Skip to content

Plugin privacy notice

hackÜ Inc. acts as the processor. The data of the people who appear in the plugin —a company’s employees— belongs to that company, which is the controller and the one that decides what it is used for and how long it is kept.

If you are one of those people and you want to exercise your rights over your data, go to your employer. hackÜ handles those requests through them.

The plugin does not create new data. It reads what already exists in hackÜ about the company you authorised:

Category What it includes
Identification Name, email, phone, document, country
Training Courses, pensums, progress, evaluations, surveys, challenges
Communication Communications sent and the status of each delivery
Operations Bulk uploads, points ranking, membership seats

Free-text survey answers are counted but never returned. They are what a person wrote about themselves or about their colleagues, and there is no operational question that needs them.

Name, email and phone appear only if two independent conditions are met:

  1. The hackÜ deployment allows it. That is a configuration decision, not the user’s.
  2. Whoever authorises grants the users:pii permission on the consent screen.

If either of the two is missing, the plugin still works and people come through identified by an internal number. No answer invents a name it cannot see.

When you ask a question, the answer travels to the assistant you are talking to. That means that assistant’s provider processes that data.

Provider When it applies
OpenAI OpCo, LLC When using the plugin in ChatGPT or Codex

hackÜ keeps a register of subprocessors and a signed data processing agreement with OpenAI. If your organisation has its own requirements about which providers may process its staff’s data, check them before granting the personal data permission.

Reports are the deliberate exception: their contents never pass through the conversation. hackÜ generates the file and sends a link to the email of whoever asked for it, who downloads it with their own session signed in.

Every query leaves an audit entry in hackÜ: who asked, which tool they used, with which parameters, how many results they got and how long it took. It is there so the company can review who consulted what. The contents of the conversation are not stored.

An authorisation is pinned to one single company, chosen at the moment of authorising. There is no way to query another one from that same authorisation.

Access is cut off on its own if you stop administering that company in hackÜ: it does not depend on somebody remembering to revoke it.

Except for requesting reports, the plugin does not modify or delete anything.

Retention of the data you query is set by each company in its contract with hackÜ. The plugin introduces no deadlines of its own over it: it reads what is already stored.

The exception is the audit log described above, which is new data. It is kept under the same terms as the rest of the platform’s operational records, according to the contract with each company.

Write to ventas@hacku.com or see www.hacku.com.