Sub-processor List
Effective 2026-06-21 · 2026-06-21
hey ema — Sub-processor List
Last updated: 2026-06-21
1. Purpose
This Sub-processor List sets out the third parties that Hey ema engages to Process Personal Information on Hey ema's behalf in providing Hey ema. It is incorporated by reference into Hey ema's Data Processing Agreement (DPA) at Annex III.
By executing the MSA, the Customer is taken to authorise the Sub-processors listed below as at the Effective Date of the MSA. New or replacement Sub-processors will be notified in accordance with §7 of the DPA.
2. How to subscribe to updates
Customers can subscribe to email notifications about changes to this list at https://heyema.app/docs/sub-processors or by emailing privacy@heyema.com.
3. Current Sub-processors
3.1 Core infrastructure
| Sub-processor | Purpose | Personal Information categories | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, compute, and networking (including ECS, RDS, S3, and related services) | All categories of Customer Data | Australia (ap-southeast-2), United States, Europe (depending on Customer region) | AWS DPA + EU SCCs / UK IDTA where relevant |
| Amazon Web Services, Inc. (Amazon CloudFront) | Content delivery for static assets and signed media URLs | IP address, request metadata | Global edge | AWS DPA + EU SCCs / UK IDTA where relevant |
| Amazon Web Services, Inc. (Amazon IVS) | Live stream ingest, playback, and recording | Stream metadata; limited viewer context | Australia (ap-southeast-2) | AWS DPA + EU SCCs / UK IDTA where relevant |
| Cloudflare, Inc. (RealtimeKit) | Real-time video meetings only (not used for general CDN or WAF) | Participant identity; audio and video during active sessions | Australia and configured Realtime regions | Cloudflare DPA + EU SCCs / UK Addendum where relevant |
3.2 AI / model providers
Hey ema does not call Anthropic or OpenAI APIs directly. Large-language-model inference is provided only through the Sub-processors below.
| Sub-processor | Purpose | Personal Information categories | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Microsoft (Azure AI Foundry / Azure OpenAI Service) | Large-language-model inference for AI chat and agent features | Prompts and contextual data submitted via Hey ema features | Models deployed in-region (Australia) | Microsoft Products & Services DPA + EU SCCs / UK Addendum where relevant |
| Amazon Web Services, Inc. (Amazon Bedrock) | Large-language-model inference for video and meeting AI (for example summaries, action items, and segmentation) | Transcripts, meeting content, and prompts submitted for processing | Australia (ap-southeast-2) | AWS DPA + EU SCCs / UK IDTA where relevant |
Azure AI Foundry models are deployed in-region. Customer Data submitted for inference through Azure is not used to train the models, is not retained beyond the request, and is not transferred out of region on those terms. Bedrock inference is confined to the AWS region in which the request is processed.
3.3 Operational tools
| Sub-processor | Purpose | Personal Information categories | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing for platform billing and, where enabled, tenant commerce | Billing contact details, payment instrument tokens, transaction metadata | United States and Australia | Stripe DPA + SCCs |
| Amazon Web Services, Inc. (Amazon SES) | Transactional email delivery | Recipient email address and email content | Australia (ap-southeast-2) | AWS DPA + EU SCCs / UK IDTA where relevant |
| Amazon Web Services, Inc. (Amazon SNS / End User Messaging) | SMS notifications | Mobile phone number and message content | Australia (ap-southeast-2) (ap-southeast-2) | AWS DPA + EU SCCs / UK IDTA where relevant |
| Chatwoot (self-hosted by By Loci Pty Ltd) | In-app customer support | Name, email address, and support conversation content | Australia (self-hosted) | Not applicable — hosted in Australia under Hey ema's control |
| Sentry (Functional Software, Inc.) | Error, performance, and session-replay monitoring | Telemetry; device and browser metadata; occasional Personal Information in error or replay contexts | United States | Sentry DPA + SCCs |
| Google LLC (Firebase Cloud Messaging) | Web push notifications where an End User opts in | Device push token; optional user identifier linked to the token | Global | Google Cloud Data Processing Terms + SCCs |
| Google LLC (Tag Manager) | Analytics on the documentation site at https://docs.heyema.app only | Pseudonymised usage and navigation data | Global | Google SCCs |
3.4 Identity and enrichment
The Sub-processors in this section are engaged only when a relevant sign-in or enrichment feature is enabled — for example when an End User chooses a social login on the platform, or profile enrichment is turned on for a tenant. They are not used for Hey ema's internal administration. Customer-configured integrations (including Microsoft 365 calendar, Teams, and meetings) are described in §3.5.
| Sub-processor | Purpose | Personal Information categories | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Microsoft Corporation (Entra ID / Microsoft account) | Platform sign-in when an End User chooses Microsoft authentication | Name and email address from the identity provider | Customer Microsoft tenant region; United States / Europe | Microsoft Products & Services DPA + EU SCCs / UK Addendum where relevant |
| Google LLC | Platform sign-in (Google OAuth) when enabled | Name and email address from the identity provider | Global | Google SCCs |
| Apple Inc. | Platform sign-in when enabled; Apple Wallet event passes | Name and email address from the identity provider; pass holder details on device | Global | Apple terms and applicable DPAs |
| Meta Platforms, Inc. | Platform sign-in (Facebook Login) when enabled | Name and email address from the identity provider | Global | Meta SCCs |
| GitHub, Inc. | Platform sign-in when enabled | Name, email address, and public profile fields from the identity provider | United States | GitHub DPA + SCCs |
| LinkedIn Corporation | Platform sign-in when enabled | Name and email address from the identity provider | United States / global | LinkedIn DPA + SCCs |
| Clearbit, Inc. | Attendee profile enrichment when the feature is enabled | Email address and enriched professional profile attributes | United States | Clearbit DPA + SCCs |
| Apollo.io | Attendee profile enrichment when the feature is enabled | Email address, organisation name, and enriched profile attributes | United States | Apollo DPA + SCCs |
3.5 Customer-configured integrations and custom SSO
Customers may enable third-party integrations and custom single sign-on for their End Users. Those providers are chosen and configured by the Customer and are not Sub-processors of Hey ema unless Hey ema separately engages them on the Customer's behalf.
Where a Customer enables such an integration or custom SSO, Personal Information may be disclosed to that third party as directed by the Customer. The Customer is responsible for its relationship with that provider, including any required notices and agreements. Hey ema facilitates the technical connection only.
Examples of Customer-configured integrations include:
- Microsoft 365 (Microsoft Graph) — calendar sync, Teams and meeting subscriptions, Outlook add-in document access, and related collaboration features when a Customer connects its Microsoft tenant;
- Slack — notifications and interactive workflows when a Customer connects its Slack workspace;
- Registration, program, accounting, and membership systems — for example EventsAir, Capstan, Stripe (tenant commerce), Xero, and membership or CE write-back providers; and
- Custom SSO — identity providers configured by the Customer for End User sign-in to a tenant portal.
The integrations available in Hey ema may change over time. Material additions of Hey ema-engaged Sub-processors that Process Customer Data on Hey ema's behalf will be notified under §7 of the DPA. Customer-configured integrations are outside that notification process unless Hey ema begins Processing through a new centrally operated Sub-processor.
4. Affiliates
By Loci Pty Ltd may engage Affiliates as Sub-processors on the same terms as third-party Sub-processors. The current list of relevant Affiliates is: none currently listed.