Skip to content

Legal

Privacy Policy.

Written to be read, not scrolled past. This is how we handle personal data on this website and in the platform — including the edges most policies leave out.

Who we are, and how to reach us

N Six Hub is built and operated by N Six Studios Ltd (“we”, “us”), a company registered in England and Wales under company number 16428711, with its registered office at 1364a London Road, Norbury, London, England, SW16 4DE. We are registered with the Information Commissioner's Office.

For anything about personal data — questions, requests, worries — email privacy@nsixhub.com. For everything else, hello@nsixhub.com.

We have not appointed a Data Protection Officer, because the law does not require one of us: we are not a public authority, and our core activities involve neither large-scale systematic monitoring of people nor large-scale processing of special-category data. Data-protection questions still have one clear route — privacy@nsixhub.com — and a person answers them.

Two roles: controller and processor

For some data we are the controller — we decide why and how it is processed. That covers your account and sign-in data, billing details, security and audit records, visits to this website, and enquiries you send us.

For the business records your organisation keeps inside the platform — customers, jobs, notes, files, messages, form submissions — your organisation is the controller and we are its processor. We handle that data on your organisation’s instructions, and your organisation is responsible for having a lawful basis for what it collects. Organisations define their own record fields, so records can contain sensitive data — health information, for example — and the platform lets organisations restrict who sees fields marked sensitive; collecting such data lawfully is the organisation’s responsibility. The formal terms of that processing are in our Data Processing Agreement (DPA) at nsixhub.com/legal/dpa.

If your details are in N Six Hub because a business you deal with put them there, that business is the controller. Contact them first — and if you come to us instead, we will pass your request on and help them answer it.

This website

Browsing nsixhub.com sets no cookies at all and sends nothing to third parties from your browser — no analytics, no trackers, no embedded widgets. Even the fonts are served from our own site.

If you email us, we use what you send to reply and handle your enquiry — nothing else. We don’t buy contact lists, and we only send marketing to people who asked for it; if you did, you can withdraw that consent at any time.

Your account and sign-in

Your account holds what you give us: name, email address, phone number, job title, profile photo, preferences, and any further profile details you or your organisation choose to add.

When you sign in we record the IP address, the browser and device used, and a device identifier — so you and your organisation’s administrators can see active sessions and spot sign-ins that don’t look like you. Your password is stored only as a one-way hash; we never hold it in readable form. If you use two-factor authentication we store what is needed to verify it.

If you administer billing, we store your organisation’s billing name, address and tax ID. Card details are entered with our payment provider, Stripe, directly — we keep only the token, card brand, last four digits and expiry date that Stripe returns. Full card numbers never touch our systems.

Devices, activity and location

The platform keeps a record of each device you use with it — its name, type, platform, last IP address, sign-in count — and, for signed-in use, how long you are connected each day. Actions you take in a workspace are written to activity trails. If you use N Six Hub through your employer, your organisation’s administrators can see this activity: that is workplace monitoring, and your organisation is responsible for telling you about it and for its lawful basis. We build the limits in and disclose them here.

If your organisation uses field or timekeeping features, the app can record GPS points — coordinates, accuracy, heading, speed and battery level. Detailed GPS history is deleted automatically after 90 days. Live staff location is accepted only while you have an open shift — the server refuses location pings outside one — and is deleted after 31 days. Clock-in and clock-out locations, idle-time figures on time entries, and a last-known-location on your profile are kept with those records until they are deleted.

Content your organisation stores

Business records in N Six Hub are whatever your organisation defines: contact details, jobs, documents, photos, signatures, custom fields. Public forms can feed submissions from people without accounts straight into these records.

One-to-one and group chat is end-to-end encrypted: message content is encrypted on your device and we store only the unreadable ciphertext — we cannot read your messages, and attachments and voice notes are encrypted the same way before upload. Disappearing messages are permanently deleted shortly after they expire (a cleanup runs every ten minutes). Chat inside meetings is different: it is stored readable, with your name, so treat it like any other meeting record.

Meetings can only be recorded when they are created as recorded meetings — that setting switches off end-to-end encryption for the meeting and shows a consent notice to everyone who joins. Phone-system calls store the numbers involved, durations, the audio recording and a timestamped transcript. Voice is transcribed on our own infrastructure — call and meeting audio is not sent to a cloud transcription service. Recordings and transcripts are kept until deleted.

For SMS features, message content is stored, but the other party’s phone number is stored as a keyed hash plus a masked display copy rather than in full. Uploaded audience spreadsheets are deleted after 30 days. Records of consent and of opt-outs — including STOP replies — are kept indefinitely as legal evidence, because proving you opted out protects you.

If your organisation runs HR or payroll on the platform, staff profiles hold employment details, and payroll records hold National Insurance numbers, tax codes, pay and pension details. Identity, right-to-work and bank documents are stored privately, and every download of a sensitive document is written to the audit log.

