Last revision of this Product Notice: v1.2 – 28 May 2026 - Added Ai-related details to Processing Operation(s)]
Prior version(s) of this Product Notice: [v1.1 – 17 May 2021]
This Product Notices describes the privacy relevant aspects of the above-mentioned Acquia product/services.
Acquia Content Hub is a cloud-based content distribution and discovery service that enables customers to author, search, and share content throughout a complex network of sites and channels. Content Hub Enterprise supports publishing content from Drupal sites and syndicating content to Drupal sites either using the Acquia Content Hub modules or through the Content Hub API.For details about this Product, please refer to the Product Description available online at https://docs.acquia.com/guide.
| Categories of Personal Data | Categories of Data Subjects | Purpose of Processing | Categories of Data Recipients | Needed for Core Features | Processing Location | Acquia Inc. acts as Processor |
|---|---|---|---|---|---|---|
| The Service does not store personal data. However, Customers in their sole discretion may configure, design, and administer their websites to capture personal data which may be sent via the Service if the Customer’s solution or workflow so dictates. Such personal data may include individual identifiers, contact details, online identifiers, network activity, location data, and any sensitive data categories. | The Service does not store personal data. However, Customers in their sole discretion may configure, design, and administer their websites to capture personal data which may be sent via the Service if the Customer’s solution or workflow so dictates. The relevant data subjects would primarily be Customer’s end users including visitors to Customer’s website. | Provision of the Services by Acquia to Customer | Site administrators; customers and visitors of Customer’s Drupal application(s) | Yes | Depends on the data center location chosen by customer | Yes |
| Objective | Technology/Measure | Data at Rest | Data in Transit |
|---|---|---|---|
| Anonymization and Pseudonymization | Stored data is 1) not anonymized or tokenized, and 2) at the customer's discretion (e.g. if the customer configures their Drupal site to export stored data to Content Hub, it will do so). | Yes | Yes |
| Data confidentiality | Access control measures Encryption at customer level Encryption at Acquia level (see Security Annex and Product Guide) | Yes Yes Yes | Yes Yes Yes |
| Data integrity | Anti-tampering technology (see Security Annex) | Yes | Yes |
| Data availability including restoring availability, restoring access to personal data, and data resilience | Business continuity and disaster recovery measures (see Security Annex) | Yes | N/A |
| Regular testing, assessing and evaluating of TOMs |
• SSAE16/ISAE 3402: SOC 1 Type II
• SOC 2 Type II
• ISO 27001:2013
Through the Service’s administration console and through the Customer’s own Drupal application, the Customer may manage, update, retrieve, and erase individual Personal Data.
Data is retained in both the Customer’s Drupal application, and in the Service. The "source of truth" is the Customer's Drupal application, but the Service retains a copy of the latest revision to be syndicated.
The specific list of sub-processors is available from: www.acquia.com/about-us/legal/subprocessors.
Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through above website.
| Categories of Personal Data | Categories of Data Subjects | Purpose of Processing | Categories of Data Recipients | Needed for Core Features | Processing Location | Acquia Inc. acts as Processor |
|---|---|---|---|---|---|---|
| The Service does not store personal data. However, Customers in their sole discretion may configure, design, and administer their websites to capture personal data which may be sent via the Service if the Customer’s solution or workflow so dictates. Such personal data may include individual identifiers, contact details, online identifiers, network activity, location data, and any sensitive data categories. | The Service does not store personal data. However, Customers in their sole discretion may configure, design, and administer their websites to capture personal data which may be sent via the Service if the Customer’s solution or workflow so dictates. The relevant data subjects would primarily be Customer’s end users including visitors to Customer’s website. | Provision of the Services by Acquia to Customer | Site administrators; customers and visitors of Customer’s Drupal application(s) | Yes | Depends on the data center location chosen by customer | Yes |
| Objective | Technology/Measure | Data at Rest | Data in Transit |
|---|---|---|---|
| Anonymization and Pseudonymization | Stored data is 1) not anonymized or tokenized, and 2) at the customer's discretion (e.g. if the customer configures their Drupal site to export stored data to Content Hub, it will do so). | Yes | Yes |
| Data confidentiality | Access control measures Encryption at customer level Encryption at Acquia level (see Security Annex and Product Guide) | Yes Yes Yes | Yes Yes Yes |
| Data integrity | Anti-tampering technology (see Security Annex) | Yes | Yes |
| Data availability including restoring availability, restoring access to personal data, and data resilience | Business continuity and disaster recovery measures (see Security Annex) | Yes | N/A |
| Regular testing, assessing and evaluating of TOMs | Regular security and process reviews (see also Security Annex) | Yes | N/A |
• SSAE16/ISAE 3402: SOC 1 Type II
• SOC 2 Type II
• ISO 27001:2013
Through the Service’s administration console and through the Customer’s own Drupal application, the Customer may manage, update, retrieve, and erase individual Personal Data.
Data is retained in both the Customer’s Drupal application, and in the Service. The "source of truth" is the Customer's Drupal application, but the Service retains a copy of the latest revision to be syndicated.
The specific list of sub-processors is available from: www.acquia.com/about-us/legal/subprocessors.
Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through above website.
| Regular security and process reviews (see also Security Annex) |
| Yes |
| N/A |
If this content did not answer your questions, try searching or contacting our support team for further assistance.
If this content did not answer your questions, try searching or contacting our support team for further assistance.