This Data Processing Agreement ("DPA") forms part of the Terms of Service at hey.support/terms (the "Agreement") between Mungozone Web Solutions LLP, an Indian limited liability partnership (LLPIN AAB-1685) with its registered office at SH 16/46, Ashok Bhawan, Kadipur PO Shivpur, Varanasi, Uttar Pradesh, India 221003 ("Mungozone", "we", "us", "Processor"), and you, the entity subscribing to the Service ("Customer", "you", "Controller").
This DPA is pre-signed by Mungozone on behalf of the Processor and is deemed signed by Customer on the earlier of (i) acceptance of the Agreement or (ii) first paid Subscription. Enterprise Customers may sign a counterpart DPA document on request.
GrandWorks and Hey Support are trade names of Mungozone.
Definitions
Capitalised terms not defined here have the meanings given in the Agreement.
Applicable Data Protection Law means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK Data Protection Act 2018 and the UK GDPR ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act and California Privacy Rights Act ("CCPA / CPRA"), the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and any other applicable law.
Customer Personal Data means Personal Data processed by Mungozone on behalf of Customer under the Agreement.
Data Subject, Personal Data, Personal Data Breach, Processing, Processor, Controller, and Supervisory Authority have the meanings given in the GDPR.
Restricted Transfer means a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not recognised as providing an adequate level of protection.
SCCs means the Standard Contractual Clauses approved by the European Commission Decision (EU) 2021/914 of 4 June 2021, as amended.
Sub-processor means a third party engaged by Mungozone to process Customer Personal Data.
Service has the meaning given in the Agreement.
UK Addendum means the International Data Transfer Addendum to the SCCs issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018, as amended.
Roles and scope
For the purposes of Applicable Data Protection Law, the parties acknowledge and agree that:
- Customer is the Controller of Customer Personal Data
- Mungozone is the Processor acting on Customer's behalf
- Each party is responsible for its own compliance with Applicable Data Protection Law
This DPA applies to the Processing of Customer Personal Data by Mungozone in providing the Service to Customer. Annex A describes the details of Processing.
Mungozone separately acts as a Controller for Personal Data described in our Privacy Policy at hey.support/privacy, including data about Customer's billing contacts and Authorized Users. That Processing is governed by the Privacy Policy, not by this DPA.
Duration
This DPA begins on the earlier of (i) the Effective Date of the Agreement and (ii) Mungozone first Processing Customer Personal Data on Customer's behalf. It continues for the duration of the Agreement and for any period after termination during which Mungozone Processes Customer Personal Data on Customer's behalf, including for return or deletion under Section 13.
Details of Processing
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex A (Description of Processing). The Processing is necessary to provide the Service to Customer under the Agreement.
Customer instructions
Mungozone Processes Customer Personal Data only on documented instructions from Customer. The Agreement, this DPA, and Customer's use of the Service through its account constitute Customer's complete and final instructions to Mungozone for the Processing of Customer Personal Data.
Mungozone Processes Customer Personal Data for the following purposes:
- Providing, operating, securing, and supporting the Service
- Resolving Service-related issues
- Complying with Customer's reasonable instructions consistent with the Agreement
- Complying with applicable law
Mungozone will inform Customer if, in its opinion, an instruction violates Applicable Data Protection Law. Mungozone is not required to follow instructions that would violate Applicable Data Protection Law.
Mungozone will not Process Customer Personal Data for any other purpose. Specifically, Mungozone will not use Customer Personal Data to train AI models (its own or its Sub-processors').
Personnel and confidentiality
Mungozone will ensure that personnel authorised to Process Customer Personal Data:
- Are bound by appropriate confidentiality obligations
- Receive training on data protection and security relevant to their role
- Access Customer Personal Data only on a need-to-know basis
- Are subject to access controls that enforce least privilege
Security measures
Mungozone will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as required by Article 32 of the GDPR.
These measures are described in Annex B (Technical and Organisational Measures). Mungozone may update them from time to time, provided that the updates do not materially decrease the level of protection.
Sub-processors
General authorisation
Customer authorises Mungozone to engage Sub-processors to Process Customer Personal Data, subject to the conditions in this Section 8 and the SCCs (where applicable).
