HUGIN
Legal

Privacy Policy

Official Hugin legal terms from Fixeon AI Labs.

Effective date: June 16, 2026

Last updated: June 27, 2026

Operator: Fixeon AI Labs ("Hugin," "we," "us," or "our")

Contact: fixeonai@gmail.com

Registered address: No.2 Haile Selassie Street, Asokoro, Abuja, Nigeria

This Privacy Policy explains how Fixeon AI Labs collects, uses, shares, and protects information in connection with Hugin. It applies to our website at gethugin.com, the Hugin application at app.gethugin.com, our APIs, MCP endpoints, integrations, workflows, documentation, support, and related services (together, the "Service").

This Policy is written to cover Hugin as it exists today and to keep covering Hugin as it grows — including future features, connectors, AI capabilities, models, APIs, billing options, providers, and related services — unless we publish a separate notice for a specific feature. We describe categories of data, providers, and processing rather than listing every individual feature, so that ordinary product changes do not leave this Policy out of date. Our current list of third-party providers is maintained on our Subprocessors page.

1. What Hugin Does

Hugin is company brain infrastructure for AI-native teams. Hugin lets a team connect approved business data sources, process and organize that data into reusable context, apply permissions and redaction rules, deliver selected context and reusable company procedures to authorized AI tools, agents, copilots, and workflows, and, where enabled, let those tools take approved actions in connected applications through product interfaces and MCP/API integrations. Hugin is a business-to-business product intended for organizational use.

2. Our Role: Controller and Processor

Data protection laws distinguish between a "controller" (who decides why and how data is processed) and a "processor" (who processes data on a controller's behalf).

  • For account, workspace, billing, support, security, and website/analytics data, Hugin generally acts as a controller, and this Policy governs that processing.
  • For the content a customer connects, ingests, pushes, or retrieves through Hugin ("Customer Data"), Hugin generally acts as a processor that processes the data on the customer's documented instructions. The customer is the controller and is responsible for the lawful basis, notices, and consents for that data. Our processing of Customer Data is governed by this Policy together with the customer's agreement and our Data Processing Addendum.

3. Information We Collect

We collect and process information needed to provide, secure, bill for, support, and improve Hugin.

Account and workspace information

Names, email addresses, hashed passwords or third-party (e.g. Google) sign-in identities, user identifiers, workspace names and slugs, workspace memberships and roles, access and governance settings, support level, and related account metadata. Authentication identities are held by our authentication provider.

Connected source information (Customer Data)

When a customer connects a source, Hugin reads data from approved sources at the customer's direction. Depending on the connectors a customer enables and the scopes they grant, this may include messages, emails, documents, files, issues, tickets, records, calendar events, media, metadata, permission snapshots, and source scope rules. Where the customer enables approved actions for a specific customer, source, and action, Hugin may also process action names, argument schemas, customer-provided action inputs, dry-run previews, approval metadata, execution status, and result summaries for the connected application. The exact data depends entirely on the customer's configuration and the permissions the customer grants. Available source connectors change over time; current examples are listed on our Subprocessors page and shown in the product.

Custom and push source data

If a customer uses custom or push ingestion, Hugin may process records the customer sends, including external IDs, object types, text content, structured payloads, timestamps, metadata, content hashes, permission information, and deletion/tombstone signals.

Context, processing, and retrieval data

To operate the Service, Hugin creates and stores processing artifacts. These may include raw source object records, normalized objects, object versions, synthesized context and wiki pages, content chunks, embeddings, extracted entities and relationships, facts, timeline entries, context requests, the text of queries made to Hugin (for example agent task descriptions), selected results, citations, redaction summaries, reusable skill drafts and published skill packages, skill references/assets, skill freshness and lineage records, action allowlists, dry-run and approval records, action execution audit summaries, trace identifiers, and operational metadata. Records of model executions store cryptographic hashes of inputs/outputs and routing metadata rather than the underlying prompt and response content.

