Data Processing Agreement
When you use Heyloha, we process personal data on your organisation's behalf. The terms for that are set out in this agreement, as Article 28 of the GDPR requires.
Version 1.3, last changed 9 October 2026
Download
The English version is the binding one.
Need a signed copy? Email support@heyloha.ai and we'll send you one to sign.
In short
- You are the controller and Heyloha is the processor. We only process personal data on your documented instructions: this agreement, your dashboard settings and your AI agents.
- The providers we use are on our public sub-processor list. We email you at least 30 days before adding or replacing one, and you can object.
- If a personal data breach affects your data, we tell you without undue delay and within 72 hours at the latest.
- We don't use your conversations, transcripts or knowledge base to train AI models, and neither does our language model provider, OpenAI.
- When the contract ends, we return or delete your data within 30 days of your instruction. Without an instruction, we delete it within 90 days.
- You can audit our compliance at most once a year, with 30 days' notice.
- Our main processing happens in the Netherlands, and the agreement is governed by Dutch law.
This summary doesn't replace the agreement. Where they differ, the agreement applies.