Current Sub-processors
The current Sub-processors are listed in Annex C (List of Sub-processors) and published at hey.support/subprocessors.
Sub-processor obligations
Mungozone will ensure each Sub-processor:
- Is bound by a written agreement that imposes data protection obligations equivalent to those in this DPA
- Provides sufficient guarantees to implement appropriate technical and organisational measures
- Is subject to confidentiality obligations regarding Customer Personal Data
- Is not authorised to use Customer Personal Data for its own purposes, including training of AI models, except as required to provide the contracted service to Mungozone
Mungozone remains liable to Customer for the acts and omissions of its Sub-processors.
Notification and objection
Mungozone will notify Customer at least thirty days before adding or replacing a Sub-processor. Customer may subscribe to such notifications by emailing [email protected].
If Customer objects to a new Sub-processor on reasonable data-protection grounds, Customer must notify Mungozone within thirty days of the announcement. The parties will work in good faith to resolve the objection, including by Mungozone offering an alternative arrangement. If no resolution is reached, Customer may terminate the affected portion of the Service for cause, and Mungozone will refund any prepaid fees for the unused portion of the term.
International transfers
Permitted transfers
Mungozone may transfer and Process Customer Personal Data outside the country of origin to provide the Service. The Service is operated from infrastructure in the United States. Sub-processors are located as specified in Annex C.
Transfers from the EEA, the United Kingdom, and Switzerland
Where transfers of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to Mungozone or its Sub-processors constitute Restricted Transfers, the SCCs Module Two (Controller to Processor) apply, as supplemented by the UK Addendum where applicable and as adjusted for Switzerland under FADP guidance.
The SCCs are incorporated into this DPA by reference and are described in Annex D (Standard Contractual Clauses). For the SCCs:
- Module Two (Controller to Processor) applies
- Clause 7 (Docking clause) applies
- Clause 9 Option 2 (General written authorisation) applies, with the thirty-day notice period in Section 8
- Clause 11(a) optional language does not apply
- Clause 17 governing law: Republic of Ireland
- Clause 18 forum: courts of Ireland
- Annex I.A (Parties): Customer is the data exporter; Mungozone is the data importer
- Annex I.B (Description of transfer): as set out in Annex A of this DPA
- Annex I.C (Competent supervisory authority): Customer's applicable EEA authority, or the Irish Data Protection Commission where no other authority is identified
- Annex II (Technical and organisational measures): as set out in Annex B of this DPA
- Annex III (List of sub-processors): as set out in Annex C of this DPA
UK Addendum
For transfers subject to UK GDPR, the UK Addendum to the SCCs applies. The tables of the UK Addendum are completed with reference to this DPA, the SCCs above, and the Annexes.
Swiss transfers
For transfers subject to FADP, the SCCs apply with the following adaptations:
- References to GDPR include FADP
- The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner
Other jurisdictions
For transfers subject to DPDP Act or other Applicable Data Protection Law, Mungozone will comply with applicable transfer requirements as they come into force. Enterprise Customers may negotiate specific transfer mechanisms in their Order Forms, including regional data residency where available.
Conflict
To the extent any provision of this DPA conflicts with the SCCs, the SCCs prevail in relation to Restricted Transfers.
Data Subject rights
Mungozone will, taking into account the nature of the Processing, assist Customer by appropriate technical and organisational measures, insofar as possible, to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
If Mungozone receives a request from a Data Subject relating to Customer Personal Data, Mungozone will:
- Promptly notify Customer
- Not respond directly to the Data Subject except as required by law or as agreed with Customer
- Provide reasonable cooperation in Customer's response, including by providing relevant tools and information available through the Service
Customer is responsible for responding to Data Subject requests relating to its Personal Data.
Personal Data Breach notification
Mungozone will notify Customer without undue delay, and in any event within seventy-two hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent reasonably known at the time of notification:
- The nature of the Personal Data Breach
- The categories and approximate number of Data Subjects and Personal Data records affected
- The likely consequences of the Personal Data Breach
- Measures taken or proposed to address the Personal Data Breach and mitigate its possible adverse effects
- Contact details for further information
Mungozone will reasonably cooperate with Customer in the investigation, mitigation, and remediation of any Personal Data Breach. Mungozone will document Personal Data Breaches in line with Applicable Data Protection Law.
