HubBroker - Roles and Responsibilities under GDPR

Roles and Responsibilities under GDPR
This document provides an overview of how responsibilities under the General Data Protection Regulation (GDPR) are allocated between HubBroker ApS and customers using HubBroker services.
The exact GDPR role of each party depends on the specific processing activity and the purposes for which personal data is processed.
Roles
For personal data that a customer submits to or processes through HubBroker's integration, EDI, e-invoicing or related services:
- The customer generally acts as the Data Controller because the customer determines why the personal data is processed.
- HubBroker ApS generally acts as a Data Processor, processing personal data on behalf of and according to the documented instructions of the customer.
HubBroker ApS may separately act as a Data Controller for personal data that it processes for its own legitimate business purposes, such as:
- Customer and prospect contact information
- Contract and billing administration
- User account administration
- Security and audit records
- Customer support communications
- Website enquiries
- Compliance with legal obligations
The applicable role should be assessed according to the specific processing activity.
Personal Data Processed through HubBroker Services
Depending on the customer's configuration and integration flows, HubBroker services may process personal data contained in business documents or electronic transactions.
Examples may include:
- Names and business contact details
- Email addresses and telephone numbers
- Customer and supplier contact information
- Billing and delivery information
- Employee or contact identifiers
- Order, invoice and shipment information
- Electronic document identifiers
- IP addresses and technical logs
- Authentication and access-related information
- Other personal data included by the customer in EDI, API, e-invoicing or integration messages
Customers should avoid transmitting personal data that is not necessary for the intended integration or business process.
Data Controller Responsibilities
Where the customer acts as Data Controller, the customer is responsible for determining the purposes and lawful basis for processing personal data.
The customer is responsible for:
- Ensuring that personal data is processed lawfully, fairly and transparently
- Establishing an appropriate lawful basis for processing
- Providing required privacy information to data subjects
- Determining what personal data is submitted to HubBroker
- Applying data minimisation principles
- Ensuring that personal data is accurate and kept up to date where required
- Defining appropriate data retention requirements
- Managing requests from data subjects, including access, rectification, restriction, portability, objection and erasure where applicable
- Assessing whether a data subject request can legally be fulfilled
- Providing documented processing instructions to HubBroker
- Ensuring appropriate contractual arrangements are in place with HubBroker
- Assessing personal-data breaches and making required notifications to supervisory authorities and affected data subjects
- Ensuring that its own applications, systems, credentials and integrations are appropriately secured
HubBroker will provide reasonable assistance to customers with their GDPR obligations where required by applicable law and the Data Processing Agreement.
Data Processor Responsibilities – HubBroker ApS
When acting as a Data Processor, HubBroker ApS is responsible for processing personal data in accordance with applicable GDPR requirements and the customer's documented instructions.
HubBroker's responsibilities include:
- Processing personal data only on documented instructions from the customer, unless processing is required by applicable law
- Ensuring that persons authorised to process personal data are subject to appropriate confidentiality obligations
- Implementing appropriate technical and organisational security measures
- Assisting customers, where applicable, in responding to requests from data subjects
- Assisting customers with GDPR security and personal-data-breach obligations where required
- Informing the customer without undue delay after becoming aware of a personal-data breach affecting personal data processed on the customer's behalf
- Maintaining appropriate records relating to processing activities where required
- Making available information reasonably necessary to demonstrate compliance with applicable processor obligations
- Managing sub-processors in accordance with the Data Processing Agreement and GDPR requirements
- Ensuring appropriate safeguards are used where personal data is transferred internationally
- Deleting or returning customer personal data following termination of services, according to the customer's instructions, contractual obligations and applicable legal requirements
HubBroker will not use personal data processed on behalf of a customer for unrelated purposes.
HubBroker ApS Data Processing
What Data HubBroker Processes
The personal data processed by HubBroker depends on the customer's integrations, trading partners, document types and configuration.
HubBroker may process data contained in:
- EDI documents
- Electronic invoices
- Purchase orders
- Order confirmations
- Shipping and delivery documents
- Product and trading-partner messages
- API messages
- XML, JSON, CSV and other structured documents
- Business documents transferred through supported integration channels
- System and transaction logs required for operation, monitoring and security
HubBroker does not determine the content placed into customer business documents where it acts solely as Data Processor.
