DigiiHub

Privacy policy

Effective date: July 13, 2026

In plain terms

  • Your organization’s data lives in its own isolated space in our database. Other organizations cannot read it, and neither can other organizations’ admins.
  • Everything sent between your browser and our servers is encrypted in transit.
  • We do not sell your data or your participants’ data, to anyone, for any reason.
  • Data your participants give you belongs to your organization, not to us. We store and process it on your behalf.

Who we are

DigiiHub is operated by The Legacy League Creative, LLC, doing business as Chronicle House (“Chronicle House,” “we,” “us”). This policy explains what personal data DigiiHub collects, how it is stored, and the choices you have. It covers the DigiiHub application and the public program hubs it serves.

Data lives on our servers, not only in your browser

DigiiHub is a hosted, multi-tenant service. Unlike a local-only tool, the information you and your participants enter is stored in a managed cloud database on our infrastructure so it can be shared across an organization, kept between sessions, and served to public hub visitors.

Each organization’s records are isolated at the database level using row-level security, so one organization cannot read another organization’s data.

Information we collect

We collect the following categories of data:

  • Account data. Names, email addresses, and authentication credentials for administrators and collaborators who sign in.
  • Organization and program data. The organizations, programs, groups, sessions, and speakers that administrators create.
  • Participant data.Information about program participants, entered by the participant or by an organization’s administrators. Depending on how an organization uses DigiiHub, this can include a participant’s name and email address, their group and session enrollment, workbook responses they write, discussion posts and replies they make, and the group directory profile fields they add, such as a business name, industry, role or title, short bio, and contact details. Surveys are delivered through external survey tools, so DigiiHub records that a participant completed a survey, not the answers they gave.
  • Billing data. Subscription and payment information, processed by our payment provider (Stripe). We do not store full card numbers.
  • Usage and audit data. Records of key actions taken in the product, retained for security and recordkeeping.

Participant data and who controls it

When an organization uses DigiiHub to manage other people’s information, that organization decides what participant data is collected and why. In that arrangement the organization is the controller of the participant data and Chronicle House acts as a processor handling it on the organization’s behalf.

Organizations that need signed data-processing terms with Chronicle House can request them at the contact below.

How we use data

We use data to operate and secure the service, provide support, process subscriptions, and serve the public hub pages organizations choose to publish. We do not sell personal data.

Service providers

We rely on a small number of processors to run DigiiHub: a managed database and authentication provider, a payment processor for subscriptions, an email delivery provider for account and invitation messages, and a hosting provider. Each receives only the data needed for its function.

Data retention and deletion

The information in an organization’s account is retained while that account exists. Cancelling a subscription ends access at the close of the paid period but does not by itself delete stored data. Deletion is available at two levels, and both are real: rows and uploaded files are removed, not just hidden.

An organization’s administrator can delete the whole organization. The public hub goes dark immediately, and after a 7 day grace window everything is permanently deleted, including uploaded files. The administrator can cancel within that window.

A participant can be removed individually, at any time, on request to their organization: their workbook answers, discussion posts and replies, survey records, directory profile, and notification history are permanently deleted right away, without affecting other participants’ content. Where someone else replied to one of their posts, the post is kept only as a placeholder that contains none of their words or identity. Audit records are kept for security with the person’s identity, address, and content removed, and a minimal record that the deletion was performed is retained as proof of compliance.

Deleted data leaves our live systems immediately. Encrypted backups retain data until they expire on the provider’s rolling window (currently up to 7 days). Backups exist only for disaster recovery; if one is ever restored, previously performed deletions are re-applied before service resumes.

Your choices and rights

Administrators can access and update the data in their organization. Because an organization controls its participants’ data, a participant who wants to access, correct, or remove their information should first contact the organization that entered it. Participants and organizations can also reach us at security@chroniclehouse.co, and we will work with the controlling organization on the request.

Removal requests from participants are carried out by the organization that controls the data, using the deletion capability described above, or by us together with that organization when a request reaches us directly. A person whose account no longer belongs to any organization can delete the account themselves from their account menu.

Security

We protect data with row-level isolation between organizations, encrypted connections, and access controls. No system is perfectly secure, but we work to safeguard the information entrusted to us.

Contact

Questions about this policy can be directed to:

The Legacy League Creative, LLC dba Chronicle House
1000 Ballpark Way, Suite 310
Arlington, TX 76011
Support: support@chroniclehouse.co