Billing and subscription information

Hugin uses Polar as its Merchant of Record for purchases. We process billing-account identifiers, customer name and email, checkout and subscription details, plan and add-on selections, prepaid context-ops packs, usage ledger records, cancellation requests, refund metadata, and provider identifiers. Full payment card details are handled by Polar and its payment processor and are not received or stored by Hugin. See our Refund Policy and Section 6 of our Terms of Service.

Support information

If you contact support, we process your messages, contact details, the contents of any attachments you send, and related metadata in order to help you.

Logs, analytics, diagnostics, and security data

Request and trace identifiers, sanitized operational metadata, rate-limit and security events, audit events, webhook and provider event identifiers, error information, workflow status, and product analytics events. Our analytics are configured to strip sensitive values — including message/query content, prompts, emails, secrets, and tokens — before any event reaches our analytics provider. Connection and security metadata such as IP addresses may be processed by our hosting, authentication, security (CAPTCHA), and analytics providers for security and reliability.

Website and marketing information

On our website, if you submit a form (for example a resource opt-in or a demo/booking request), we collect the information you provide, such as your name and email, and route it to our marketing and scheduling tools. Our website also uses first-party identifiers stored in your browser to understand site usage. See our Cookie & Tracking Policy for detail on the identifiers we use and your choices.

4. How We Use Information

We use information to:

  • provide, operate, maintain, and secure Hugin;
  • connect to and read from approved customer sources at the customer's direction;
  • process, normalize, index, retrieve, and serve context to authorized AI tools;
  • author, store, refresh, publish, and serve reusable company procedures where the customer uses skill features;
  • list, preview, approve, execute, meter, and audit approved connected-app actions where the customer enables action features;
  • enforce workspace membership, roles, source access rules, object-type limits, redaction, skill grants, action grants, approval settings, and consumer permissions;
  • create traces, evidence, lineage, and audit records;
  • manage subscriptions, entitlements, usage, checkout, cancellations, credits, refunds, trials, and support level;
  • detect, prevent, and respond to misuse, abuse, security threats, rate-limit violations, and service failures;
  • debug, monitor, maintain, and improve the Service (without using Customer Data to train AI models — see Section 5);
  • communicate with you about service, security, billing, legal, and support matters, and (where permitted) about products and updates you can opt out of;
  • comply with legal obligations and enforce our agreements.

5. AI and Model Processing

Hugin sends selected Customer Data to AI model providers only as needed to process, summarize, embed, classify, transcribe, retrieve, construct context, or draft/refine customer-authorized skill content for the customer's authorized use cases. All such traffic is routed through a single model gateway, and our standing commitments are:

  • No training on your data. We do not use Customer Data to train, fine-tune, or otherwise improve any AI model, ours or a third party's. Model calls are inference-only.
  • Zero data retention enforced in code. Every model request is forced into zero-data-retention mode (the gateway sets "deny data collection" and "zero data retention" on every call, and our code rejects any attempt to override this). Approved model routes are limited to providers that support no-retention processing.
  • Transparency. Hugin produces AI-assisted outputs (context packets, summaries, entities, relationships, skill drafts, traces, and similar). AI systems can produce inaccurate, incomplete, biased, or unexpected outputs. Customers are responsible for reviewing AI outputs before relying on them, and must apply human review for legal, financial, medical, employment, security, or other high-impact decisions. See our Acceptable Use Policy.

6. Third-Party Providers (Subprocessors)

We use vetted third-party providers to operate Hugin, across hosting, database/authentication/storage, background processing, caching, AI model routing, billing, email, analytics, security, and connector integration. The current, authoritative list — with each provider's purpose, the data categories it processes, and its location — is maintained on our Subprocessors page, which forms part of this Policy.

These providers process information on our behalf under contract, or as described in their own terms. We may add, replace, or remove providers as Hugin evolves; the Subprocessors page is updated accordingly, and customers with a signed DPA receive change notifications as described there. Customers are responsible for any third-party sources, connected applications, or AI tools they choose to connect to Hugin.