Purpose of Processing
Personal data processed through HubBroker services may be used as necessary to provide the contracted services, including:
- Receiving electronic business documents
- Validating document content
- Transforming data between formats
- Routing documents between customer systems and trading partners
- Delivering electronic invoices and other transactions
- Processing API and EDI integrations
- Monitoring transaction status
- Detecting and investigating processing errors
- Maintaining service security
- Providing technical support
- Maintaining required operational and audit records
HubBroker does not process customer personal data for purposes unrelated to providing and securing the contracted services unless otherwise required by law or separately agreed.
Data Minimisation
Customers should provide only the personal data reasonably necessary for the relevant business process.
HubBroker applies appropriate controls and processes designed to limit processing to data required for delivering, operating, securing and supporting its services.
Data Storage and Location
Customer data may be stored or processed in systems and infrastructure used by HubBroker and its authorised service providers.
Specific hosting locations, authorised sub-processors and international-transfer safeguards should be documented in HubBroker's applicable:
- Data Processing Agreement
- Sub-processor information
- Privacy documentation
- Security documentation
Where personal data is transferred outside the European Economic Area, HubBroker will use an applicable GDPR transfer mechanism where required.
Data Retention and Deletion
Personal data should not be retained for longer than necessary for the purpose for which it is processed.
Retention periods may depend on:
- Customer instructions
- Contractual requirements
- Transaction processing requirements
- Security and audit requirements
- Backup and disaster-recovery processes
- Applicable legal or regulatory retention obligations
Upon termination of the applicable service, HubBroker will delete or return personal data processed on behalf of the customer in accordance with the Data Processing Agreement and applicable legal requirements, unless applicable law requires continued retention.
Data contained in backup systems may remain for a limited period according to HubBroker's backup-retention schedule and will be protected from normal operational use until overwritten or securely deleted according to the applicable retention process.
Data Subject Requests
The customer, as Data Controller, is generally responsible for handling requests from its data subjects.
Where HubBroker receives a request relating to personal data for which a customer is the Data Controller, HubBroker will normally refer the request to the relevant customer unless applicable law requires otherwise.
HubBroker will provide reasonable technical and organisational assistance where necessary to enable the customer to respond to valid requests.
Personal Data Breaches
HubBroker maintains processes for identifying, investigating and responding to security incidents.
Where HubBroker becomes aware of a personal-data breach affecting personal data processed on behalf of a customer, HubBroker will notify the affected customer without undue delay in accordance with applicable GDPR requirements and contractual obligations.
The customer, as Data Controller, remains responsible for determining whether notification to a supervisory authority or affected data subjects is required.
Security of Processing
HubBroker applies appropriate technical and organisational measures taking into account the nature of the processing and associated risks.
These measures may include, as applicable:
- Access controls
- Authentication and authorisation controls
- Encryption
- Network and infrastructure security
- Logging and monitoring
- Backup and recovery procedures
- Vulnerability and patch management
- Incident-management processes
- Employee confidentiality and security requirements
- Business continuity and disaster-recovery measures
- Periodic security reviews
Security responsibility is shared according to the respective GDPR roles of HubBroker and the customer.
Sub-processors
HubBroker may use authorised sub-processors to assist in providing its services.
Where HubBroker acts as Data Processor, sub-processors handling customer personal data will be subject to appropriate contractual data-protection obligations as required by GDPR.
Current sub-processor information should be maintained separately and made available to customers where applicable.
International Data Transfers
Where personal data is transferred to a country outside the European Economic Area that is not covered by an applicable adequacy decision, appropriate safeguards will be used where required, such as applicable Standard Contractual Clauses or another lawful transfer mechanism.
Accountability and Documentation
HubBroker maintains appropriate privacy, security and data-processing documentation according to its role and applicable legal requirements.
Relevant documentation may include:
- Privacy Policy
- Data Processing Agreement
- Information Security Policies
- Sub-processor information
- Data-retention requirements
- Security and incident-management procedures
- Records of processing activities where applicable
Category: GDPR
Last date of update: 24.08.2026