HeyouIt just works.
Learning HubTrust
✦Get a demo
In this document
  1. Current Subprocessors
  2. Website Subprocessors
Subprocessor List

Subprocessor List¶

The third-party services Heyou relies on. We don't use subprocessors to create cross-customer datasets.

Effective: 2026-05-10Last updated: 2026-09-15Version: 1.0
In this document
  1. Current Subprocessors
  2. Website Subprocessors

Heyou uses a limited set of third-party subprocessors required to provide, operate, secure, support, and bill for the service.

Current Subprocessors ¶

Subprocessor Purpose Typical Data Categories Status
Google Cloud Platform / Vertex AI Cloud hosting, infrastructure, storage, logging, monitoring, and approved AI processing through Vertex AI / Gemini Customer Data, service metadata, logs, prompts and outputs where AI processing is used Required for core service
Descope Identity, authentication, SSO, user management, and access-control workflows User account identifiers, authentication metadata, access-control metadata Required for authentication
Customer.io Customer communications, product notifications, lifecycle emails, and service-related messaging Business contact information, product-notification metadata Used for communications
Stripe Billing, subscription management, invoicing, and payment-related workflows Billing contact information, subscription and invoice metadata, payment-related records Used for billing
Attio CRM and customer relationship management Business contact information, account records, sales notes, commercial relationship data Business operations
Fathom Meeting recording, transcription, call summaries, and meeting intelligence for customer or prospect interactions, where used Meeting participant information, recordings, transcripts, summaries Used where meetings are recorded or summarized
Meta Platforms, Inc. — WhatsApp Business Platform Delivers the WhatsApp query channel, where a User chooses to ask Heyou questions over WhatsApp The User's WhatsApp phone number, the question the User sends Heyou, and Heyou's answer, in transit and transiently at rest pending delivery; Heyou retains the question and answer only for the conversation turn Used only where a User enables the WhatsApp channel

Website Subprocessors ¶

The following subprocessors support heyou.io (the public marketing site) and process website-visitor data. Where consent is required under EU/UK ePrivacy and GDPR rules, the relevant subprocessor is gated on the visitor's explicit opt-in via the site's cookie banner. PostHog additionally receives operational telemetry from the Heyou product, described below the table.

Subprocessor Purpose Typical Data Categories Consent Required
Vercel Inc. (US, hosted in EU regions where available) Hosting of heyou.io, serverless execution, edge logs, ephemeral storage for evaluation briefs (/tmp) HTTP request metadata, IP address (edge logs), evaluation-brief content and the email if the visitor submits one Necessary (legitimate interests)
Google LLC — Gemini API (EU/US, Vertex AI region pinning where configured) Backs the on-site chat agent and the optional brand-color lookup for the evaluation page Visitor chat messages, the persona/concern context, the domain extracted from a submitted work email for brand-color resolution Necessary (legitimate interests; visitor-initiated)
Google LLC — Favicon CDN (s2.gstatic.com) Serves the company logo displayed on co-branded evaluation pages The domain portion of the visitor's email (e.g. monday.com) — never the full email Necessary (legitimate interests; visitor-initiated)
Google LLC — Google Analytics 4 (EU/US regional processing) First-party visitor analytics for marketing-site usage Pageviews, anonymous client identifiers (_ga / _ga_<ID> cookies), referrer, browser, OS, screen size, coarse geolocation (country/region) derived from IP at Google Analytics opt-in only
PostHog Inc. (EU Cloud — eu.i.posthog.com) Product analytics for the marketing site Pageviews, anonymous distinct_id (UUID, first-party cookie + localStorage), autocapture click/submit/change events on tagged selectors (no input values), browser/OS/screen/referrer/UTM, client IP server-side at PostHog Cloud (used for coarse geolocation and not stored in events) Analytics opt-in only

PostHog session recording is disabled site-wide; PostHog never receives form field values, email addresses, or brief content from the marketing site. Google Analytics 4 is configured without ad-personalization signals. Both analytics subprocessors load only after the visitor opts in via the cookie banner and are immediately opted-out on revocation.

Separately from the marketing site, PostHog receives operational telemetry from the Heyou product covering AI model calls: the model used, token counts, cost, timing, and pseudonymous tenant and user identifiers. It does not receive prompt or response content, relationship data, message content, names, or email addresses. The identifiers are internal numeric references that PostHog cannot resolve to a named individual on its own; they remain personal data and are handled accordingly under the DPA.

Heyou does not sell Customer Data, does not use subprocessors to create cross-customer datasets, and does not use one customer’s data to benefit another customer. Data shared with each subprocessor is limited to what is necessary for the applicable service purpose.

Subprocessors that process Customer Data or personal data on Heyou’s behalf are governed by contractual data protection obligations, including confidentiality, security, and breach-notification commitments. Heyou provides customers with advance notice of material subprocessor changes in accordance with the DPA.

Some subprocessors may process only limited business contact information or operational metadata, depending on how the customer uses Heyou and how Heyou supports the account.

User-authorized third-party platforms that a user chooses to connect are not subprocessors of Heyou. Those platforms operate the user’s account independently and are governed by the user’s direct relationship with the platform. Google Calendar is one such source: an Authorized User may connect it under the read-only events scope, and that connection is governed by the Google Workspace Integrations section of the Privacy Policy and by the user’s own relationship with Google.

Slack and Anthropic are also not subprocessors, on a related but distinct basis. The Heyou Slack app and the Heyou Claude connector may each be installed by an individual User or deployed by the Customer across an organization. Either way, Heyou does not engage Slack or Anthropic to process data on Heyou’s behalf: each operates the User’s or Customer’s own account under that party’s own agreement with the provider, and data reaches Heyou through that relationship. Both are query surfaces — Heyou reads the question a User sends it and the identifiers needed to authenticate that User and reply. Heyou does not read Slack channels, message history, files, or workspace membership, and does not read Claude chat history, memory, or projects. Heyou creates no lasting store or index from either, and does not use data from either to train any large language model.

Meta is listed above as a subprocessor rather than treated this way, because a User messaging Heyou on WhatsApp messages a Heyou-operated business number. Meta transmits and processes those messages on Heyou’s behalf. The WhatsApp channel is described in the Messaging Channels section of the Privacy Policy.

Questions? Email legal@heyou.io or privacy@heyou.io.
← Back to Trust Center
HeyouIt just works.
Learning HubBlogTrustSecurityPrivacyTermsDPASubprocessors
© Heyou. Network Intelligence.