Legal
Privacy Policy
How Hübner Management GmbH processes personal data when you use huebner.io.
Last updated: 24 July 2026 · Version 1.4
1. Controller
The controller responsible for processing personal data on huebner.io is:
Hübner Management GmbH
Im Reberle 8
FL-9494 Schaan
Principality of Liechtenstein
Telephone: +41 77 261 07 24
Email: hartmut@huebner.io
We have not appointed a data protection officer. Questions about data protection can be sent directly to the address above.
2. Scope and legal bases
This Privacy Policy applies to huebner.io, its English and German pages, the AI Field Notes, the newsletter sign-up, the contact channels offered through the website, and the linked MindKeep prototype (a private knowledge hub) offered as a public case for evaluation.
We process personal data under the General Data Protection Regulation (GDPR), the Liechtenstein Data Protection Act and other applicable Liechtenstein law. Depending on the processing, we rely in particular on:
- your consent under Article 6(1)(a) GDPR;
- steps taken before entering into a contract or performance of a contract under Article 6(1)(b) GDPR;
- compliance with legal obligations under Article 6(1)(c) GDPR;
- our legitimate interests under Article 6(1)(f) GDPR, particularly in operating a secure website, responding to enquiries and maintaining business relationships.
3. Website access and server logs
When you access the website, technically necessary connection data is processed. This may include your IP address, date and time, requested address, referrer, browser and device information, and status or error data.
This processing is necessary to deliver the website, maintain stability, investigate errors and protect the service against misuse and attacks. The legal basis is our legitimate interest in a secure and functional website under Article 6(1)(f) GDPR.
We do not maintain our own permanent archive of complete access logs. Hosting and security providers retain technical logs only for as long as necessary for operation, security, error analysis, abuse prevention or compliance with legal duties. Logs connected with a security incident may be retained until the investigation and any related legal action are complete.
4. Hosting and technical delivery
The website is deployed through Lovable. Its European contact address is:
Lovable Labs AB
Regeringsgatan 25
111 53 Stockholm
Sweden
Privacy email: dpo@lovable.dev
Lovable works with affiliated companies and technical subprocessors. Infrastructure provided by Cloudflare may be used to deliver and protect the website securely around the world.
Depending on the contract and processing involved, Lovable Labs Incorporated, 1111b South Governors Avenue, Dover, DE 19904, United States, may also act as contracting party or data importer.
Hosting involves the processing of the technical data described in Section 3. The providers process this data on our behalf under appropriate data protection agreements. Where data is processed outside the European Economic Area, the providers rely on recognised safeguards such as adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses.
Lovable may provide aggregated project analytics, such as visitor numbers, page views, time on site, bounce rate, referring pages and device categories. We use this information to improve the website technically and editorially, based on our legitimate interest under Article 6(1)(f) GDPR. It is not used by us to create personal advertising profiles.
The source code is managed in a private or access-controlled GitHub project. GitHub does not receive newsletter or contact data through an ordinary visit to huebner.io. If you follow an external GitHub or GitHub Pages link, the privacy terms of that external service apply.
5. AI Field Notes newsletter
When you subscribe to the AI Field Notes newsletter, we process:
- your email address;
- your first name, if you provide it voluntarily;
- your selected language;
- subscription status and technical administration data;
- delivery, unsubscribe and error information for sent emails.
We process this data to send and administer the newsletter on the basis of your consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time for the future by using the unsubscribe link in each email or contacting hartmut@huebner.io.
Mailing lists and consent records are managed in a self-hosted instance of the open-source Listmonk software on European infrastructure provided by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
We use the following provider for technical email delivery:
Lettermint B.V.
Willemsvaart 16 B
8019 AB Zwolle
The Netherlands
Privacy email: legal@lettermint.co
Lettermint processes recipient addresses, sender information, message content, and delivery, unsubscribe, bounce and complaint information on our behalf. Under Lettermint's Data Processing Agreement, the personal data we provide is processed entirely within the EU or EEA. According to the currently published list, the subprocessors handling email data are located in the Netherlands and France.
Lettermint currently retains complete sent messages, metadata and delivery events for 28 days and then deletes them automatically. Unsubscribe and suppression information may be retained for longer where necessary to prevent further mailings and demonstrate compliance with a withdrawal.
We use double opt-in. You first receive a confirmation email, and newsletter delivery begins only after you select the confirmation link. Unconfirmed sign-ups are deleted after an appropriate period.
Newsletter data is retained until you unsubscribe or the mailing purpose ends. After unsubscribing, your email address may be kept on a suppression list where necessary to prevent further mailings and demonstrate compliance with the withdrawal. The legal basis for this limited retention is Article 6(1)(f) GDPR.
