Privacy policy

Last updated: September 2026

Who we are

UX ContentHub is operated by SV Content Writer BV, a company registered in Belgium under number 0777.737.585, with its registered office at Zuerbergstraat 45, 3080 Tervuren, Belgium ("we", "us", "our").

For any question about this policy or your personal data, contact us at hello@ux-contenthub.com.

What this policy covers

This policy applies to:

  • our website, www.ux-contenthub.com;

  • our Figma plugin, UX ContentHub, including its Advanced Features;

  • the UX ContentHub Portal (portal.ux-contenthub.com) and the API behind it (api.ux-contenthub.com).

Our role

For website visitors, account holders and billing, we decide how and why personal data is processed. We act as the data controller.

The content a customer organisation stores in its workspace (texts, translations, comments) belongs to that organisation. We process it only to provide the service, on the organisation's instructions. For that content, the organisation is the controller and we act as its processor. A data processing agreement (DPA) is available on request.

Data we collect

When you visit our website
  • Information you send us by email or through a form: name, email address, company, message.

  • Aggregated visit statistics from Framer Analytics, which does not use cookies: pages visited, referring site, device type and country.

When you use the plugin or the Portal

Account data. Name, email address, role (admin, editor, dev, viewer), the workspaces you belong to, and invitations you send or receive. Sign-in is handled by our authentication provider; we never see or store your password.

Figma identity. Your Figma user ID and display name, used to attribute reviews and changes in the plugin.

Workspace content. Variable names and their text values in every language, Figma file names and identifiers, frame names, project names, usage counts, review status, comments and mentions.

Figma team connection (optional). If a workspace admin connects the workspace to a Figma team, we store an access token, encrypted in our database. We use it only to read the team's member list (Figma handle and email) to help invite colleagues, the list of projects and files, and file thumbnails.

Licence and payment. For the plugin's base version, payments are processed by Figma; we do not receive your payment details. When you activate a licence code, we store the code, the plan attached to it, and your Figma user ID and display name. Licence checks are the only data the base version sends to our servers. Advanced Features subscriptions are invoiced directly by us, using your company's billing details.

Technical logs. Our servers record technical information for each request: IP address, date and time, requested address, browser, and errors. We use these logs only for security and troubleshooting.

We do not use tracking or analytics tools in the plugin or the Portal.

How AI features process your text

AI features (translation suggestions, text improvements, matching with existing variables) run on open-weight models hosted on infrastructure we operate ourselves: our server in Germany and a dedicated inference server in Belgium, connected through an encrypted private network.

  • Your texts are never sent to third-party AI providers.

  • Your texts are never used to train AI models.

  • A workspace's content is never used for, or visible to, another workspace.

Why we process your data

  • Providing the plugin, the Portal and the API (accounts, workspaces, synchronisation, AI features): performance of our contract with you or your organisation.

  • Processing workspace content: on behalf of the customer organisation, under its instructions.

  • Answering your questions and providing support: our legitimate interest in responding to you, or steps taken before a contract.

  • Securing our services and fixing errors (technical logs): our legitimate interest in keeping the service secure and available.

  • Website analytics (aggregated, without cookies): our legitimate interest in understanding how our website is used.

  • Newsletters and product updates by email: your consent.

  • Invoicing and accounting: our legal obligations.

We do not sell or rent your personal data, and we do not use it for advertising.

Service providers

We rely on a small number of providers. Each one processes data only to deliver its service to us.

  • Netcup GmbH (Germany): server hosting for the API, the database and the Portal.

  • Auth0 (Okta, Inc.) (European Union, EU tenant): sign-in and account authentication.

  • OVH SAS (France): email and domain names.

  • Figma, Inc. (United States): plugin platform, payments for the plugin's base version, Figma team connection.

  • Tailscale Inc. (Canada, United States and other countries; metadata only): encrypted private network between our servers. It cannot read the data it carries.

  • Framer B.V. (Netherlands): website hosting and website analytics.

Our AI inference server in Belgium is operated by us, not by a third party.

International transfers

Most data stays in the European Union. When a provider transfers data outside the EU (Figma, Google, Tailscale, and Okta as Auth0's parent company), the transfer is covered by the EU-US Data Privacy Framework or by the European Commission's Standard Contractual Clauses.

How long we keep your data

  • Account data: as long as your account is active. Deleted within 30 days of a deletion request.

  • Workspace content: as long as the organisation's subscription is active. Deleted within 30 days of a deletion request from the workspace admin.

  • Figma team access token: until the admin disconnects the Figma team or the workspace is deleted.

  • Technical server and application logs: 14 days, then deleted automatically.

  • Database backups: 7 days, then deleted automatically. Backups are encrypted.

  • Emails and support requests: as long as needed to handle the request, and at most 2 years.

  • Invoices and accounting records: the period required by Belgian accounting and tax law.

  • Website analytics: aggregated statistics without cookies or personal identifiers, kept according to Framer's retention settings.

Cookies

Website. Our website does not use cookies that require your consent. Visit statistics are collected with Framer Analytics, which works without cookies.

Portal and plugin. The Portal uses only what is strictly necessary to keep you signed in and remember the workspace you selected. These are not tracking cookies and do not require consent. The plugin stores its settings locally in Figma.

Security

  • All traffic is encrypted in transit (HTTPS/TLS).

  • Servers and data are hosted in the European Union.

  • Workspaces are isolated: a user sees only the content of the workspace they are signed in to.

  • Access is role-based (admin, editor, dev, viewer); write actions are restricted by role.

  • Figma access tokens are encrypted in our database. Daily database backups are encrypted and stored on our own infrastructure in the European Union.

  • Sign-in is delegated to Auth0; we never store passwords.

We do not access workspace content, except to restore the service or at the customer's request. No online system is completely secure. If a data breach is likely to put your rights at risk, we will notify the competent authority and, where required, the people affected, within the legal deadlines.

Your rights

Under the GDPR, you have the right to:

  • access the personal data we hold about you;

  • have inaccurate or incomplete data corrected;

  • have your data deleted;

  • restrict or object to certain processing, including processing based on our legitimate interest;

  • receive your data in a portable format;

  • withdraw your consent at any time, without affecting processing done before.

To exercise these rights, email hello@ux-contenthub.com. We answer within one month. If your data is part of an organisation's workspace, we may forward your request to that organisation, as it controls that content.

You can also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be.

External links

Our website and services may link to other websites, such as Figma. We are not responsible for their privacy practices.

Changes to this policy

We may update this policy when our services or legal requirements change. The date at the top shows the latest version. For significant changes, we will inform account holders by email or in the Portal.

Contact

SV Content Writer BV - hello@ux-contenthub.com