Skip to content
TTeamHubby Doek Works
Commercial AgreementGeneral TermsPrivacy Notice
Legal documentation

Privacy Notice

Official TeamHub documentation from Doek Works.

Page updated September 22, 2026

TeamHub Privacy Notice

Version 0.1 - Draft Effective: [Effective date] Last updated: [Last updated date]

Draft notice: This Privacy Notice contains placeholders and assumptions that must be completed and verified before publication. In particular, the sections concerning service providers, cookies, analytics, community telemetry and retention periods must be aligned with the actual technical and business processes. This document is not legal advice and should be reviewed by a qualified privacy professional or lawyer before use.

1. Who we are

Doek Works, a sole proprietorship (eenmanszaak) trading as Doek Works, is responsible for the processing of personal data described in this Privacy Notice.

Our details are:

  • Legal name: Doek Works
  • Trading name: Doek Works
  • Legal form: Sole proprietorship (eenmanszaak)
  • Registered address: Elzenlaan 21
  • Postal code and city: 9422 ES Smilde
  • Country: The Netherlands
  • Dutch Chamber of Commerce number: [Chamber of Commerce number]
  • VAT number: [VAT number]
  • Website: [Website URL]
  • General email address: [General email address]
  • Privacy contact: [Privacy email address]

In this Privacy Notice, we refer to ourselves as “we”, “us” or “our”.

2. Scope of this Privacy Notice

This Privacy Notice explains how we process personal data in connection with:

  1. our website and online forms;
  2. requests for information, demonstrations or Trial Licence Keys;
  3. commercial TeamHub subscriptions;
  4. orders, payments, invoicing and accounting;
  5. the creation and administration of TeamHub Licence Keys;
  6. customer support and business communication;
  7. consultancy, implementation, training and custom-development services;
  8. security and vulnerability reports;
  9. newsletters or marketing communication, if offered; and
  10. community usage telemetry, where applicable.

This Privacy Notice applies to personal data for which we determine the purposes and means of processing and therefore act as controller.

3. TeamHub customer environments

TeamHub is a self-hosted Nextcloud application. It normally runs inside a Nextcloud environment selected, hosted or managed by the customer or its service provider.

We do not host and do not routinely access the files, messages, team information, user accounts or other content processed within a customer's TeamHub and Nextcloud environment.

Providing TeamHub or a commercial Licence Key does not, by itself, make us a processor of the personal data stored in the customer's environment.

If a customer separately asks us to process personal data on its behalf, for example through remote administration, data migration or support involving access to personal data, the parties will determine whether a separate data processing agreement is required before that processing begins.

4. Personal data we may process

The personal data we process depends on how you interact with us.

4.1 Website and contact data

When you visit our website or contact us, we may process:

  • your name;
  • your business email address;
  • your telephone number, if provided;
  • your organisation and job title;
  • the subject and content of your message;
  • the date and time of the communication;
  • correspondence history;
  • your IP address and basic technical request information contained in webserver or security logs; and
  • cookie or analytics information, where applicable.

4.2 Trial request data

When you request a TeamHub Trial, we may process:

  • your name;
  • your organisation;
  • your business email address;
  • your telephone number, if provided;
  • the applicable Nextcloud Instance UUID;
  • the requested or expected number of Seats;
  • your intended use case or reason for requesting a Trial, if requested;
  • the Trial start and expiry dates;
  • the Trial Licence ID; and
  • correspondence concerning the Trial.

4.3 Customer, order and billing data

When an organisation orders Products or Services, we may process:

  • the customer's legal and trading names;
  • registered and billing addresses;
  • Dutch Chamber of Commerce or equivalent registration number;
  • VAT or tax identification number;
  • names and business contact details of authorised representatives, administrators and billing contacts;
  • Order, quotation, contract and invoice numbers;
  • subscription plan and ordered quantities;
  • payment status, payment reference and transaction information;
  • bank-account information where payment is made by bank transfer;
  • correspondence concerning the Order or invoice; and
  • contract-acceptance records, including accepted document versions, date, time and account or contact details.

We normally do not directly receive or store full payment-card details. Where an external payment provider is used, that provider processes the payment information required to complete the transaction under its own privacy information.

