Hosted in France
The application servers and the database are located in France, with a European operator. No data is transferred outside the European Union.
HubPlace sees inside your IT estate. We take that responsibility seriously: here is exactly how your data is handled.
The application servers and the database are located in France, with a European operator. No data is transferred outside the European Union.
Every exchange — browser and agents alike — goes over HTTPS/TLS. Passwords are hashed with bcrypt and never stored in clear text.
Each organisation has its own perimeter. A request cannot cross an organisation boundary, not even through a mistyped URL.
Each module (estate, health, tickets, projects, applications) is enabled independently per user or per group.
The technical credential vault stores passwords encrypted; every reveal is logged.
Administration actions are logged, and the change history of each endpoint is kept for the period you define.
This is the first thing IT managers check: the HubPlace agent listens on no port and accepts no inbound connection.

HubPlace processes a limited volume of personal data: that of your users (name, work email address) and the link between an endpoint and a person. Here is the applicable framework.
Thiris, the publisher of HubPlace, acts as a processor within the meaning of Article 28 of the GDPR. You remain the controller for your users' and your estate's data.
Data is processed for the sole purpose of delivering the service: inventory, monitoring, support and project management. It is never sold, never used for advertising and never used to train models.
Health analysis sends anonymised technical indicators to an AI model (usage rates, pending patches, drive status). No user name and no file content is sent.
Monitoring data is kept for the period you configure, up to twelve months by default. Deleting your workspace permanently erases your data.
Access, rectification, erasure, portability and restriction can be exercised from your workspace or on request to our contact address. We respond within thirty days.
The list of technical providers (hosting, email and SMS delivery, AI analysis) is available on request and kept up to date.
No. Every query is filtered on the signed-in user's organisation, at database level. There is no cross-tenant view available to customers.
Only technical administrators, for operations and support purposes, and only when necessary. Those accesses are logged.
You export your data to Excel, then request deletion of your workspace. Erasure is permanent and confirmed in writing.
Yes. A processing agreement compliant with Article 28 of the GDPR is available on request, along with a description of the technical and organisational measures.
Optional remote access runs through an encrypted outbound tunnel initiated by the appliance on your network. It is disabled by default.
Write to us: we answer precisely, including to your IT department's security questionnaires.