Data processing agreement
Last updated 22 July 2026
This DPA forms part of the terms of service between you, the controller, and Hepo, the processor. A countersigned PDF is available on request and is the version to file.
1. Scope
We process personal data only to provide the service and only on your documented instructions. Your instructions are your configuration: which modules are enabled, what retention you set, which fields you exclude from capture.
2. Categories of data
| Category | Examples |
|---|---|
| Contact data | Email, name and attributes you pass through identify |
| Conversation data | Messages, attachments, internal notes, translations |
| Technical data | IP derived city, network operator, browser, operating system |
| Behavioural data | Session recordings as masked DOM events, page views, referrers |
Data subjects are your website visitors and the members of your own team who use the console.
3. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Object storage provider | Recordings and uploaded files | European Union |
| Model provider | AI agent responses, hosted plans only | European Union or United States |
We give thirty days notice before adding or replacing a sub-processor, and you may object. Self hosted deployments have no sub-processors at all, which is the cleanest answer to this section and one reason regulated buyers choose it.
4. Security measures
- TLS on every connection. Server-side encryption at rest on the object store.
- Input masking applied in the visitor browser before transmission, with no option to disable.
- Role-based access enforced server side, scoped per site, not merely hidden in the interface.
- Access to production systems limited to named engineers with individual credentials.
- Recordings expire and are purged on the retention policy you configure.
We do not currently hold SOC 2 or ISO 27001 certification and we do not claim to. See the security page for the full statement, including what we have not done.
5. International transfers
Hosted data is stored in the European Union. Where a sub-processor operates outside the EEA, the transfer is covered by the standard contractual clauses, incorporated into this DPA by reference.
6. Assisting you
We will help you respond to data subject requests. Access and portability are self-service: export from the console at any time. Erasure is a single operation that removes transcripts, recordings and analytics rows together, available in the interface and through the API.
7. Breach notification
We will notify you without undue delay and in any case within seventy two hours of becoming aware of a personal data breach affecting your data, with what we know at the time rather than waiting for a complete picture.
8. Audit
We will answer security questionnaires ourselves and provide documentation on request. For deployments where an on-site audit right is required, self-hosting removes the need: the infrastructure is yours.
9. Deletion on termination
On termination we delete all personal data within thirty days, except where retention is required by law. Export before you close the account; the export is available on every plan.
10. Signing
Mail support@hepo.ai with your entity name and we will send a countersigned copy. There is no charge and no plan requirement for this.