Notifications under this Section 11 do not constitute an acknowledgment by Mungozone of any fault or liability.
Audits and certifications
Information
Mungozone will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. This includes:
- This DPA and the Privacy Policy
- The current list of Sub-processors
- Mungozone's Technical and Organisational Measures (Annex B)
- Independent audit reports as they become available (SOC 2 Type I expected Q3 2026, Type II expected Q1 2027)
- Reasonable responses to written security questionnaires
Audits
Customer may audit Mungozone's compliance with this DPA no more than once per twelve-month period, except where required by a Supervisory Authority or following a confirmed Personal Data Breach.
Audits will be conducted as follows:
- Customer gives Mungozone at least thirty days' written notice
- Audits take place during business hours, do not unreasonably interfere with Mungozone's operations, and are subject to confidentiality
- Customer may use an independent third-party auditor reasonably acceptable to Mungozone, bound by appropriate confidentiality obligations
- Audits do not require Mungozone to grant access to information of other customers, internal employee records, or commercially sensitive information unrelated to the audit
- Customer bears the cost of the audit, unless the audit reveals material non-compliance, in which case Mungozone bears reasonable cost
- Mungozone may satisfy audit obligations by providing relevant independent audit reports (SOC 2, ISO 27001, or equivalent) when available
Return and deletion
On termination or expiry of the Agreement, or earlier on Customer's written request, Mungozone will:
- Cease Processing Customer Personal Data, except as required by law
- At Customer's option, return Customer Personal Data to Customer or delete it
- Delete existing copies, except to the extent storage is required by law and only for the period required
Customer can export Customer Personal Data through the Service or the Public API at any time during the Subscription Term and for thirty days after termination. After thirty days, Mungozone may delete Customer Personal Data per its retention policy.
Deletion will propagate to operational backups within fourteen days, by rotation: backups are not edited in place, so a deleted record is removed from every backup still holding it as those backups age out of the recovery window. Where Mungozone restores from a backup, re-applying deletions made after that backup was taken is a required step of the restore. Audit logs, security logs, and billing records may be retained for longer where required by law, but will be protected per this DPA and may not be used for any other purpose.
On request, Mungozone will certify in writing that deletion has been carried out.
Liability
Each party's liability under or in connection with this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement.
Nothing in this DPA limits or excludes liability that cannot be limited or excluded under Applicable Data Protection Law.
Customer acknowledges that Mungozone's pricing reflects the allocation of risk in the Agreement.
Order of precedence
If there is a conflict:
- The SCCs (where applicable to a Restricted Transfer) prevail over this DPA
- This DPA prevails over the Agreement in matters of Personal Data Processing
- The Agreement prevails over this DPA in all other matters
Miscellaneous
Entire agreement
This DPA, including its Annexes, sets out the parties' entire agreement on the Processing of Customer Personal Data and supersedes any prior agreements on the same subject matter.
Amendment
Mungozone may amend this DPA from time to time as needed to reflect changes in Applicable Data Protection Law or in the Service. Material changes will be notified by email to account holders at least thirty days before they take effect. Amendments required by Applicable Data Protection Law may take effect immediately on notice.
Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force.
No third-party beneficiaries
Except for the SCCs (which give rights to Data Subjects under their third-party-beneficiary clauses) and except as required by Applicable Data Protection Law, this DPA does not create rights for any party other than Customer and Mungozone.
Governing law and jurisdiction
This DPA is governed by the laws of India, except that disputes relating to the SCCs are governed by the law specified in the SCCs (the Republic of Ireland).
Disputes are resolved per the dispute resolution clause of the Agreement, except that disputes relating to the SCCs are resolved per the SCCs.
Counterparts and signature
This DPA is pre-signed on behalf of Mungozone. Customer is deemed to sign on acceptance of the Agreement or on first paid Subscription. Enterprise Customers may execute a counterpart on request. Electronic signatures and click-through acceptance are valid.
Notices
Notices under this DPA may be given by email to the addresses on file or to:
- For Mungozone: [email protected], with formal legal notices also sent to the registered office
- For Customer: the primary administrator email on the account
Description of Processing
Subject matter
Provision of the Hey Support platform to Customer under the Agreement, including AI-powered customer support chatbots, knowledge base management, conversation handling, voice interactions, human handoff, and analytics.
