Skip to content

Legal

Sub-processors

To run heykiku we rely on a small number of third parties. Every one of them that touches customer data is listed below — what they do, what they can see, and where they run it. If a company isn’t on this list, it doesn’t process your data.

Last updated 8 August 2026

Who processes what

Sevalla

Kinsta Inc.

What it does
Application hosting, PostgreSQL database, and object storage
What it can see
All customer content — documents, extracted text, voice memos, chat history, and account records
Where it runs
European Union (Frankfurt)
Data processing agreement
View DPA

Mistral AI

Mistral AI SAS

What it does
AI processing — answers, document text extraction, and search
What it can see
Document content and the questions asked about it
Where it runs
European Union (France)
Data processing agreement
View DPA

PostHog

PostHog, Inc.

What it does
Product analytics and error monitoring
What it can see
Usage events, cookieless, with visitor IP addresses discarded at ingestion — but cookieless is not the same as anonymous: once you are signed in, the analytics we send include your account id, so we can tell which workspace a problem belongs to. Your name and email address are not sent.
Where it runs
European Union (Frankfurt)
Data processing agreement
View DPA

Resend

Plus Five Five, Inc.

What it does
Transactional email — invites, verification, billing notices
What it can see
Recipient email address and message content
Where it runs
Sent from Ireland. Account metadata and delivery logs are stored in the United States.
Data processing agreement
View DPA

Polar

Polar Software Inc.

What it does
Billing, subscriptions, and payments
What it can see
Billing contact details, subscription state, and payment metadata. Card details go to Polar's payment provider — heykiku never sees them.
Where it runs
United States
Data processing agreement
View DPA

Cloudflare

Cloudflare, Inc.

What it does
Bot protection on the marketing chat bubble (Turnstile), and the CDN in front of our application
What it can see
IP address and browser signals used to score the challenge; request routing metadata
Where it runs
Global anycast network; US-incorporated
Data processing agreement
View DPA

Where your data actually lives

The content layer — your knowledge base, the documents in it, the answers generated from them, and your account records — stays in the European Union. Authentication is first-party: sign-in runs on our own EU-hosted infrastructure, not a third-party identity provider.

Billing and email delivery records are US-routed, and Cloudflare’s edge is a US-incorporated anycast network. We would rather say that plainly than round it up to “everything in the EU,” which is the claim most vendors make and few can support. All sub-processors operate under GDPR-compliant data-processing agreements, with transfers covered by Standard Contractual Clauses where they leave the EEA.

What isn’t on this list, and why

Google Drive. If you connect Drive, heykiku reads the files you point it at, using access you granted and can revoke. Google is processing your data for you, not for us, so it is a source you control rather than a sub-processor we appoint. The connection is yours to disconnect at any time.

Model training. No sub-processor on this list trains models on your content. Your documents are used to answer your questions and nothing else.

When this list changes

Before we add a sub-processor that will handle customer content, we update this page and email workspace owners. You have the right to object (GDPR Art. 28(2)) — write to us and we’ll talk it through; if we can’t resolve it, you can cancel and take your data with you.

Questions about anything here, or need a signed DPA? Email [email protected]. See also our privacy page.