Skip to content

Data processing agreement

Last updated 22 July 2026

This document is written in plain language so you can actually read it. It has not yet been reviewed by counsel for your jurisdiction, and the final signed version supersedes this page. Ask us for the executable copy before you rely on it.

This DPA forms part of the terms of service between you, the controller, and Hepo, the processor. A countersigned PDF is available on request and is the version to file.

1. Scope

We process personal data only to provide the service and only on your documented instructions. Your instructions are your configuration: which modules are enabled, what retention you set, which fields you exclude from capture.

2. Categories of data

CategoryExamples
Contact dataEmail, name and attributes you pass through identify
Conversation dataMessages, attachments, internal notes, translations
Technical dataIP derived city, network operator, browser, operating system
Behavioural dataSession recordings as masked DOM events, page views, referrers

Data subjects are your website visitors and the members of your own team who use the console.

3. Sub-processors

Sub-processorPurposeLocation
Object storage providerRecordings and uploaded filesEuropean Union
Model providerAI agent responses, hosted plans onlyEuropean Union or United States

We give thirty days notice before adding or replacing a sub-processor, and you may object. Self hosted deployments have no sub-processors at all, which is the cleanest answer to this section and one reason regulated buyers choose it.

4. Security measures

  • TLS on every connection. Server-side encryption at rest on the object store.
  • Input masking applied in the visitor browser before transmission, with no option to disable.
  • Role-based access enforced server side, scoped per site, not merely hidden in the interface.
  • Access to production systems limited to named engineers with individual credentials.
  • Recordings expire and are purged on the retention policy you configure.

We do not currently hold SOC 2 or ISO 27001 certification and we do not claim to. See the security page for the full statement, including what we have not done.

5. International transfers

Hosted data is stored in the European Union. Where a sub-processor operates outside the EEA, the transfer is covered by the standard contractual clauses, incorporated into this DPA by reference.

6. Assisting you

We will help you respond to data subject requests. Access and portability are self-service: export from the console at any time. Erasure is a single operation that removes transcripts, recordings and analytics rows together, available in the interface and through the API.

7. Breach notification

We will notify you without undue delay and in any case within seventy two hours of becoming aware of a personal data breach affecting your data, with what we know at the time rather than waiting for a complete picture.

8. Audit

We will answer security questionnaires ourselves and provide documentation on request. For deployments where an on-site audit right is required, self-hosting removes the need: the infrastructure is yours.

9. Deletion on termination

On termination we delete all personal data within thirty days, except where retention is required by law. Export before you close the account; the export is available on every plan.

10. Signing

Mail support@hepo.ai with your entity name and we will send a countersigned copy. There is no charge and no plan requirement for this.