We do not use newsletter data for third-party advertising and do not sell mailing lists. Individual-level open or click tracking will take place only if the feature is expressly activated, any consent required for it has been obtained and this Privacy Policy has been updated accordingly.
6. Contacting us
If you contact us by email, telephone, WhatsApp, Telegram, LinkedIn or another channel, we process the contact details and content you provide, together with metadata required for the communication. We use this data to answer your enquiry, prepare a possible engagement or manage an existing business relationship.
The legal basis is Article 6(1)(b) GDPR where the communication concerns a contract or pre-contractual steps. In other cases, processing is based on our legitimate interest in responding to enquiries and conducting business communications under Article 6(1)(f) GDPR.
Emails are processed through Google Workspace. The provider for users in the EEA and Switzerland is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
If you use an external communication service such as WhatsApp, Telegram or LinkedIn, that provider also processes your data under its own responsibility. Data may be processed outside the EEA. For confidential or sensitive information, please use email where possible and provide only the information needed for your enquiry.
We delete general enquiries when they have been resolved and no further retention is necessary. Data connected with proposals, engagements or business relationships is retained for as long as required for the relationship, the establishment or defence of legal claims, and statutory documentation or retention duties.
7. YouTube videos
Notes may contain YouTube videos using privacy-enhanced mode. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
A YouTube video is loaded only after you select the relevant button. Loading the video creates a connection to YouTube or Google. In particular, your IP address, browser and device information, and details of the page you visited may be transmitted. If you are signed in to a Google service, Google may associate the request with your account. Google may also process data in third countries.
The legal basis for loading the video is your consent under Article 6(1)(a) GDPR. Without your consent, the external video remains blocked. You can use a separately provided YouTube link instead.
8. External links and downloads
The website links to GitHub, FlowBoard, MindKeep, Flow Momentum, MMIND.ai, LinkedIn, WhatsApp, Telegram, academic sources and other external services. Merely displaying a link does not generally transmit data to the external provider. Once you follow it, that provider's privacy terms apply.
Images, fonts and PDF documents provided directly on huebner.io are generally delivered through the website itself. Downloading a file creates the same technical connection data as an ordinary page request.
9. Cookies and similar technologies
huebner.io does not currently use Google Analytics or its own advertising or marketing cookies. Fonts are served locally and are not loaded from Google Fonts. The aggregated project analytics described in Section 4 may be based on technical hosting and access data; we do not embed a separate analytics script for this purpose.
Hosting and security providers may use strictly necessary cookies or similar identifiers to prevent attacks, protect sessions and provide reliable delivery. This processing is based on our legitimate interest in website security and functionality under Article 6(1)(f) GDPR. We request consent before loading non-essential external content, particularly YouTube.
If analytics, personalisation or marketing services are introduced later, we will update this Privacy Policy and, where required, the consent controls before they are activated.
10. AI-assisted editorial work with OpenAI
We use Codex and other OpenAI services to research, draft, edit, translate and quality-check website and newsletter content. The provider for users in the EEA and Switzerland is:
OpenAI Ireland Limited
1st Floor, The Liffey Trust Centre
117-126 Sheriff Street Upper
Dublin 1, D01 YC43
Ireland
Privacy email: privacy@openai.com
Data protection officer: dpo@openai.com
This may involve processing working materials and prompts selected by us. These may include publicly available sources, academic papers, project documents, drafts, and the names and professional or biographical details of authors, speakers or project participants. We process this information to create, review, translate and improve our own content. The legal basis is our legitimate interest in efficient and careful editorial work under Article 6(1)(f) GDPR.
Merely visiting huebner.io or subscribing to the newsletter does not automatically send your IP address, email address or form entries to OpenAI. We do not upload newsletter mailing lists to OpenAI for content creation. We limit editorial inputs to the data required and do not generally submit confidential information or special categories of personal data unless a separate legal basis and appropriate safeguards are in place for the specific case.
Working materials and outputs are retained in the relevant accounts and project environments only for as long as needed for editorial work, documentation or legal duties; the applicable account and retention settings also apply. Depending on the account used, OpenAI processes data either as an independent controller under its Privacy Policy or, for an eligible business offering, as a processor under the OpenAI Data Processing Addendum. Where data is processed outside the EEA, the safeguards applicable to the relevant offering apply, including adequacy decisions or Standard Contractual Clauses.
11. Google Search Console, SEO and AI Search
We use Google Search Console to assess the visibility and technical presentation of huebner.io in Google Search. The provider for users in the EEA and Switzerland is:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland
For the indexing and display of publicly available content in Google Search, Google's privacy information also identifies Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States, as controller.
Search Console provides us mainly with aggregated performance information. This may include search queries, viewed pages, impressions, clicks, click-through rate, average position, and country and device categories. Google limits or anonymises rare or sensitive search queries according to its own criteria. We use this data to investigate errors, optimise search performance and improve public content. The legal basis is our legitimate interest in a technically sound and discoverable website under Article 6(1)(f) GDPR.
