---
title: "Content Hub Product Privacy Notice"
date: "2026-05-15T19:55:51+00:00"
summary: "Understand Acquia Content Hub's privacy practices—data processing, retention, security measures, and your rights under GDPR compliance."
image:
type: "page"
url: "/service-offerings/content-hub-product-privacy-notice"
id: "32d06033-8c28-4b10-a057-67182ba60e9b"
---

Acquia Content Hub
------------------

  
Last revision of this Product Notice: v1.2 – 28 May 2026 - Added Ai-related details to Processing Operation(s)\]  
Prior version(s) of this Product Notice: \[v1.1 – 17 May 2021\]  
This Product Notices describes the privacy relevant aspects of the above-mentioned Acquia product/services.  
 

About the Product
-----------------

Acquia Content Hub is a cloud-based content distribution and discovery service that enables customers to author, search, and share content throughout a complex network of sites and channels. Content Hub Enterprise supports publishing content from Drupal sites and syndicating content to Drupal sites either using the Acquia Content Hub modules or through the Content Hub API.For details about this Product, please refer to the Product Description available online at [https://docs.acquia.com/guide](https://docs.acquia.com/guide).  
 

### 1\. Processing Operation(s)

The objective of Processing of Personal Data by data importer is the performance of the Services pursuant to the Agreement.

*   Processing of Personal Data to deliver its core functionalities required: ☐ yes ☒ no
*   Optional features processing Personal Data: ☐ yes ☒ no
    *   The optional features are deactivated by default: ☐ yes ☐ no ☒ n/a\*
*   Processing of sensitive Personal Data: ☐ yes\*\* ☒ no ☐ n/a\*
*   Profiling of individuals based on personal characteristics: ☐ yes ☒ no ☐ n/a\*
*   Automated decision making that produces legal or other significant impacts on individuals: ☐ yes ☒ no ☐ n/a\*\*
*   Processing via an AI tool available with the Product ☐ yes ☒ no
    *   The AI feature is deactivated by default: ☐ yes ☐ no ☒ n/a\*
    *   The AI feature processes Personal Data: ☐ yes ☐ no ☒ n/a\*
    *   The AI feature processes sensitive Personal Data ☐ yes ☐ no ☒ n/a\*
    *   The Customer can control what data the AI tool processes: ☐ yes ☐ no ☒ n/a\*

\* (n/a = not applicable)  
\*\* (optional; depends on the Customer’s Drupal application)

### 2\. Details of Personal Data being processed

Categories of Personal Data

Categories of Data Subjects

Purpose of Processing

Categories of Data Recipients  
 

Needed for Core Features 

Processing Location

Acquia Inc. acts as Processor

The Service does not store personal data. However, Customers in their sole discretion may configure, design, and administer their websites to capture personal data which may be sent via the Service if the Customer’s solution or workflow so dictates. Such personal data may include individual identifiers, contact details, online identifiers, network activity, location data, and any sensitive data categories.

The Service does not store personal data. However, Customers in their sole discretion may configure, design, and administer their websites to capture personal data which may be sent via the Service if the Customer’s solution or workflow so dictates. The relevant data subjects would primarily be Customer’s end users including visitors to Customer’s website.

Provision of the Services by Acquia to Customer

Site administrators; customers and visitors of Customer’s Drupal application(s)

Yes

Depends on the data center location chosen by customer

Yes

### 3\. Privacy Enhancements

Objective

Technology/Measure

Data at Rest

Data in Transit

Anonymization and Pseudonymization

Stored data is 1) not anonymized or tokenized, and 2) at the customer's discretion (e.g. if the customer configures their Drupal site to export stored data to Content Hub, it will do so).

Yes

Yes

Data confidentiality

Access control measures

Encryption at customer level

Encryption at Acquia level

(see [Security Annex](https://security.acquia.com/) and [Product Guide](/service-offerings/content-hub-product-guide "Content Hub Product Guide"))

Yes

Yes

Yes

Yes

Yes

Yes

Data integrity

Anti-tampering technology ([see Security Annex](https://security.acquia.com/))

Yes

Yes

Data availability including restoring availability, restoring access to personal data, and data resilience

Business continuity and disaster recovery measures (see  
[Security Annex](https://security.acquia.com/))

Yes

N/A

Regular testing, assessing and evaluating of TOMs

Regular security and process reviews (see also [Security Annex)](https://security.acquia.com/)

Yes

N/A

### 4\. Certifications

• SSAE16/ISAE 3402: SOC 1 Type II  
• SOC 2 Type II  
• ISO 27001:2013

### 5\. Data Subject Rights

Through the Service’s administration console and through the Customer’s own Drupal application, the Customer may manage, update, retrieve, and erase individual Personal Data.  
 

### 6\. (Personal) Data Retention Cycles

Data is retained in both the Customer’s Drupal application, and in the Service. The "source of truth" is the Customer's Drupal application, but the Service retains a copy of the latest revision to be syndicated.  
 

### 7\. Sub-Processing

The specific list of sub-processors is available from: [www.acquia.com/about-us/legal/subprocessors](https://www.acquia.com/about-us/legal/subprocessors).  
Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through above website.

###   
8\. Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses  
4(d) and 5(c) (or document/legislation attached)

Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex (available from https://www.acquia.com/about-us/legal/gdpr) applicable to the specific Services purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is wholly responsible for implementing and maintaining security and data administration within any data exporter applications, configuration settings, or log settings used by data exporter in conjunction with the Services.