Legal
Sub-processors
To run heykiku we rely on a small number of third parties. Every one of them that touches customer data is listed below — what they do, what they can see, and where they run it. If a company isn’t on this list, it doesn’t process your data.
Last updated 8 August 2026
Who processes what
Sevalla
Kinsta Inc.
- What it does
- Application hosting, PostgreSQL database, and object storage
- What it can see
- All customer content — documents, extracted text, voice memos, chat history, and account records
- Where it runs
- European Union (Frankfurt)
- Data processing agreement
- View DPA
Mistral AI
Mistral AI SAS
- What it does
- AI processing — answers, document text extraction, and search
- What it can see
- Document content and the questions asked about it
- Where it runs
- European Union (France)
- Data processing agreement
- View DPA
PostHog
PostHog, Inc.
- What it does
- Product analytics and error monitoring
- What it can see
- Usage events, cookieless, with visitor IP addresses discarded at ingestion — but cookieless is not the same as anonymous: once you are signed in, the analytics we send include your account id, so we can tell which workspace a problem belongs to. Your name and email address are not sent.
- Where it runs
- European Union (Frankfurt)
- Data processing agreement
- View DPA
Resend
Plus Five Five, Inc.
- What it does
- Transactional email — invites, verification, billing notices
- What it can see
- Recipient email address and message content
- Where it runs
- Sent from Ireland. Account metadata and delivery logs are stored in the United States.
- Data processing agreement
- View DPA
Polar
Polar Software Inc.
- What it does
- Billing, subscriptions, and payments
- What it can see
- Billing contact details, subscription state, and payment metadata. Card details go to Polar's payment provider — heykiku never sees them.
- Where it runs
- United States
- Data processing agreement
- View DPA
Cloudflare
Cloudflare, Inc.
- What it does
- Bot protection on the marketing chat bubble (Turnstile), and the CDN in front of our application
- What it can see
- IP address and browser signals used to score the challenge; request routing metadata
- Where it runs
- Global anycast network; US-incorporated
- Data processing agreement
- View DPA
Where your data actually lives
The content layer — your knowledge base, the documents in it, the answers generated from them, and your account records — stays in the European Union. Authentication is first-party: sign-in runs on our own EU-hosted infrastructure, not a third-party identity provider.
Billing and email delivery records are US-routed, and Cloudflare’s edge is a US-incorporated anycast network. We would rather say that plainly than round it up to “everything in the EU,” which is the claim most vendors make and few can support. All sub-processors operate under GDPR-compliant data-processing agreements, with transfers covered by Standard Contractual Clauses where they leave the EEA.
What isn’t on this list, and why
Google Drive. If you connect Drive, heykiku reads the files you point it at, using access you granted and can revoke. Google is processing your data for you, not for us, so it is a source you control rather than a sub-processor we appoint. The connection is yours to disconnect at any time.
Model training. No sub-processor on this list trains models on your content. Your documents are used to answer your questions and nothing else.
When this list changes
Before we add a sub-processor that will handle customer content, we update this page and email workspace owners. You have the right to object (GDPR Art. 28(2)) — write to us and we’ll talk it through; if we can’t resolve it, you can cancel and take your data with you.
Questions about anything here, or need a signed DPA? Email [email protected]. See also our privacy page.