Connecting Google Search Console does not itself add a tracking script or separate Search Console cookies to huebner.io. The measurements arise from the use of Google Search and are processed by Google under its own privacy terms.
If the Google Search Console connector in Lovable is enabled, Lovable can access the website's Search Console data and display it in the project environment. Lovable's processing is also described in Section 4. At our request, Lovable's SEO and AI Search features may inspect public pages, source code and metadata and evaluate search and competitor data supplied by Semrush. Newsletter addresses, contact messages and unpublished personal submissions are not provided for this purpose.
Google determines how long data remains available within its services. We retain exported reports only for as long as they are needed to analyse, document and improve the website. Where Google processes data outside the EEA, the adequacy decisions, certifications or Standard Contractual Clauses described by Google apply.
12. Public AI systems
huebner.io itself does not provide a public AI chatbot, and merely visiting the website or subscribing to the newsletter does not send your input to an AI model. The linked MindKeep prototype processes account and content data with AI models as described in the MindKeep section of this policy.
13. MindKeep prototype
MindKeep is a working prototype built and operated by Hübner Management GmbH: a private knowledge hub that turns documents, emails and notes into a citable knowledge base with AI assistance. It is offered publicly as a case for evaluation at https://app.mindkeep.li/signup. MindKeep is not yet a commercial SaaS offering; please do not upload confidential production data.
When you register, we process your email address, name, login credentials (magic link or password) and technical usage data to operate your account (Article 6(1)(b) GDPR). Content you upload — documents, notes and chat inputs — is stored in your workspace and processed to provide search, citation and output features.
MindKeep runs on European infrastructure: the application and its database (self-hosted Supabase/Postgres) are hosted by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
AI processing of your content uses models by:
Mistral AI SAS
15 rue des Halles
75001 Paris
France
Content is processed within the European Union by default. Non-EU AI models are technically disabled and are activated only on explicit request for a specific workspace. According to its privacy policy, Mistral does not use paid API input and output to train its models and retains API data for up to 30 days.
Account-related emails, including confirmation messages, login links and invitations, are sent through:
Lettermint B.V.
Willemsvaart 16 B
8019 AB Zwolle
The Netherlands
Privacy email: legal@lettermint.co
Lettermint processes the recipient address, sender information, message content and technical delivery data on our behalf. Under Lettermint's Data Processing Agreement, the personal data we provide is processed entirely within the EU or EEA. Complete sent messages, metadata and delivery events are currently retained for 28 days and then deleted automatically.
MindKeep account emails are operational messages and are separate from the AI Field Notes newsletter described in Section 5. Creating a MindKeep account does not subscribe you to the newsletter. A newsletter subscription requires a separate double-opt-in registration managed through Listmonk.
You can export your data and request deletion of your account at any time in the app settings; deletion completes within 30 days and also removes stored files.
The legal basis for operating the prototype is Article 6(1)(b) GDPR (providing the requested service) and, for security and abuse prevention, Article 6(1)(f) GDPR.
14. Recipients and international transfers
Personal data is available only to the internal functions and service providers that need it for the purposes described above. These include hosting and security providers, newsletter and email services, and, where necessary, professional advisers or public authorities acting under a legal obligation.
For recipients outside the EEA, we require an applicable adequacy decision or appropriate safeguards under Article 46 GDPR, particularly Standard Contractual Clauses. Even with these safeguards, the level of protection in a third country may differ from that in the EEA.
15. Your rights
Where the statutory requirements are met, you have the right to:
- request access to your personal data (Article 15 GDPR);
- have inaccurate data corrected (Article 16 GDPR);
- request erasure (Article 17 GDPR);
- restrict processing (Article 18 GDPR);
- receive data in a portable format (Article 20 GDPR);
- object to processing based on legitimate interests (Article 21 GDPR);
- withdraw consent at any time for the future (Article 7(3) GDPR).
We do not make solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.
To exercise your rights, contact hartmut@huebner.io. We may request appropriate proof of identity where this is necessary to protect your data.
16. Right to complain
You may lodge a complaint with a data protection supervisory authority. The competent authority in Liechtenstein is:
Data Protection Authority, Principality of Liechtenstein
Kirchstrasse 8
PO Box 684
FL-9490 Vaduz
Telephone: +423 236 60 90
Email: info.dss@llv.li
Website: www.datenschutzstelle.li
17. Data security
We and our service providers use appropriate technical and organisational measures to protect personal data against loss, unauthorised access, alteration and misuse. These measures include encrypted transmission, access controls and regular updating of the systems used. Absolute security of data transmission and storage cannot be guaranteed.
18. Changes
We update this Privacy Policy when the website, service providers or legal requirements change. The version published on this website is the current version.