Payment provider: [Name of payment provider or “To be determined”] Payment provider privacy notice: [URL]

4.4 Licence administration data

To create and administer a TeamHub commercial Licence Key, we may process:

  • customer reference;
  • Licence ID;
  • subscription type;
  • ordered number of Seats;
  • technical Licence Key Seat capacity;
  • production Instance UUID;
  • non-production Instance UUID, where applicable;
  • Licence Period, start date and expiry date;
  • Trial status, where applicable;
  • payment and renewal status; and
  • records of replacement, migration and add-on Licence Keys.

A TeamHub Licence Key may contain a Licence ID, customer reference, Instance UUID, subscription type, Seat capacity, start date, expiry date and digital signature.

The Licence Key does not contain TeamHub user identities, messages, files or other customer content stored inside the Nextcloud environment.

Licence Key validation takes place locally inside the customer's Instance. TeamHub does not contact us to validate a commercial Licence Key.

4.5 Support and service data

When you request support or other Services, we may process:

  • name, organisation and business contact details;
  • support request and correspondence;
  • TeamHub and Nextcloud version numbers;
  • relevant dependent-app versions;
  • technical configuration information;
  • log extracts, screenshots and diagnostic information voluntarily supplied by the customer;
  • information about changes made to the Software;
  • appointment, training or consultancy information;
  • time records and work notes; and
  • temporary access information where remote access is separately agreed.

Customers should remove personal data, credentials and confidential information that is not reasonably required for support before providing logs, screenshots or other diagnostic material.

We will not request permanent access to a customer's environment as part of a standard TeamHub commercial subscription.

4.6 Security and vulnerability reports

When you report a vulnerability or security concern, we may process:

  • your name or chosen identifier;
  • your contact details;
  • organisation or affiliation, if provided;
  • technical details of the report;
  • affected versions and environments;
  • communication concerning investigation and coordinated disclosure; and
  • acknowledgements or credit preferences.

4.7 Newsletter and marketing data

If we offer a newsletter or other direct marketing, we may process:

  • name;
  • business email address;
  • organisation;
  • subscription preferences;
  • consent record, where consent is used;
  • date of subscription and unsubscription; and
  • limited delivery or engagement information, if enabled.

Current marketing tools: [None / Name of provider] Marketing tracking enabled: [Yes / No / To be determined]

4.8 Community usage telemetry

TeamHub installations without an active paid Licence Key or Trial may send community usage telemetry as described in the separate TeamHub Telemetry Notice.

The Telemetry Notice must identify:

  • the exact fields transmitted;
  • the transmission frequency;
  • the receiving endpoint;
  • whether a persistent or rotating identifier is used;
  • whether the Instance UUID, hostname or customer reference is transmitted;
  • technical metadata received by the server, including IP-address logging where applicable;
  • the purposes of the processing;
  • the applicable legal basis;
  • retention periods;
  • recipients and hosting location; and
  • available controls or methods to prevent transmission.

Usage telemetry is disabled while:

  1. a paid TeamHub Licence Key is valid;
  2. a paid Licence Key is within its fourteen-day Grace Period; or
  3. a Trial Licence Key is valid.

After an active Licence Key, Trial or applicable Grace Period ends, the Instance may return to the community telemetry state described in the Telemetry Notice.

Telemetry Notice URL: [Telemetry Notice URL] Telemetry endpoint: [Telemetry endpoint] Telemetry hosting provider and region: [Provider and region] Telemetry retention period: [Retention period]

Required before publication: Replace this subsection with verified technical details and make the Telemetry Notice available from the TeamHub administration interface and website.

5. Why we process personal data and our legal bases

We process personal data only where we have an appropriate legal basis.

5.1 To enter into and perform an agreement

We may process personal data where necessary to:

  • prepare and respond to a quotation or Order;
  • process a commercial subscription;
  • create, deliver and administer Licence Keys;
  • provide support, maintenance, consultancy, training or custom development;
  • communicate about the Agreement;
  • process renewals, add-ons or Instance migrations; and
  • handle contractual complaints.

The legal basis is the performance of a contract or steps requested before entering into a contract. Where the customer is an organisation rather than the individual concerned, we may instead rely on our legitimate interest in entering into and performing the business relationship with that organisation.

5.2 To comply with legal obligations

We may process personal data to comply with tax, accounting, administrative, sanctions and other legal obligations.

The legal basis is compliance with a legal obligation.

5.3 For our legitimate business interests

We may process personal data where necessary for legitimate interests such as:

  • maintaining customer and supplier relationships;
  • answering business enquiries;
  • securing our website, systems and Licence Key process;
  • preventing fraud and misuse;
  • maintaining appropriate business and support records;
  • establishing, exercising or defending legal claims;
  • improving our Products and Services using appropriately limited information;
  • investigating defects and security incidents; and
  • protecting our legal and commercial interests.

