Privacy
Privacy
Where heykiku stores your data, how long we keep it, why we’re allowed to process it, and the controls you have. Questions? Email [email protected].
Support access (impersonation)
To help us reproduce UI issues you report, the heykiku team can sign in to your workspace as you. We use this to look at the same screens you see — not to read documents you wouldn’t already show us.
Each impersonation session requires a written reason, is recorded in our audit log, and automatically expires after 60 minutes.
We rely on legitimate interest (GDPR Art. 6(1)(f)) as the legal basis for support access — the standard basis B2B SaaS tools use for support work, because providing support is necessary for us to deliver the service you signed up for. That’s also why the setting is on by default: legitimate interest doesn’t require an opt-in, it requires that you can say no.
And you can: you retain the right to object (GDPR Art. 21), and the toggle at Account → Privacy is how you exercise it. Switch support access off at any time — sign-in attempts are rejected from then on, and any impersonated session for your account is signed out the moment it tries to load the dashboard.
Marketing chat bubble
On parts of this site you’ll see a small chat bubble that lets you ask kiku, our AI assistant, about heykiku before you sign up. We log the conversation along with the page you were on, the referrer, and any UTM parameters in the URL. We do this so we can answer follow-up questions, improve the bot, and recognise your reply if you later choose to email us.
If you click email me a recap we send the transcript to [email protected] so we can reply to you. The reply is a manual one-to-one email — we do not enrol you in any marketing list.
Processors involved: Mistral (the model that generates kiku’s replies), Resend (delivers the email recap), Cloudflare Turnstile (bot protection on the first message), and PostHog EU (cookieless product analytics — your chat messages and your email address are never sent to PostHog).
Want a conversation deleted? Email [email protected] from the same address you used to chat with us. We’ll remove the matching rows.
Sub-processors and where your data lives
Your customer content — the knowledge base, documents, voice memos, and chat history — is hosted in the European Union. Authentication is first-party: sign-in runs on our own EU-hosted infrastructure, not a third-party identity provider.
The full list — every sub-processor, what it can see, and where it runs — lives on its own page so it can be dated and referenced from a DPA: heykiku.com/sub-processors.
In short: the content layer stays in the EU, while billing and email delivery records are US-routed — a common pattern we prefer to disclose plainly rather than round up to a claim like “everything in the EU.” All sub-processors operate under GDPR-compliant data-processing agreements.
How long we keep your data
Your data lives as long as your account does, and leaves when you do. We don’t warehouse things “just in case.”
| What | How long |
|---|---|
| Your account (email, name, password hash) | Until you delete your account — then removed immediately |
| Your workspace and everything in it (documents, folders, settings) | Until you delete the workspace, plus a 7-day grace period in case you change your mind — then permanently erased, including the copies our AI provider indexed |
| Chat conversations and voice memos | Hidden immediately when you delete them; fully removed, including the AI provider’s copy, when your account or workspace is erased |
| Product analytics | Determined by our analytics provider’s plan retention — cookieless, no names or emails |
| Sign-in sessions | Expire after 7 days of inactivity and are swept from our database automatically |
| Audit logs (who did what, from where) | Retained for security purposes — if you delete your account, your name is removed from log entries right away, though IP addresses and device metadata on those entries are kept for incident investigation |
| Billing records and invoices | As long as tax law requires — the one thing account deletion legally can’t erase |
| Pre-signup chats (the marketing bubble) | Until you ask us to remove them |
Two honest footnotes. First, database backups: when you delete something, it disappears from the live product immediately, but it takes up to 7 days to age out of our automated database backups. Second, account erasure removes your personal data from the live database, but a small amount of residual data stays for operational reasons — security audit entries (with IP metadata kept for incident investigation), questions your team asked (the workspace’s knowledge, not yours), your pseudonymous analytics identifier (an account id, never your name or email), and some operational records (verification tokens, lifecycle-email logs, unsubscribe preferences). We document these explicitly rather than claiming “everything” is gone when it isn’t.
Workspace deletion has one separate analytics step. It removes your workspace content from heykiku and the AI provider, but the automatic teardown does not currently remove the PostHog workspace group or events carrying the workspace’s tenant id. If you ask us to remove the full customer dataset, email [email protected] and we’ll handle that PostHog deletion by hand. PostHog’s response is asynchronous, so we only describe it as complete after we receive a provider receipt and verify the group and its tenant-tagged events are gone.
Want something gone faster? Email [email protected] and we’ll handle it ourselves.
Why we’re allowed to process your data
GDPR requires a legal basis for every kind of processing — here’s ours, in plain words rather than article numbers.
Because you asked us to (contract — Art. 6(1)(b))
Almost everything heykiku does is just the product working: storing your documents, answering questions about them, transcribing voice memos, keeping you signed in, sending you the emails the product needs to send (password resets, invites, invoices). We can’t do the job without processing this data, and this is the basis for it.
One important nuance: for the content of your knowledge base, your agency is in charge — legally, the “controller” — and we process it strictly on your instructions. What’s inside your documents is between you and the people in them; our job is to store it, search it, and never look at it for our own purposes.
Because the law makes us (legal obligation — Art. 6(1)(c))
Invoices and billing records stick around for as long as bookkeeping law requires. Not our choice, and not something account deletion can override.
Because it’s reasonable, and you can object (legitimate interest — Art. 6(1)(f))
A few things we do without asking first, because the impact on you is small and the alternative is a worse product: cookieless analytics (no names, no emails, EU-hosted), security audit logs, the occasional onboarding email while you’re getting set up (every one has an unsubscribe link), the pre-signup chat bubble, and support access — which has its own section above.
For all of these you have the right to object (Art. 21): unsubscribe, flip the toggle, or email [email protected], and we’ll stop.
What we never rely on
We don’t process your data based on consent walls, we don’t sell it, and there is no basis under which we would use your knowledge base to train AI models.
Your rights
Want a copy of your data, or your account and its data removed? Email [email protected] from your account address and we’ll handle it — we reply to every request ourselves.
You also have the right to lodge a complaint with your local data-protection authority (GDPR Art. 77). If something feels wrong, we’d appreciate the chance to fix it first — but that right is yours either way.
See also: Terms of service · Sub-processors