Privacy Policy
Effective Date: Mart 19, 2026
1. General Information
This Privacy Policy defines how personal data is collected, used, stored, and protected within the GDHub platform.
The document is designed in accordance with GDPR (EU Regulation 2016/679) and reflects best practices for digital platforms, including those participating in EU funding and grant programs (e.g. AMIF, EIT, Creative Europe).
2. Data Controller
Operator (Data Controller):
Individual Entrepreneur DZMITRY DRYNAU
Registered office address: Georgia, Tbilisi, Samgori District, Police Street I Dead End, N5, 0182
Email: info@gdhub.io
3. Categories of Data
3.1 Public Profile Data
This data is visible to other users of the platform:
- First name, last name
- Profile photo
- Skills, experience, portfolio links
- Tools and technologies used
- Availability (time commitment)
- Participation in projects
Purpose: collaboration, team formation, visibility in the ecosystem
3.2 Private Data (Restricted Access)
This data is not publicly visible:
- Email address
- Year of birth
- IP address
- Technical logs
- Account activity
Purpose: authentication, security, analytics
3.3 Communication Data
- Telegram / Discord username
- Messages or interactions (if applicable in future features)
Purpose: enabling collaboration and communication
3.4 Optional Data
- City / country
Purpose: improving matching, localization
4. Purposes of Processing
Data is processed for:
- Providing core platform functionality
- Enabling collaboration between users
- Supporting user accounts and authentication
- Improving the Service (analytics, UX)
- Ensuring security and fraud prevention
- Complying with legal obligations
5. Legal Basis
Processing is based on:
- Contract (Terms of Service)
- Consent
- Legitimate interest (platform development, security)
6. Infrastructure & Subprocessors
To operate the platform, GDHub uses third-party services (“subprocessors”).
Core Infrastructure:
- Cloud Hosting: Vercel
- Database: PostgreSQL (managed hosting providers)
- Authentication & APIs: custom backend services
- Analytics (optional): may include tools like Google Analytics or similar
- Communication tools: Telegram / Discord (user-initiated)
These providers may process data on behalf of the Operator under contractual agreements.
7. Data Processing Agreement (DPA)
If GDHub provides services to organizations (e.g. studios, universities, incubators), a Data Processing Agreement (DPA) may apply.
In such cases:
- GDHub acts as a Data Processor
- The client organization acts as a Data Controller
The DPA includes:
- scope and purpose of processing
- data categories
- security measures
- confidentiality obligations
- subprocessors list
- data subject rights support
- breach notification procedures
A standard DPA can be provided upon request at privacy@gdhub.io
8. Data Retention
Data is retained:
- while the account is active
- up to 30 days after deletion (for recovery/security)
- longer if required by law
After retention period:
- data is deleted or anonymized
9. Cross-Border Transfers
Data may be transferred outside the user’s country, including outside the EU.
Safeguards include:
- Standard Contractual Clauses (SCCs)
- GDPR-compliant providers
- secure infrastructure
10. Security Measures
GDHub applies:
- HTTPS encryption
- access control (role-based)
- secure authentication
- infrastructure monitoring
- regular updates
11. Cookies
Cookies are used for:
- session management
- preferences
- analytics
Users can disable cookies in browser settings.
12. Data Sharing
Data may be shared:
- with infrastructure providers (hosting, analytics)
- when required by law