Where we rely on legitimate interests, we assess whether the processing is necessary and balance our interests against the rights and interests of the individuals concerned.

5.4 Consent

We may rely on consent for optional processing, including:

  • receiving an optional newsletter;
  • non-essential cookies or analytics where consent is required; and
  • other clearly identified voluntary processing.

Consent may be withdrawn at any time. Withdrawal does not affect processing that was lawful before withdrawal.

5.5 Community telemetry legal basis

The legal basis for community telemetry must be established and documented after the final telemetry design has been verified.

Proposed legal basis: [Consent / Legitimate interests / Other basis, subject to legal review]

A detailed necessity and balancing assessment must be completed if legitimate interests are used. If consent is used, the telemetry must not start before a valid choice has been made and consent must be as easy to withdraw as it was to provide.

6. Sources of personal data

We normally receive personal data:

  • directly from you;
  • from your employer or organisation;
  • from an authorised reseller, managed service provider or hosting provider;
  • through our website and ordering process;
  • through our payment and accounting providers;
  • through support, consultancy and security communications;
  • from public business registers and professional sources where relevant; and
  • through community telemetry, as described in the Telemetry Notice.

If an organisation provides us with another person's data, that organisation is responsible for ensuring it is authorised to do so and, where required, for informing that person.

7. Sharing personal data

We do not sell personal data.

We may share personal data where reasonably necessary with:

  • website and infrastructure hosting providers;
  • email and communication providers;
  • payment providers and banks;
  • accounting software providers, accountants and tax advisers;
  • customer-support or ticketing providers;
  • analytics or cookie providers, where used;
  • security, monitoring and backup providers;
  • professional advisers, including lawyers and insurers;
  • contractors and subprocessors supporting our Products or Services;
  • competent authorities where disclosure is legally required; and
  • a buyer, investor or legal successor in connection with a genuine business transfer, subject to appropriate confidentiality safeguards.

Our current relevant service providers will be identified below or in a separate Subprocessor and Service Provider List.

PurposeProviderProcessing locationMore information
Website hosting[Provider][Country/region][URL]
Business email[Provider][Country/region][URL]
Payments[Provider][Country/region][URL]
Accounting[Provider][Country/region][URL]
Customer support[Provider or email only][Country/region][URL]
Analytics[None / Provider][Country/region][URL]
Newsletter[None / Provider][Country/region][URL]
Telemetry endpoint[Provider][Country/region][URL]
Backups and storage[Provider][Country/region][URL]

8. International transfers

We aim to use service providers that process personal data within the European Economic Area where reasonably possible.

If personal data is transferred outside the European Economic Area, we will use an appropriate transfer mechanism where required, such as:

  • an adequacy decision;
  • European Commission standard contractual clauses;
  • another legally recognised transfer mechanism; or
  • an applicable legal exception.

Current transfers outside the EEA: [None identified / Describe transfers]

Information concerning relevant transfer safeguards may be requested using the privacy contact details in section 1.

9. Retention

We retain personal data no longer than reasonably necessary for the purposes described in this Privacy Notice, unless a longer period is required by law or is reasonably necessary for legal claims.

Our proposed retention periods are:

CategoryProposed retention period
General contact enquiriesUp to 12 months after the enquiry is closed
Unsuccessful quotationsUp to 12 months after expiry or rejection
Order and contract recordsDuration of the relationship plus [2 years / other period]
Licence administration recordsLicence Period plus [2 years / other period]
Invoice and accounting recordsPeriod required under applicable tax and accounting law
Support recordsUp to [2 years] after closure of the request
Consultancy and project recordsDuration of the project plus [2 years / other period]
Security reportsAs long as reasonably necessary for investigation, remediation, disclosure and accountability
Website and security logs[30 days / other period]
Newsletter dataUntil unsubscription, plus a limited suppression record where necessary
Community telemetry[Retention period to be determined]
Legal claimsAs long as reasonably required for the relevant limitation or claim period

We may retain limited records longer where required to demonstrate compliance, prevent repeated misuse or maintain an unsubscribe or suppression list.

10. Cookies and website analytics

Our website may use cookies or similar technologies required for security, operation and user preferences.

Current cookie configuration: [No cookies / Necessary cookies only / Describe cookies]

Current analytics configuration: [No analytics / Privacy-friendly analytics / Provider and configuration]

Where required by law, non-essential cookies and similar technologies will not be used before the visitor has made a valid choice.