Why we use data, and the legal bases

To run your account and provide the platform — storage, features, support, billing — we process data because it is necessary for the contract with our subscriber (Article 6(1)(b) UK GDPR). Where you use N Six Hub through your organisation’s subscription rather than a contract of your own, we rely on our legitimate interest in providing the service your organisation has contracted for.

Security data — sign-in records, session and device details, audit trails — rests on our legitimate interests: keeping accounts and the platform secure, preventing fraud and abuse, and keeping the service reliable. Keeping financial and tax records, and sending HMRC the fraud-prevention data described below, rest on legal obligation. Marketing from us rests on consent, which you can withdraw at any time.

For content your organisation stores in the platform, the lawful basis is your organisation’s to establish — we process it only on your organisation’s instructions.

You are under no statutory obligation to give us personal data. The one exception is the HMRC fraud-prevention data described below, which the law requires if your organisation uses the VAT connection. Some data is a contractual requirement instead: an account cannot be created without a name, an email address and a password, and a paid subscription cannot run without billing details — without them we simply cannot provide the service. Everything else, like a phone number or profile photo, is optional, and the platform works without it.

AI features and what they send

AI features work by sending data to third-party AI providers. When you use the assistant, summaries, drafting or analysis, the relevant record content, transcript text or prompt goes to OpenAI or Google (Gemini), depending on the task. Photographed business cards are read by Google Gemini. Spoken assistant replies are synthesised by ElevenLabs from the reply text — which can include customer details — but your own voice audio is never sent to them.

Migration is deliberately different: when AI maps data from a platform you are leaving, it sees sanitised structure and masked sample values only — credentials are stripped, and emails, phone numbers and card numbers are masked before anything leaves us. That protection applies to migration mapping; the other AI features send real content, as described above.

Each AI call is logged — which feature, which model, token counts, never the prompt text — and those logs are deleted after 180 days. AI assistant conversations are stored like other workspace content, until deleted.

Automated decisions and profiling

What the platform’s AI produces — record summaries and signals, pipeline forecasts, recommendations in the management brief — is advisory. Each is generated when a person asks, shown to that person with its reasoning, and acted on only if a human decides to. We do not make decisions about you by automated means alone that have legal or similarly significant effects.

Organisations can set up automations that run without anyone pressing a button — sending a confirmation when a booking is made, for example. Those follow rules your organisation writes and fire on events like a record changing status or a payment arriving, not on AI judgements about you; what an organisation’s automations do is that organisation’s responsibility as controller.

HMRC fraud-prevention data (Making Tax Digital)

If your organisation connects N Six Hub to HMRC for VAT, UK law requires every Making Tax Digital software provider to send fraud-prevention headers with each request to HMRC. This is HMRC’s legal requirement on all MTD software, not our choice, and using the connection is impossible without it. The legal basis is legal obligation.

In plain English: whenever you view or file VAT data connected to HMRC — not only when submitting a return — the following travels to HMRC alongside the request: a random device identifier (created the first time you use an HMRC-connected screen and stored in your browser), your public IP address and connection port with a timestamp, your screen size, colour depth and scaling, your browser window size, your timezone, your browser’s user-agent string, and your N Six Hub account identifier. Details of our own software and servers go too — product name, version, server addresses and a hashed licence identifier. Where multi-factor authentication details are available they may be included as a type, timestamp and salted reference — never the secret itself.

This data goes only to HMRC, which receives it as a public authority in its own right. We never estimate or fabricate any of it: if a required value cannot be collected honestly, the platform refuses to submit rather than send a placeholder. And we deliberately do not collect what HMRC no longer requires from web applications — your local network addresses, browser plug-ins and do-not-track setting stay on your device. A VAT filing itself carries your organisation’s VAT registration number and the nine VAT return figures.

Payroll (RTI) submissions are prepared in the platform but are not yet transmitted to HMRC — the platform tells you plainly that nothing has been filed rather than pretending.

Who else receives data

We use a small set of service providers to run N Six Hub: hosting in the UK (OVH), subscription billing (Stripe), email delivery (currently relayed through Hostinger’s EU servers), AI (OpenAI and Google), voice synthesis (ElevenLabs), and geocoding and routing (TomTom, in the EU) — which means customer addresses you geocode reach TomTom. Address search can also fall back to Nominatim, a service run by the OpenStreetMap Foundation, which receives the address text you type. Map tiles and weather lookups send coordinates to open-data services. SMS and phone-call features, when enabled, route through Twilio or through a telephony account your organisation connects. The current list of sub-processors, with what each receives, is at nsixhub.com/legal/sub-processors.

Some things that look like third parties aren’t: calls and meetings run on our own self-hosted media servers, voice transcription runs on our own machines, and file storage sits on our own infrastructure.

