Privacy Policy
Last updated: September 20, 2025
1. Who we are
Cloud API Hub ("we", "us") operates a hosted workflow automation platform available at cloudapihub.com and related subdomains. For privacy inquiries contact [email protected].
Cloud API Hub
Kızıltoprak Mah. 947. Sok. Kurtoğlu Sitesi Osmanlı Konakları, E-Blok No: 2
Muratpaşa / Antalya, Turkey
2. Scope
This Privacy Policy explains how we process personal data when you visit our marketing site, create an account, use the customer portal or automation workspace, or contact support.
3. Data we collect
- Account data: name, email address, organization name, authentication logs, and role assignments.
- Billing data: subscription status, plan, and transaction references. Payment card details are processed by our merchant-of-record and payment partners; we do not store full card numbers on our servers.
- Service data: workflow definitions, execution logs, files you upload within plan limits, datatable content, and metadata required to run automations.
- Credentials: API keys, OAuth tokens, and connection settings you choose to store for integrations. These are encrypted at rest and accessed only to execute authorized workflows.
- Technical data: IP address, browser type, device information, and security/abuse logs.
- Communications: support tickets and email correspondence.
4. How we use data
We use personal data to:
- Provide, secure, and maintain the Service;
- Authenticate users and enforce plan limits;
- Process subscriptions and communicate billing events;
- Respond to support requests and improve reliability;
- Detect fraud, abuse, and security incidents;
- Comply with legal obligations.
We do not sell personal data.
5. Legal bases (EEA/UK users)
Where GDPR applies, we rely on contract performance (providing the Service), legitimate interests (security and product improvement), consent where required (e.g., optional marketing), and legal obligation.
6. Retention
We retain account and billing records while your account is active and for a reasonable period afterward for legal and accounting purposes. Execution logs and uploaded files are retained according to your plan's history and retention settings, then deleted or anonymized unless longer retention is required by law or active dispute.
7. Sharing and subprocessors
We share data with service providers that help us host infrastructure, process payments, send transactional email, and monitor security. These providers process data under contractual obligations consistent with this Policy. We may disclose data if required by law or to protect rights and safety.
8. International transfers
We serve customers globally. Data may be processed in Turkey and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers.
9. Security
We implement administrative, technical, and organizational measures including encryption of stored credentials, access controls, and monitoring. No method of transmission or storage is completely secure; please use strong passwords and 2FA.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. Contact [email protected] to exercise these rights. You may lodge a complaint with a supervisory authority where applicable.
11. Cookies
Our marketing site uses essential cookies and local storage only as needed for basic functionality. The authenticated applications may use session cookies required for login. We do not use invasive third-party advertising trackers on this marketing site.
12. Children
The Service is intended for business users and is not directed to children under 16.
13. Changes
We may update this Policy by posting a revised version on this page. Significant changes will be communicated through the customer portal or email when appropriate.