.
Right to Erasure: In certain circumstances, you may request that we delete your personal data. This right, also known as the right to be forgotten, applies when the data is no longer necessary for the purpose for which it was collected, when you withdraw consent, when you object to processing, or when processing was unlawful. We will comply with valid erasure requests unless retention is required by law or necessary for the establishment, exercise, or defense of legal claims.
Right to Restrict Processing: You may ask us to limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to its processing. During the restriction period, we will store but not otherwise process your data.
Right to Data Portability: Where processing is based on consent or contract and is carried out by automated means, you may request that we transmit your personal data directly to another data controller where technically feasible.
Right to Object: You have the right to object to processing based on legitimate interests or for direct marketing purposes. Upon receiving an objection, we will cease the relevant processing unless we demonstrate compelling legitimate grounds that override your interests.
To exercise any of these rights, please contact us using the details provided in Section 15. We may need to verify your identity before processing your request. We will respond to all valid requests within the legally mandated timeframe and will not discriminate against you for exercising your privacy rights.
↑ Back to top10. California Privacy Rights
If you are a resident of the State of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information. This section describes those rights and explains how California residents can exercise them.
Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you in the preceding 12 months, including the sources from which the information was collected, the business or commercial purpose for collection, and the categories of third parties with whom we have shared the information. You may make such a request no more than twice in any 12-month period.
Right to Delete: You may request that we delete any personal information we have collected from you, subject to certain exceptions. We will honor verifiable deletion requests unless the information is necessary for us to complete a transaction, detect security incidents, debug errors, exercise free speech, comply with legal obligations, or use the data internally in a lawful manner compatible with the context in which you provided it.
Right to Opt-Out: Under the CCPA, you have the right to opt out of the sale of your personal information to third parties. AppHub LLC does not sell personal information as that term is defined under the CCPA. We also do not share personal information for cross-context behavioral advertising purposes.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. This means we will not deny you goods or services, charge different prices, provide a different level of quality, or suggest that you may receive a different price or level of quality as a result of exercising your rights.
To submit a CCPA request, please contact us using the details in Section 15 with the subject line California Privacy Rights Request. We will verify your identity by matching the information you provide with data we already maintain. Authorized agents may submit requests on your behalf, provided they present written authorization signed by you.
↑ Back to top11. Privacy for Children
Our website and services are not directed to, nor do we knowingly collect personal information from, individuals under the age of 18. We take the protection of the privacy of minors very seriously and have implemented measures to prevent the inadvertent collection of data from children.
We do not target our marketing, content, or services toward children, and we do not have actual knowledge that we collect, use, or disclose personal information from anyone under 18 years of age. Our contact form includes a confirmation that the submitter is at least 18 years old or has the consent of a parent or legal guardian.
If we become aware that we have inadvertently collected personal data from an individual under the age of 18 without verified parental consent, we will take immediate steps to delete that information from our systems. Parents or guardians who believe that their child has provided us with personal information without their consent should contact us immediately using the details in Section 15.
We encourage parents and guardians to monitor their online activities and to instruct them never to provide personal information through websites without permission. For additional information about protecting the privacy of children online, we recommend consulting resources provided by the Federal Trade Commission and other consumer protection agencies.
↑ Back to top13. Third-Party Services and Links
Our website may contain links to third-party websites, platforms, and services that are not owned or controlled by AppHub LLC. This Privacy Policy applies solely to information collected by us and does not govern the practices of any third party.
We are not responsible for the privacy policies, content, or practices of any linked websites. When you click on a third-party link, you will be directed away from our site, and any information you provide to that third party will be governed by their own privacy policy. We encourage you to review the privacy policies of every website you visit before providing any personal information.
Third-Party Analytics: As noted in Section 12, we utilize analytics services provided by third parties. These providers may set their own cookies and collect data according to their respective privacy policies. We have reviewed and selected providers who offer privacy-compliant configurations and who comply with applicable data protection laws.
Embedded Content: Our website may occasionally embed content such as videos, maps, or social media feeds from third-party platforms. Embedded content behaves as if you visited the originating platform directly, and those platforms may collect data about you, use cookies, and monitor your interaction with the embedded content. We include embedded content only when necessary to illustrate our services and we select platforms that provide privacy-respecting embedding options.
↑ Back to top14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational factors. When we make material changes, we will update the Last Updated date at the top of this page and provide prominent notice on our website.
For significant modifications that materially affect your rights or the ways we process your personal information, we may provide additional notice through direct communication, such as an email notification to existing clients or a banner announcement on our website homepage. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your privacy.
Your continued use of our website and services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of our website and services and, where applicable, request deletion of your personal data in accordance with Section 9 of this policy.
We maintain a version history of this Privacy Policy for our internal records. If you would like to review a previous version, please contact us using the details provided below, and we will make reasonable efforts to accommodate your request.
↑ Back to top15. How to Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, we welcome you to reach out to us. We are committed to addressing your inquiries promptly and transparently.
AppHub LLC
116 Huntington Ave FL 15
Boston, 02116-5749
United States (US)
Email: memo@apphub.hair
Phone: +17432873638
Website: https://www.apphub.hair
If you believe that we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction. For residents of the European Economic Area, a list of national data protection authorities is available from the European Data Protection Board website. For United States residents, you may contact the Federal Trade Commission or your state attorney general office.
We appreciate your trust in AppHub LLC and remain dedicated to safeguarding your personal information with the highest standards of care and integrity.
↑ Back to top