Duration of processing
The Subscription Term, plus any period required for return or deletion of Customer Personal Data per Section 13.
Nature and purpose of processing
To operate the Service for Customer, including hosting, transmission, indexing, embedding, retrieval, response generation, and analytics on Customer Personal Data. To enable Customer's Authorized Users to manage chatbots and respond to end users. To provide support and security for the Service.
Categories of Data Subjects
- Customer's Authorized Users (employees, contractors, or other persons whom Customer authorizes to access the Service)
- Customer's end users who interact with chatbots deployed via the Service ("Visitors")
- Other individuals whose Personal Data Customer chooses to upload to the Service (for example, in lead records or knowledge base content)
Categories of Personal Data
For Authorized Users:
- Name, email address, password (hashed)
- Workspace assignments, role assignments
- Login timestamps, IP addresses, audit log entries
For Visitors and other individuals:
- Persistent visitor identifiers (random IDs)
- Conversation content (messages, AI responses, attachments)
- Voice recordings (if voice features are enabled)
- Names, email addresses, phone numbers, and other contact information that Visitors provide or that Customer captures via lead capture
- IP addresses and device-level signals
- Any other Personal Data Customer chooses to include in Customer Content (for example in uploaded documents, FAQ pairs, or knowledge sources)
Special categories of Personal Data
The Service is not designed for, and Customer should not use the Service to Process, special categories of Personal Data (Article 9 of GDPR), Personal Data relating to criminal convictions and offences (Article 10 of GDPR), or, for clarity, protected health information governed by HIPAA, without prior written agreement with Mungozone.
Frequency
Continuous for the duration of the Subscription Term.
Retention
Per Section 13 of this DPA and the Privacy Policy.
Technical and Organisational Measures
Mungozone implements and maintains the following Technical and Organisational Measures. These are intended to demonstrate compliance with Article 32 of the GDPR and may be updated from time to time.
1. Pseudonymisation and encryption
- TLS 1.3 for all data in transit
- AES-256 for all data at rest, including database, backups, and attachment storage
- Pseudonymous visitor identifiers used for chatbot end users; no direct identifier unless Visitors voluntarily provide one
- API keys stored as SHA-256 hashes only
2. Confidentiality, integrity, availability, and resilience
- Row-level security in the Postgres database enforcing tenant isolation at the data layer
- Cross-team isolation enforced at the API layer (out-of-scope requests return 404 to prevent enumeration)
- Strict origin validation on chat and configuration endpoints
- HMAC-SHA256 signed outbound webhooks with twenty-four-hour secret rotation overlap
- SSRF protections on outbound URL fetching (knowledge crawling, webhooks)
- Application redundancy via cloud-provider infrastructure
- Daily backups with seven-day point-in-time recovery
- Documented incident response plan
- Documented business continuity and disaster recovery procedures
3. Restoration after incidents
- Tested point-in-time recovery procedure
- Failover capability for application infrastructure
- Documented recovery time and recovery point objectives for production data
4. Process for testing and evaluating effectiveness
- Quarterly internal security reviews
- Vulnerability scanning on application infrastructure
- Periodic penetration testing on critical surfaces (planned annually)
- SOC 2 Type I audit programme begun (Type I expected Q3 2026, Type II Q1 2027)
- ISO 27001 evaluation planned for late 2027
5. User authentication and access controls
- Password hashing using bcrypt at strong cost factor
- Multi-factor authentication available; hardware-key 2FA required for Mungozone production access
- Role-based access controls (Platform Admin, Workspace Owner, Workspace Member)
- Least-privilege principle applied to internal access
- Production access restricted to a small number of authorised engineers
- Access reviews conducted periodically
- Single sign-on and SCIM provisioning planned for Enterprise plans
6. Logging and monitoring
- Application logs retained for ninety days with PII redaction where practicable
- Audit logs of security-relevant events retained for one year
- Centralised logging with alerting on anomalies
- Access logs for production systems
7. Software security
- Secure software development lifecycle including code review for production changes
- Dependency vulnerability monitoring and prompt patching
- Static analysis on application code where applicable
- Build pipeline enforces type-checking, linting, and testing before deployment
- Documented change management process
8. Physical security
- Infrastructure provided by cloud providers with their own physical security controls (Vercel, Supabase, others)
