Privacy Policy
Last updated: 23 July 2026This policy explains how Dubir Group LTD collects, uses, and protects personal data when you use Hartia, our document automation platform for legal firms. We handle data in line with the EU General Data Protection Regulation (GDPR) and Cyprus data-protection law.
1. Controller
The data controller for your account data is Dubir Group LTD, a company registered in Cyprus (registration number HE 394277), registered office Charalampou Mouskou & Grigori Afxentiou, 20. ATHINODOROU BUSINESS CENTER, 3rd floor, Flat/Office 306, 8010, Paphos, Cyprus. Privacy enquiries: [email protected].
2. Controller vs. processor
There are two distinct roles to be aware of:
- For your account and our own operations (your firm name, login email, branding, billing, usage), Dubir Group LTD is the controller.
- For the data you enter about your clients (names, passport details, addresses, family composition, and other information you put into a document or intake form), your firm is the controller and Hartia acts as your processor, handling that data on your instructions to generate your documents. You are responsible for having a lawful basis to provide it to us. We never use client data for anything except producing your documents, and we do not train AI models on it.
3. What we collect
You provide to us:
- Account & firm data: your name, email address, password (stored only as a salted hash), firm name, branding assets (logo, colours), your service catalog and prices, and billing details.
- Workspace content: the client data, proposals, immigration packages, legal service agreements, intake-form submissions, and templates you create.
- Communications: messages you send to support.
Collected automatically:
- Technical & usage data: IP address, browser/device information, and log data needed to operate and secure the Service.
- Essential storage: an authentication token kept in your browser to keep you signed in. We do not use a session cookie for this.
- Analytics & advertising: our public marketing pages use analytics tools (PostHog, self-hosted Umami) and advertising measurement pixels (for example Reddit) that may set cookies or similar identifiers to measure traffic and campaign performance. No analytics or advertising trackers run inside a client intake form.
4. How we use data & legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide, maintain, and secure the Service | Performance of a contract |
| Process subscriptions, top-ups, and payments | Performance of a contract; legal obligation |
| Send service emails (e.g. password reset, document delivery) | Performance of a contract |
| Improve and troubleshoot the Service; prevent abuse | Legitimate interests |
| Measure our website and advertising performance | Consent / legitimate interests |
| Comply with tax, accounting, and legal obligations | Legal obligation |
| Optional product updates or marketing (if offered) | Consent (you can withdraw at any time) |
5. Where data lives
- Cloud plan: data is stored on infrastructure located in the European Union, encrypted in transit and at rest.
- On-premise plan: all data, including the database and generated documents, is stored on hardware physically located in your office. Nothing is sent to our servers.
6. Sharing & sub-processors
We do not sell your personal data. We share data only with service providers (sub-processors) that help us run Hartia, under contracts that require appropriate safeguards. Depending on your plan, these include:
- Cloud hosting / infrastructure (Fly.io, EU region): to store and run the application and database on the Cloud plan.
- Payment processing (Creem.io): our merchant of record for subscription and top-up billing. Creem handles the payment transaction, VAT, and receipts as an independent controller of the payment data.
- Product analytics (PostHog): usage analytics to understand and improve the product.
- Website analytics (self-hosted Umami): traffic and campaign measurement on our public marketing pages, run on our own infrastructure.
- Email delivery (Brevo): to send account emails and deliver documents on your behalf.
On the On-premise plan none of this applies to your client data, which never leaves your hardware. We may also disclose data where required by law, to enforce our Terms, or to protect rights, safety, and security. A current list of sub-processors is available on request at [email protected].
7. International transfers
Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
8. Retention
We keep account and workspace data for as long as your account is active. After you close your account, we delete or anonymise personal data within a reasonable period (within 30 days of a deletion request), except where we must retain certain records (for example, billing and tax records) to comply with legal obligations. You can export your data before closing your account. On the On-premise plan, client data never leaves your control in the first place.
9. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time. To exercise these rights, contact [email protected]; we will respond within 30 days. If your personal data was entered into a firm's workspace where that firm is the controller, please direct your request to the firm; we will assist them as their processor. You also have the right to lodge a complaint with your local data protection authority.
10. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or in-app) and update the “Last updated” date above.
12. Contact
For any privacy question or request, email [email protected] or write to Dubir Group LTD, Charalampou Mouskou & Grigori Afxentiou, 20. ATHINODOROU BUSINESS CENTER, 3rd floor, Flat/Office 306, 8010, Paphos, Cyprus.