Data also leaves the platform when your organisation sends it somewhere: automations and webhooks post record data to endpoints your organisation configures; merchant payment accounts your organisation connects (SumUp, Square, Adyen, Worldpay, Stripe) receive payment amounts and references under your organisation’s own agreement with the provider, with card details collected on the provider’s own pages; dialler integrations your organisation enables open the contact’s number with that dialler. If you connect your own mailbox, its password is stored encrypted and mail is fetched live — we don’t copy your mailbox contents. These recipients are chosen by your organisation or by you, not by us.

Inside the signed-in app, your browser loads fonts from Google and — when you use map features — Google Maps, so your IP address reaches Google. Our own support staff can access a workspace to help you or to investigate abuse; every such session is itself logged. We do not sell personal data, and there is no advertising anywhere in the product.

International transfers

Most processing happens in the UK — the platform is hosted on UK infrastructure. Some processing happens in the EU (email relay, TomTom geocoding), where transfers from the UK are covered by the UK’s adequacy regulations for the EEA.

OpenAI, Google, ElevenLabs, Stripe and Twilio process data in the United States. For those transfers the safeguard we rely on is the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, and we require it of each provider in its data-processing terms. If you want the specifics for a particular provider, email privacy@nsixhub.com.

How long we keep data

Different data runs on different clocks, and these are the real ones. Deleted automatically: detailed GPS history after 90 days; live staff locations after 31 days; AI usage logs after 180 days; webhook and application logs after 30 days; uploaded SMS audience spreadsheets after 30 days; files in the media bin after 30 days; disappearing chat messages within minutes of expiry; activity and security audit trails after 2 years; permission-change and platform-administration logs after 7 years; field-interaction history after 1 year.

Kept for as long as your account or organisation is active, or until deleted: business records and files, chat messages without a disappearing timer, recordings and transcripts, time entries, AI conversations, imported files and account profiles. Records moved to the bin stay there until someone permanently deletes them — there is no automatic purge of the record bin.

Kept as legal evidence regardless: billing and invoice records, marketing consent and opt-out records, and acceptances of our terms (recorded with the IP address and browser they were made from). Financial records are kept for as long as tax law requires.

Deletion — what actually happens

We would rather tell you precisely than reassure you vaguely. When an administrator deletes a user, the account is archived and recoverable from the bin — that is not erasure. Erasure is a separate, deliberate action: it replaces the person’s identity data in place, permanently disables sign-in, deletes their staff documents, notifications and device records, and ends their sessions. Records of work they did remain, attributed to an anonymised profile, and billing records and audit trails remain for their own legal and security lifetimes before expiring.

An organisation can export its records from within the platform. That export is not everything: stored files, chat and meeting data, and billing ledgers are not in the archive — each is available separately. An organisation can also permanently purge its data — a hard delete of the organisation’s records and stored files, behind a typed confirmation. Two honest caveats: audit trails survive a purge until their own expiry, and some communications data held in a separate database — end-to-end-encrypted chat message data, meeting records and voice and video call history — can currently persist beyond a purge. We say this because a policy that overstates deletion is worse than one that admits its edges.

Permanently deleting an individual record removes the record, but files attached to it can remain in storage until an organisation-level purge.

There is no self-service account deletion yet: erasure requests go through your organisation’s administrator, or straight to privacy@nsixhub.com if that isn’t workable.

Your rights

You have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to how it is used, and to receive a portable copy. Where we act as your organisation’s processor, your organisation is the right first door — but you can always email privacy@nsixhub.com, and we will pass the request on and help. Either way, we respond within one month.

Complaining to the regulator

You can complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or on 0303 123 1113. We would appreciate the chance to put things right first — email privacy@nsixhub.com — but that is your choice, not a condition.

How we protect data

Connections to the platform are encrypted in transit (TLS). Passwords are stored as one-way Argon2 hashes; sign-in sessions are short-lived and refresh tokens are stored only as hashes. Two-factor authentication is available on every account — authenticator codes, one-time email or SMS codes, or single-use backup codes.

Every request to the platform is scoped to the organisation established by its authentication token — organisation identity is never taken from what a client claims. Inside an organisation, access is governed by roles and record-level permissions, and fields marked sensitive can be masked from users without explicit access. Third-party credentials the platform holds for you — connected-service tokens, signing keys, mailbox passwords — are encrypted with AES-256-GCM.

Uploads are screened for malicious file types. Consequential actions are written to audit trails kept for two years, and administrators can review record-level activity. When our safeguards change, for better or worse, this page changes with them.

Cookies

This website sets no cookies. The platform sets three, all strictly necessary for keeping you signed in, plus functional browser storage — drafts, preferences, your own message-encryption keys. Nothing is analytics or advertising. The detail is in our Cookie Policy at nsixhub.com/legal/cookies.

Changes & contact

If this policy changes materially we will say so on this page, with the date of the change. Questions or requests: privacy@nsixhub.com for anything about personal data, hello@nsixhub.com for everything else.

Last updated: 3 September 2026.