Further information will be made available in [Cookie Notice URL / this section after final configuration].

11. Security

We use reasonable technical and organisational measures appropriate to the nature of the personal data and the risks involved.

These measures may include:

  • access controls and least-privilege access;
  • multi-factor authentication where available;
  • encryption in transit;
  • appropriate backups;
  • system and dependency updates;
  • logging and security monitoring;
  • confidentiality obligations;
  • limited retention;
  • secure Licence Key generation and storage procedures; and
  • incident-response procedures.

No method of electronic storage or transmission is completely secure. We therefore cannot guarantee absolute security.

12. Your privacy rights

Depending on the circumstances and applicable law, you may have the right to:

  • obtain information about our processing of your personal data;
  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • request data portability where applicable;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with a competent supervisory authority.

These rights are not absolute. We may need to retain or continue processing certain data where required by law, necessary for contractual administration, or necessary for legal claims.

To exercise a privacy right, contact us at [Privacy email address]. We may request reasonable information to verify your identity and protect personal data against unauthorised disclosure.

We will respond within the period required by applicable law.

13. Complaints

Please contact us first if you have a question or concern about our use of personal data. We will try to resolve the matter appropriately.

You also have the right to lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens Website: https://www.autoriteitpersoonsgegevens.nl/

If you live or work in another European Economic Area country, you may also contact the supervisory authority in that country.

14. Automated decision-making

We do not use personal data for automated decision-making that produces legal effects or similarly significant effects on individuals.

If this changes: [Describe the logic, significance and expected consequences before implementation.]

15. Children

Our Products and Services are intended for organisations and business users. We do not knowingly offer commercial TeamHub subscriptions directly to children or collect children's personal data for those subscriptions.

TeamHub may be used by customer organisations in environments that include users under the age of 18. The relevant customer controls that environment and is responsible for determining the lawful basis, notices, permissions and safeguards applicable to those users. We do not routinely receive the personal data of those users.

16. Links and third-party services

Our website and documentation may contain links to third-party websites, products or services. Their privacy practices are governed by their own privacy notices. We are not responsible for third-party privacy practices outside our control.

17. Changes to this Privacy Notice

We may update this Privacy Notice when our organisation, Products, Services, suppliers or legal obligations change.

The current version and effective date will be shown at the beginning of this document.

Where a change is material, we will take reasonable steps to bring it to the attention of affected persons, for example through our website, email or the TeamHub administration interface.

Earlier versions are available from us on request where reasonably required.

18. Contact

For privacy questions, requests or complaints, contact:

Doek Works Attn: Privacy Elzenlaan 21 9422 ES Smilde The Netherlands

Email: [Privacy email address] Website: [Website URL]


Completion checklist before publication

The following items must be completed or verified before this Privacy Notice is published:

  • [ ] Insert the legal entity, trading name, address, KVK number and VAT number.
  • [ ] Insert the privacy, general and website contact details.
  • [ ] Confirm website hosting provider, country and webserver-log retention.
  • [ ] Confirm payment provider and link its privacy notice.
  • [ ] Confirm accounting provider or accountant arrangements.
  • [ ] Confirm business email provider and processing region.
  • [ ] Confirm whether support is handled only by email or through another platform.
  • [ ] Confirm website cookies, analytics, external embeds and consent mechanism.
  • [ ] Confirm newsletter and marketing tools, if any.
  • [ ] Verify the exact data requested for Trials.
  • [ ] Verify all fields stored in the licence system and Licence Key.
  • [ ] Confirm whether temporary remote support access may occur.
  • [ ] Complete all retention periods.
  • [ ] Create and publish the TeamHub Telemetry Notice.
  • [ ] Verify the exact telemetry payload, frequency, endpoint, identifiers and server logs.
  • [ ] Determine and document the lawful basis for community telemetry.
  • [ ] Complete any required legitimate-interest assessment or consent flow.
  • [ ] List relevant service providers and international transfers.
  • [ ] Confirm whether a Cookie Notice is required.
  • [ ] Ensure this document is linked before or at data collection points.
  • [ ] Have the completed document legally reviewed before use.

TeamHub Privacy Notice Version 0.1 - Draft Effective: [Effective date]

Doek Works
Elzenlaan 21, 9422 ES Smilde, The Netherlands

TeamHub
One view. Every team. Everything connected.