Privacy and compliance.
This page sets out the legal and regulatory framework Performance Hub operates within, the certifications that sit underneath the platform, and where Performance Hub itself stands - without overstating certification claims.
The privacy framework.
Performance Hub is a global platform, operated by a US-registered company, serving customers across many jurisdictions. We manage personal information in accordance with the privacy and data protection laws that apply to us and to your deployment, including:
- The General Data Protection Regulation (GDPR) for European and UK data.
- United States frameworks, including the California Consumer Privacy Act (CCPA) and other applicable state privacy laws.
- The Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
- Other regional regimes referenced in our privacy policy, including Canada's PIPEDA and Japan's APPI.
Rather than being anchored to a single jurisdiction, our approach is to meet the requirements of whichever of these regimes applies to a given customer, facility or data flow.
The full statement of how we collect, use, disclose and protect personal information is in the Privacy Policy. This page summarises the parts a trust review cares about.
Data controller vs data processor.
For video, people analytics and biometric features, the roles are explicit:
- Your organisation is the data controller. You decide what is collected, why, and how long it is kept.
- Performance Hub is the data processor / service provider, processing that data on your behalf and under your configuration.
This allocation matters for CCTV and biometric features in particular: lawful operation (consent, signage, lawful basis) sits with you as the operator, and Performance Hub provides the controls to do it properly. See Video, vision & facial recognition and Shared responsibility.
International transfers.
- Where personal information is transferred outside the jurisdiction it was collected, this is done only where permitted under applicable privacy laws.
- For European data, transfers outside the EEA are governed by EU standard contractual clauses (SCCs) or equivalent measures with the receiving party.
- You control the storage region for your facility's backups and footage, which is the primary mechanism for meeting data-residency obligations (see Data ownership, residency & lifecycle).
Specific privacy machinery.
- No card data held. Performance Hub does not collect or hold credit card details; payments are processed by trusted payment gateway providers including Stripe.
- Verified deletion. Account and data deletion requests pass through additional identity checks and safeguards before they are processed, so a request cannot be actioned without confirming it is genuine.
- Retention and legal holds. Personal information is retained only as long as necessary, unless a longer period is required by law (in some cases up to seven years). When retention is not required, data is deleted, destroyed or de-identified.
- Data minimisation controls. Optional contact fields (email, phone, address) are only stored when you enable them, and turning a field off removes its stored values, not just hides them.
Certified, independently audited foundations.
Performance Hub is a platform of layers. The infrastructure providers we build on hold the major independent certifications, so the foundation your deployment runs on is independently audited, not just asserted by us.
Those certifications belong to the infrastructure providers. Performance Hub's own security controls, documented across this Trust Centre, operate on top of that certified foundation. The current list of providers, roles, certifications and sources is published on Sub-processors & infrastructure - that page is the single place we keep it up to date.
Where Performance Hub stands.
Performance Hub is not currently SOC 2 or ISO 27001 certified, and this page does not claim otherwise. What is true and defensible today:
- A global privacy posture that meets GDPR, US state privacy laws, the Australian Privacy Principles and other applicable regimes, with international transfers built on SCCs.
- Customer-controlled, per-facility data residency.
- A documented, verifiable security architecture (see Security architecture).
- Continuous security operations: audit logging, centralised cloud security posture monitoring, perimeter and vulnerability scanning, and dependency monitoring.
- Independently certified infrastructure underneath the platform (see Sub-processors & infrastructure).
We will update this page as our own certification posture changes.