7. Legal Bases for Processing

Where the GDPR, UK GDPR, the Nigeria Data Protection Act 2023 ("NDPA"), or similar laws apply, we rely on one or more of the following legal bases:

  • Performance of a contract — to provide the Service you or your organization signed up for;
  • Legitimate interests — to secure, support, debug, and improve the Service, prevent abuse, and run our business, balanced against your rights;
  • Consent — where required, for example certain marketing communications or non-essential website identifiers (you may withdraw consent at any time);
  • Legal obligation — to comply with applicable law, including tax, accounting, and lawful requests;
  • Protection of vital interests / rights — to protect the rights, safety, and security of users, the public, and Hugin.

For Customer Data we process as a processor, the customer (as controller) is responsible for establishing the legal basis.

8. How We Share Information

We may share information with:

  • our subprocessors, who help us run Hugin (see Section 6);
  • customer-authorized AI tools, consumers, integrations, and connected sources, according to the customer's configuration, including sending action instructions or related data to connected applications where approved actions are enabled;
  • administrators and members of the relevant workspace, according to workspace roles and settings;
  • professional advisors, auditors, insurers, and legal representatives;
  • authorities, regulators, courts, or law enforcement when required by law or necessary to protect rights, safety, and security;
  • a successor or buyer in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to this Policy.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use third-party advertising cookies. If applicable law defines certain analytics activities as a "sale" or "sharing," we will provide legally required choices.

9. Security

Hugin is designed with layered technical and organizational controls, including: workspace isolation enforced by row-level security; role-based access checks; encryption of ingested source content at rest (AES-256-GCM) and encryption in transit (HTTPS); hashing of access tokens, consumer credentials, and approval tokens where used; private storage buckets with short-lived signed URLs; webhook signature verification; rate limiting and idempotency; schema validation for configured actions; always-on prompt-injection detection on retrieval and supported authoring surfaces; redaction options; trace and audit logging; least-privilege server boundaries; and secrets held in managed environment configuration. No system is perfectly secure. Customers are responsible for managing their users, credentials, connected sources, source scopes, skill grants, action permissions, approval settings, and consumer tokens securely.

If we become aware of a personal-data breach affecting Customer Data, we will notify affected customers without undue delay and as required by applicable law, and will assist customers with their own notification obligations as described in the DPA.

10. Data Retention

We retain information for as long as needed to provide Hugin, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support business operations. Workspace governance settings allow customers to configure retention for certain data. As a guide, our current defaults include: trace data retained for approximately 365 days; audit records retained for approximately 7 years; and raw ingested object retention configurable per workspace. Actual retention varies with customer configuration, legal requirements, and operational needs. Some information may persist for a limited period in logs, backups, billing records, or provider systems after deletion.

11. Deletion, Removal, and Data Portability

Customers can remove sources and delete workspace data through the product. Workspace deletion runs through a confirmation step with a short cancellation window, writes a record before removal, and then purges associated data in batches. Source removal deletes the data ingested from that source, and deletion/permission-revocation signals from connected sources propagate into Hugin. Customers can also request a structured export of workspace data (data portability).

Deletion is subject to legal, security, billing, backup, audit, and abuse-prevention limits, and some information may remain in backups, audit trails, billing records, or provider systems for a limited period or where legally required. To make a deletion or export request, use the in-product controls or contact fixeonai@gmail.com.

12. International Data Transfers

Fixeon AI Labs operates from Nigeria, and our subprocessors operate primarily in the United States, the United Kingdom, and the European Union (see the Subprocessors page). Your information may therefore be processed in countries other than where you are located, including countries that may not provide the same level of data protection as your home country.

Where required, we use appropriate safeguards for international transfers, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) and equivalent mechanisms, supported by additional measures such as encryption. Customers who require these safeguards can request our Data Processing Addendum, which incorporates them.

