Sub-processors

Last updated August 27, 2026

This page lists the third-party providers HAPP engages to deliver the Platform, the Assistant, and the Services. Each one processes personal data only on Our instructions and under written data processing terms, and their access is limited to what the relevant service requires.

We update this page before We add or replace a sub-processor. Business clients who want advance notice by email may subscribe by writing to [email protected] with the subject "subprocessor notifications"; We give 30 (thirty) days' notice of any addition or replacement, and Our Data Processing Agreement gives You the right to object.

Not every provider below receives data about every customer. Telephony, messaging, CRM and booking providers receive data only where You choose to connect that integration; if You do not connect it, nothing is sent to it.

Engaged for all customers. This is where Customer Data is stored. All storage and compute is located in the European Union.

Provider
Purpose
Personal data
Location
Transfer safeguard
Amazon Web Services, Inc.
Compute (EC2), managed PostgreSQL (RDS), object storage (S3), managed cache (ElastiCache)
All Customer Data stored on the Platform
EU — Frankfurt (eu-central-1)
AWS Data Processing Addendum incorporating the EU Standard Contractual Clauses, for provider-side administrative access; EU-US Data Privacy Framework
Cloudflare, Inc.
DNS, reverse proxy, CDN, DDoS protection, origin TLS certificates
IP address, request metadata, traffic in transit
Global edge; EU where available
Cloudflare Data Processing Addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework

These providers store Customer Data in the European Union and do not access it in the ordinary course of providing the service; they are listed because they hold technical access to the systems on which the data resides.

Engaged whenever an Assistant generates a response or speech. Conversation content is transmitted for the sole purpose of returning that response. No provider in this section is permitted to use Your data to train or improve its models.

Provider
Purpose
Personal data
Location
Transfer safeguard
OpenAI
Language model — response generation, analysis
Assistant instructions, message text, call transcripts
US; EU processing available
Data processing addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework. API data excluded from model training
Anthropic PBC
Language model — response generation, analysis
Assistant instructions, message text, call transcripts
US
Data processing addendum incorporating the EU Standard Contractual Clauses. API data excluded from model training
Google
Gemini language model
Assistant instructions, message text, call transcripts
EU / US
Cloud data processing addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework. Customer data excluded from model training
Groq, Inc.
Language model inference — low-latency response generation
Assistant instructions, message text, call transcripts
US
Provider data processing terms incorporating the EU Standard Contractual Clauses
ElevenLabs Inc.
Speech synthesis and speech recognition
Text for synthesis; call audio for recognition
US
Data processing addendum incorporating the EU Standard Contractual Clauses. Enterprise terms exclude model training

Engaged only where You connect the channel.

Provider
Purpose
Personal data
Location
Transfer safeguard
Meta Platforms Ireland Ltd
WhatsApp Business API, Instagram and Facebook Messenger
End-user name, phone number, avatar, message content, media
EU / US
Business Tools data processing terms and EU Data Transfer Addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework
Telegram Messenger Inc.
Telegram Bot API
End-user name, username, message content, media
Outside the EEA
Telegram Bot Platform terms — see the note below
Rakuten Viber
Viber business messaging
End-user name, phone number, message content, media
EU / outside the EEA
Provider data processing terms incorporating the EU Standard Contractual Clauses
Binotel, Ringostat, Phonet, Unitalk
Telephony — receiving and placing calls
Phone number, call metadata, call audio
Ukraine / EU
Provider data processing terms; Ukrainian law on personal data protection

Telegram

Telegram does not offer a GDPR data processing agreement to bot operators. We disclose this rather than assert a mechanism that does not exist. If Your compliance posture requires a complete processor chain, do not enable the Telegram channel; enabling it is Your instruction, given with knowledge of this limitation.

Channel operators as independent controllers

Where You connect WhatsApp, Instagram, Facebook Messenger, Telegram or Viber, the operator of that platform also processes end-user personal data as an independent controller under its own terms, outside Our control and outside Our Data Processing Agreement. Your relationship with, and obligations towards, those operators are Yours.

Provider
Purpose
Personal data
Location
Transfer safeguard
NetHunt, KeyCRM, SalesDrive, Odoo, Altegio, Google Sheets
CRM, booking and export — synchronising leads and records at your direction
Contact records, lead and booking data as configured by you
Ukraine / EU / US, per provider
Provider data processing terms; EU Standard Contractual Clauses where the provider is outside the EEA
Resend, SendPulse
Transactional email and SMS — verification codes, service notifications
Email address, phone number, message content
EU / US
Provider data processing addendum incorporating the EU Standard Contractual Clauses
Sentry
Error and performance diagnostics
Error traces, pseudonymised identifiers, technical metadata. Conversation content is excluded from application logs
EU / US
Provider data processing addendum incorporating the EU Standard Contractual Clauses
Google (Firebase) — Mobile Application only
Push notifications and mobile analytics
Device token, app usage events
EU / US
Provider data processing terms incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework
Provider
Purpose
Personal data
Location
Transfer safeguard
Google
Sign in with Google
Email address, name, avatar
EU / US
Cloud data processing addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework
Apple Distribution International Ltd
Sign in with Apple; App Store in-app purchases
Email address, name, purchase records
EU / US
Developer Program terms incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework
RevenueCat, Inc.
In-app subscription management
Pseudonymous app user identifier, subscription status
US
Provider data processing addendum incorporating the EU Standard Contractual Clauses
Monobank (JSC Universal Bank)
Card payments on the web Platform
Transaction identifier, amount, status. Full card numbers are never received or stored by HAPP
Ukraine / EU
Provider data processing terms; PCI DSS handled by the provider

All Customer Data is stored at rest in the European Union (Frankfurt, Germany). We do not change the storage region without prior notice to Our business clients.

HAPP is established in Ukraine and Our personnel access the Platform from there. Ukraine is not covered by an adequacy decision of the European Commission, so that access is itself a transfer of personal data to a third country. We rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), together with the technical and organisational measures described in Our Privacy Notice.

  • To request a copy of the transfer safeguards relied on for a specific provider, with commercially confidential terms redacted, write to [email protected].
  • To object to a new sub-processor, or to request a counter-signed Data Processing Agreement, write to [email protected].
  • For product or billing questions, write to [email protected].