- Mungozone's offices have controlled physical access
- Production systems are not accessed from physical office locations except via authorised secure means
9. Awareness and training
- Security and data-protection training for personnel handling Customer Personal Data
- Periodic refresher training
- Policy on acceptable use, confidentiality, and incident reporting
10. Sub-processor management
- Written agreements with Sub-processors imposing data-protection obligations equivalent to those in this DPA
- Initial assessment of Sub-processors before engagement, including security and data-protection posture
- Periodic review of Sub-processor compliance
- Public list of Sub-processors at hey.support/subprocessors
- Thirty-day advance notice of new or replacement Sub-processors
11. Data minimisation and purpose limitation
- The Service is designed to collect only Personal Data necessary for chatbot operation
- Customer Content is scoped to the originating workspace and chatbot; no cross-tenant access
- Customer Content is not used to train AI models, ours or Sub-processors'
- Voice traffic is processed only when voice features are enabled
- Backups are encrypted and retained only as long as needed
12. Vendor and software integrity
- Inventory of approved Sub-processors and third-party libraries
- Periodic review of third-party access
- Use of established cloud providers with mature security postures
List of Sub-processors
The Sub-processors currently engaged in Processing Customer Personal Data are:
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, edge network, serverless compute | United States |
| Supabase Inc. | Managed Postgres database with pgvector extension, authentication, and storage | United States |
| OpenAI, L.L.C. | Large language model inference and text embeddings via API | United States |
| Cartesia AI Inc. | Voice synthesis (text-to-speech) and transcription (speech-to-text) | United States |
| Stripe, Inc. | Subscription billing and payments processing | United States |
| Razorpay Software Private Limited | Subscription billing and payments processing for customers in India | India |
| Resend Inc. | Transactional email delivery | United States |
| Apple Inc. | Push notification delivery to the Hey Support iOS app (Apple Push Notification service) | United States |
| Google LLC | Push notification delivery to the Hey Support Android app (Firebase Cloud Messaging) | United States |
| Functional Software, Inc. (Sentry) | Crash diagnostics for the Hey Support mobile apps | United States |
The current list is also published at hey.support/subprocessors.
Standard Contractual Clauses
Where Restricted Transfers occur, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor), are incorporated by reference into this DPA. The official text of the SCCs is available at the European Commission's website.
Module and options
- Module: Two (Controller to Processor)
- Clause 7 (Docking clause): Applies
- Clause 9 (Use of sub-processors): Option 2 (General written authorisation) applies, with the thirty-day notice period in Section 8 of this DPA
- Clause 11 (Redress): Optional independent dispute-resolution language does not apply
- Clause 17 (Governing law): Republic of Ireland
- Clause 18 (Forum): Courts of Ireland
Completion of SCC Annexes
The Annexes to the SCCs are completed by cross-reference to this DPA:
- SCC Annex I.A (List of parties): Customer is the data exporter; Mungozone is the data importer. Contact details are those of each party's notice address under this DPA
- SCC Annex I.B (Description of transfer): As set out in Annex A of this DPA
- SCC Annex I.C (Competent supervisory authority): The supervisory authority of the EEA Member State in which the data exporter is established. If the data exporter is not established in the EEA but its processing falls within the scope of the GDPR by virtue of Article 3(2), the Irish Data Protection Commission acts as competent supervisory authority
- SCC Annex II (Technical and organisational measures): As set out in Annex B of this DPA
- SCC Annex III (List of sub-processors): As set out in Annex C of this DPA
UK Addendum
For Restricted Transfers subject to UK GDPR, the International Data Transfer Addendum to the EU Commission's SCCs (version B1.0, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018) applies. Table 1 of the UK Addendum is completed by reference to the parties to this DPA. Table 2 is completed with reference to the SCCs above. Tables 3 and 4 are completed by reference to the Annexes to this DPA.
Swiss adaptations
For Restricted Transfers subject to FADP:
- References to "Member State" include Switzerland where applicable
- The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner
- Other adaptations required for FADP equivalence apply
Prevalence
In the event of any conflict between the SCCs and other provisions of this DPA, the SCCs prevail in relation to the Restricted Transfer to which they apply.