Plugin privacy notice
Who is who
Section titled “Who is who”hackÜ Inc. acts as the processor. The data of the people who appear in the plugin —a company’s employees— belongs to that company, which is the controller and the one that decides what it is used for and how long it is kept.
If you are one of those people and you want to exercise your rights over your data, go to your employer. hackÜ handles those requests through them.
What data the plugin touches
Section titled “What data the plugin touches”The plugin does not create new data. It reads what already exists in hackÜ about the company you authorised:
| Category | What it includes |
|---|---|
| Identification | Name, email, phone, document, country |
| Training | Courses, pensums, progress, evaluations, surveys, challenges |
| Communication | Communications sent and the status of each delivery |
| Operations | Bulk uploads, points ranking, membership seats |
Free-text survey answers are counted but never returned. They are what a person wrote about themselves or about their colleagues, and there is no operational question that needs them.
Personal data is optional
Section titled “Personal data is optional”Name, email and phone appear only if two independent conditions are met:
- The hackÜ deployment allows it. That is a configuration decision, not the user’s.
- Whoever authorises grants the
users:piipermission on the consent screen.
If either of the two is missing, the plugin still works and people come through identified by an internal number. No answer invents a name it cannot see.
Where the data goes
Section titled “Where the data goes”When you ask a question, the answer travels to the assistant you are talking to. That means that assistant’s provider processes that data.
| Provider | When it applies |
|---|---|
| OpenAI OpCo, LLC | When using the plugin in ChatGPT or Codex |
hackÜ keeps a register of subprocessors and a signed data processing agreement with OpenAI. If your organisation has its own requirements about which providers may process its staff’s data, check them before granting the personal data permission.
Reports are the deliberate exception: their contents never pass through the conversation. hackÜ generates the file and sends a link to the email of whoever asked for it, who downloads it with their own session signed in.
What gets logged
Section titled “What gets logged”Every query leaves an audit entry in hackÜ: who asked, which tool they used, with which parameters, how many results they got and how long it took. It is there so the company can review who consulted what. The contents of the conversation are not stored.
Scope and limits
Section titled “Scope and limits”An authorisation is pinned to one single company, chosen at the moment of authorising. There is no way to query another one from that same authorisation.
Access is cut off on its own if you stop administering that company in hackÜ: it does not depend on somebody remembering to revoke it.
Except for requesting reports, the plugin does not modify or delete anything.
Retention
Section titled “Retention”Retention of the data you query is set by each company in its contract with hackÜ. The plugin introduces no deadlines of its own over it: it reads what is already stored.
The exception is the audit log described above, which is new data. It is kept under the same terms as the rest of the platform’s operational records, according to the contract with each company.
Contact
Section titled “Contact”Write to ventas@hacku.com or see www.hacku.com.
