Legal
Sub-processors
Every third-party provider HAPP engages to run the platform — what each one processes, where, and under which transfer safeguard. Privacy Notice section 8 and our Data Processing Agreement both point here as the authoritative list.
- Version
- Last updated 27 August 2026
- Company
- Happ
- Contact
- [email protected]
This page lists the third-party providers HAPP engages to deliver the Platform, the Assistant, and the Services. Each one processes personal data only on Our instructions and under written data processing terms, and their access is limited to what the relevant service requires.
We update this page before We add or replace a sub-processor. Business clients who want advance notice by email may subscribe by writing to [email protected] with the subject "subprocessor notifications"; We give 30 (thirty) days' notice of any addition or replacement, and Our Data Processing Agreement gives You the right to object.
Not every provider below receives data about every customer. Telephony, messaging, CRM and booking providers receive data only where You choose to connect that integration; if You do not connect it, nothing is sent to it.
Core infrastructure
Engaged for all customers. This is where Customer Data is stored — all of it in the European Union.
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Compute (EC2), managed PostgreSQL (RDS), object storage (S3), managed cache (ElastiCache) | All Customer Data stored on the Platform | EU — Frankfurt (eu-central-1) | AWS Data Processing Addendum incorporating the EU Standard Contractual Clauses, for provider-side administrative access; EU-US Data Privacy Framework |
| Cloudflare, Inc. | DNS, reverse proxy, CDN, DDoS protection, origin TLS certificates | IP address, request metadata, traffic in transit | Global edge; EU where available | Cloudflare Data Processing Addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework |
These providers do not access Customer Data in the ordinary course of providing their services; they are listed because they hold technical access to the systems on which the data resides or through which it transits.
Artificial intelligence providers
Engaged whenever an Assistant generates a response or speech. Conversation content is transmitted for the sole purpose of returning that response. Call audio and media files are not transmitted to language model providers. No provider in this section is permitted to use Your data to train or improve its models.
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| OpenAI (Ireland / USA) | Language model — response generation and analysis | Assistant instructions, message text, call transcripts | US; EU processing available | Data processing addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework. API data excluded from model training |
| Anthropic PBC (USA) | Language model — response generation and analysis | Assistant instructions, message text, call transcripts | US | Data processing addendum incorporating the EU Standard Contractual Clauses. API data excluded from model training |
| Google (Ireland / USA) | Gemini language model | Assistant instructions, message text, call transcripts | EU / US | Cloud data processing addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework. Customer data excluded from model training |
| Groq, Inc. (USA) | Language model inference — low-latency response generation | Assistant instructions, message text, call transcripts | US | Provider data processing terms incorporating the EU Standard Contractual Clauses |
| ElevenLabs Inc. (USA) | Speech synthesis and speech recognition | Text for synthesis; call audio for recognition | US | Data processing addendum incorporating the EU Standard Contractual Clauses. Enterprise terms exclude model training |
Communication channels
Engaged only where You connect the channel.
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Meta Platforms Ireland Ltd | WhatsApp Business API; Instagram and Facebook Messenger | End-user name, phone number, avatar, message content, media | EU / US | Business Tools data processing terms and EU Data Transfer Addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework |
| Telegram Messenger Inc. | Telegram Bot API | End-user name, username, message content, media | Outside the EEA | Telegram Bot Platform terms — see the note below |
| Rakuten Viber | Viber business messaging | End-user name, phone number, message content, media | EU / outside the EEA | Provider data processing terms incorporating the EU Standard Contractual Clauses |
| Binotel, Ringostat, Phonet, Unitalk | Telephony — receiving and placing calls | Phone number, call metadata, call audio | Ukraine / EU | Provider data processing terms; Law of Ukraine "On Personal Data Protection" |
Telegram. Telegram does not offer a GDPR data processing agreement to bot operators. We disclose this rather than assert a mechanism that does not exist. If Your compliance posture requires a complete processor chain, do not enable the Telegram channel; enabling it is Your instruction, given with knowledge of this limitation.
Channel operators as independent controllers. Where You connect WhatsApp, Instagram, Facebook Messenger, Telegram or Viber, the operator of that platform also processes end-user personal data as an independent controller under its own terms, outside Our control and outside Our Data Processing Agreement. Your relationship with, and obligations towards, those operators are Yours.
CRM, booking, notifications and diagnostics
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| NetHunt, KeyCRM, SalesDrive, Odoo, Altegio, Google Sheets | CRM, booking and export — synchronising leads and records at Your direction | Contact records, lead and booking data as configured by You | Ukraine / EU / US, per provider | Provider data processing terms; EU Standard Contractual Clauses where the provider is outside the EEA |
| Resend, SendPulse | Transactional email and SMS — verification codes, service notifications | Email address, phone number, message content | EU / US | Provider data processing addendum incorporating the EU Standard Contractual Clauses |
| Sentry | Error and performance diagnostics | Error traces, pseudonymised identifiers, technical metadata. Conversation content is excluded from application logs | EU / US | Provider data processing addendum incorporating the EU Standard Contractual Clauses |
| Google (Firebase) — Mobile Application only | Push notifications and mobile analytics | Device token, app usage events | EU / US | Provider data processing terms incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework |
Authentication and billing
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Google (Ireland / USA) | Sign in with Google | Email address, name, avatar | EU / US | Cloud data processing addendum incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework |
| Apple Distribution International Ltd | Sign in with Apple; App Store in-app purchases | Email address, name, purchase records | EU / US | Developer Program terms incorporating the EU Standard Contractual Clauses; EU-US Data Privacy Framework |
| RevenueCat, Inc. (USA) | In-app subscription management | Pseudonymous app user identifier, subscription status | US | Provider data processing addendum incorporating the EU Standard Contractual Clauses |
| Monobank (JSC Universal Bank, Ukraine) | Card payment processing | Transaction identifier, amount, status. Full card numbers are never received or stored by HAPP | Ukraine / EU | Provider data processing terms; PCI DSS handled by the provider |
Where Your data is stored
All Customer Data is stored at rest in the European Union (Frankfurt, Germany). We do not change the storage region without prior notice to Our business clients.
HAPP is established in Ukraine and Our personnel access the Platform from there. Ukraine is not covered by an adequacy decision of the European Commission, so that access is itself a transfer of personal data to a third country. We rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), together with the technical and organisational measures described in Our Privacy Notice.
Questions and copies
- To request a copy of the transfer safeguards relied on for a specific provider, with commercially confidential terms redacted, write to [email protected].
- To object to a new sub-processor, or to request a counter-signed Data Processing Agreement, write to [email protected].
- For product or billing questions, write to [email protected].