Data Processing
This page describes how HMH Labz LLP processes personal data when a business (“the client”) uses Heyozo. The client is the data fiduciary (controller) for its customers' data; HMH Labz is its data processor. Each client also receives a description generated from its own live configuration with its contract.
Purpose
An automated assistant answers the client's customers on the client's WhatsApp number and, if the client has one, its Telegram bot, records what they ask for, and hands conversations to the client's staff when needed. The client's staff use a web dashboard to see and act on the same data.
Data subjects and personal data
Data subjects: the client's customers who message its WhatsApp number or Telegram bot or are imported from its records, and the client's staff who sign in to the dashboard.
- WhatsApp number and profile name, or Telegram user ID, username and display name; name, area, address note and language when given.
- Message content in both directions. Voice notes are transcribed and only the transcript is kept.
- Marketing consent and its evidence: the exact wording shown, the time and the source.
- Depending on the features the client uses: orders (items, quantities, delivery note, date and status), prepaid coupons, appointments, and campaign delivery and replies.
- Staff accounts: email, name, role, sign-in times, and an audit log of changes.
No special categories of data are requested. Payment card data is never handled.
Our commitments as processor
- Process the data only on the client's documented instructions and for the purpose above.
- Ensure everyone with access is bound by confidentiality.
- Keep the security measures below in place.
- Use the sub-processors listed below, each under a written contract, and tell clients in advance about new ones so they can object.
- Help the client answer requests from its customers and meet its own legal duties.
- Notify the client without undue delay after becoming aware of a personal data breach, with the information it needs.
- At the end of the service, delete or return the data as the client instructs.
- Make available the information needed to show compliance, and allow reasonable audits by agreement.
Sub-processors
| Sub-processor | What it does | Location |
|---|---|---|
| Amazon Web Services, Inc. | Hosts the application and database (Amazon EC2). | United States (us-east-1) |
| Meta Platforms Ireland Ltd (WhatsApp Business Platform) | Carries every WhatsApp message to and from customers, on the business's own WhatsApp Business Account. | Meta's global infrastructure |
| Telegram (Telegram Bot API), only for clients who connect a Telegram bot | Carries every Telegram message to and from customers who started the business's own bot. | Telegram's global infrastructure |
| Google LLC (Gemini API) | Generates the assistant's replies and transcribes voice notes. Receives the conversation text needed for each reply, under Google's paid API terms. | Google's global infrastructure |
| OpenRouter, Inc. | Back-up route to a comparable model, used only when the Gemini API is unavailable. | United States |
| Cloudflare, Inc. | DNS for heyozo.com, and storage of encrypted backups (R2). Message content does not pass through Cloudflare's network in normal operation. | Global (DNS); backups as configured |
Security measures
- Each client's data is isolated in the database by row-level security enforced by PostgreSQL; the application connects as a role that cannot bypass it, and every route is tested for cross-client access.
- Inbound WhatsApp webhooks are verified by Meta's signature, and Telegram webhooks by a per-bot secret, before they are processed.
- WhatsApp access tokens and Telegram bot tokens are encrypted at rest. No token, password or message content is written to logs.
- Dashboard sign-in with per-person accounts and roles; HMH Labz staff use a separate console with two-factor authentication.
- TLS for all traffic. Only web traffic reaches the server; administration is by key-only SSH on a non-standard port, with automatic security updates.
- Nightly backups, encrypted before upload with a key kept off the server, retained 30 days; restores are tested.
- Customers who reply STOP are opted out immediately, and campaigns can never reach them.
Retention
Records are kept for the life of the contract, then deleted or returned on the client's instruction. A shorter automatic period can be agreed and configured. Backups expire after 30 days.
International transfers
The application and database are hosted in the United States. Model providers, Meta and Telegram may process data in other countries. Transfers are made only as the DPDP Act and the client's applicable law permit, and the client is told where its data is processed.
Requests from customers
The client can find, correct and opt out a customer from its dashboard. Deletion of an individual's data is carried out by HMH Labz on the client's written instruction. Contact hello@hmhlabz.com.