13. Children

Hugin is a business product and is not intended for children. You must not use Hugin if you are under 18 or under the age required to consent to online services in your jurisdiction, and you must not use Hugin to knowingly process the personal data of children except where you have a lawful basis and appropriate safeguards.

14. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to certain processing of personal information, to withdraw consent, and to lodge a complaint with a regulator. These include rights under the GDPR/UK GDPR, the Nigeria Data Protection Act 2023, and US state privacy laws such as the California Consumer Privacy Act (as amended by the CPRA).

  • EEA/UK residents may exercise GDPR/UK GDPR rights, including the right to lodge a complaint with a supervisory authority.
  • Nigerian residents may exercise rights under the NDPA and may complain to the Nigeria Data Protection Commission (NDPC).
  • US state residents (e.g. California, and other states with comprehensive privacy laws) may exercise rights to know, access, delete, correct, and opt out of any "sale"/"sharing" or targeted advertising. We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics. You may exercise these rights without discriminatory treatment, and you may use an authorized agent.

To exercise rights, contact fixeonai@gmail.com. If you are an end user whose data was provided to Hugin by a customer (controller), we will generally refer your request to that customer and assist them in responding. We may need to verify your identity before acting on a request, and we will respond within the timeframes required by applicable law.

15. California / US "Notice at Collection" Summary

We collect the following categories of personal information, as described above: identifiers (name, email, user/account IDs); account and commercial information (plan, subscription, billing/usage records); internet and network activity (sanitized product/usage events, security metadata); and the content a customer chooses to connect or submit (Customer Data, processed on the customer's behalf). We collect this from you, your organization, your connected sources, and our service providers. We use it for the purposes in Section 4. We disclose it to subprocessors and as described in Section 8. We do not sell it or share it for cross-context behavioral advertising. Retention is described in Section 10.

16. Nigeria (NDPA) Disclosures

As a data controller and processor operating in Nigeria, Fixeon AI Labs processes personal data in line with the principles of the NDPA, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. Our identity and contact details are at the top of this Policy. Where we carry out automated processing, we describe it in this Policy, and Hugin does not make solely automated decisions that produce legal or similarly significant effects about individuals. Where applicable, we will register with, and comply with the directions of, the Nigeria Data Protection Commission. You may contact us at fixeonai@gmail.com for any NDPA-related request.

17. Automated Processing

Hugin uses automated processing to ingest, organize, embed, retrieve, redact, and serve context, draft or refresh reusable skills where enabled, list or preview approved actions, and detect abuse and secure the Service. Hugin is a tool used by AI systems chosen and operated by the customer; Hugin itself does not make automated decisions that produce legal or similarly significant effects about individuals. Customers are responsible for any decisions they or their AI tools make using Hugin's outputs or connected-app actions, and for applying human review.

18. Customer Responsibilities

Customers are responsible for:

  • having the rights, notices, consents, and legal bases needed to connect sources and submit data to Hugin;
  • configuring source scopes, permissions, workspaces, consumers, redaction, skill access, action access, approval settings, and AI tool access appropriately;
  • deciding what information may be processed by Hugin and connected AI tools, and not connecting data they are not permitted to process;
  • complying with employment, privacy, data protection, AI, communications, and industry-specific laws that apply to them;
  • reviewing AI outputs, context, skill content, action previews, and action results before relying on them.

Note: any logo or branding image a customer uploads for a workspace may be served from a publicly accessible URL; customers should not upload sensitive content as branding.

19. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted with a new "Last updated" date. Material changes may be communicated through the Service or by email where appropriate. Your continued use of Hugin after an update takes effect means you accept the updated Policy.

20. Contact

For privacy questions, requests, or to request our Data Processing Addendum:

Fixeon AI Labs

No.2 Haile Selassie Street, Asokoro, Abuja, Nigeria

fixeonai@gmail.com