Sub-processor List

Effective 2026-06-21 · 2026-06-21

hey ema — Sub-processor List

Last updated: 2026-06-21

1. Purpose

This Sub-processor List sets out the third parties that Hey ema engages to Process Personal Information on Hey ema's behalf in providing Hey ema. It is incorporated by reference into Hey ema's Data Processing Agreement (DPA) at Annex III.

By executing the MSA, the Customer is taken to authorise the Sub-processors listed below as at the Effective Date of the MSA. New or replacement Sub-processors will be notified in accordance with §7 of the DPA.

2. How to subscribe to updates

Customers can subscribe to email notifications about changes to this list at https://heyema.app/docs/sub-processors or by emailing privacy@heyema.com.

3. Current Sub-processors

3.1 Core infrastructure

Sub-processorPurposePersonal Information categoriesProcessing locationTransfer mechanism
Amazon Web Services, Inc.Cloud hosting, storage, compute, and networking (including ECS, RDS, S3, and related services)All categories of Customer DataAustralia (ap-southeast-2), United States, Europe (depending on Customer region)AWS DPA + EU SCCs / UK IDTA where relevant
Amazon Web Services, Inc. (Amazon CloudFront)Content delivery for static assets and signed media URLsIP address, request metadataGlobal edgeAWS DPA + EU SCCs / UK IDTA where relevant
Amazon Web Services, Inc. (Amazon IVS)Live stream ingest, playback, and recordingStream metadata; limited viewer contextAustralia (ap-southeast-2)AWS DPA + EU SCCs / UK IDTA where relevant
Cloudflare, Inc. (RealtimeKit)Real-time video meetings only (not used for general CDN or WAF)Participant identity; audio and video during active sessionsAustralia and configured Realtime regionsCloudflare DPA + EU SCCs / UK Addendum where relevant

3.2 AI / model providers

Hey ema does not call Anthropic or OpenAI APIs directly. Large-language-model inference is provided only through the Sub-processors below.

Sub-processorPurposePersonal Information categoriesProcessing locationTransfer mechanism
Microsoft (Azure AI Foundry / Azure OpenAI Service)Large-language-model inference for AI chat and agent featuresPrompts and contextual data submitted via Hey ema featuresModels deployed in-region (Australia)Microsoft Products & Services DPA + EU SCCs / UK Addendum where relevant
Amazon Web Services, Inc. (Amazon Bedrock)Large-language-model inference for video and meeting AI (for example summaries, action items, and segmentation)Transcripts, meeting content, and prompts submitted for processingAustralia (ap-southeast-2)AWS DPA + EU SCCs / UK IDTA where relevant

Azure AI Foundry models are deployed in-region. Customer Data submitted for inference through Azure is not used to train the models, is not retained beyond the request, and is not transferred out of region on those terms. Bedrock inference is confined to the AWS region in which the request is processed.

3.3 Operational tools

Sub-processorPurposePersonal Information categoriesProcessing locationTransfer mechanism
Stripe, Inc.Payment processing for platform billing and, where enabled, tenant commerceBilling contact details, payment instrument tokens, transaction metadataUnited States and AustraliaStripe DPA + SCCs
Amazon Web Services, Inc. (Amazon SES)Transactional email deliveryRecipient email address and email contentAustralia (ap-southeast-2)AWS DPA + EU SCCs / UK IDTA where relevant
Amazon Web Services, Inc. (Amazon SNS / End User Messaging)SMS notificationsMobile phone number and message contentAustralia (ap-southeast-2) (ap-southeast-2)AWS DPA + EU SCCs / UK IDTA where relevant
Chatwoot (self-hosted by By Loci Pty Ltd)In-app customer supportName, email address, and support conversation contentAustralia (self-hosted)Not applicable — hosted in Australia under Hey ema's control
Sentry (Functional Software, Inc.)Error, performance, and session-replay monitoringTelemetry; device and browser metadata; occasional Personal Information in error or replay contextsUnited StatesSentry DPA + SCCs
Google LLC (Firebase Cloud Messaging)Web push notifications where an End User opts inDevice push token; optional user identifier linked to the tokenGlobalGoogle Cloud Data Processing Terms + SCCs
Google LLC (Tag Manager)Analytics on the documentation site at https://docs.heyema.app onlyPseudonymised usage and navigation dataGlobalGoogle SCCs

3.4 Identity and enrichment

The Sub-processors in this section are engaged only when a relevant sign-in or enrichment feature is enabled — for example when an End User chooses a social login on the platform, or profile enrichment is turned on for a tenant. They are not used for Hey ema's internal administration. Customer-configured integrations (including Microsoft 365 calendar, Teams, and meetings) are described in §3.5.

Sub-processorPurposePersonal Information categoriesProcessing locationTransfer mechanism
Microsoft Corporation (Entra ID / Microsoft account)Platform sign-in when an End User chooses Microsoft authenticationName and email address from the identity providerCustomer Microsoft tenant region; United States / EuropeMicrosoft Products & Services DPA + EU SCCs / UK Addendum where relevant
Google LLCPlatform sign-in (Google OAuth) when enabledName and email address from the identity providerGlobalGoogle SCCs
Apple Inc.Platform sign-in when enabled; Apple Wallet event passesName and email address from the identity provider; pass holder details on deviceGlobalApple terms and applicable DPAs
Meta Platforms, Inc.Platform sign-in (Facebook Login) when enabledName and email address from the identity providerGlobalMeta SCCs
GitHub, Inc.Platform sign-in when enabledName, email address, and public profile fields from the identity providerUnited StatesGitHub DPA + SCCs
LinkedIn CorporationPlatform sign-in when enabledName and email address from the identity providerUnited States / globalLinkedIn DPA + SCCs
Clearbit, Inc.Attendee profile enrichment when the feature is enabledEmail address and enriched professional profile attributesUnited StatesClearbit DPA + SCCs
Apollo.ioAttendee profile enrichment when the feature is enabledEmail address, organisation name, and enriched profile attributesUnited StatesApollo DPA + SCCs

3.5 Customer-configured integrations and custom SSO

Customers may enable third-party integrations and custom single sign-on for their End Users. Those providers are chosen and configured by the Customer and are not Sub-processors of Hey ema unless Hey ema separately engages them on the Customer's behalf.

Where a Customer enables such an integration or custom SSO, Personal Information may be disclosed to that third party as directed by the Customer. The Customer is responsible for its relationship with that provider, including any required notices and agreements. Hey ema facilitates the technical connection only.

Examples of Customer-configured integrations include:

  • Microsoft 365 (Microsoft Graph) — calendar sync, Teams and meeting subscriptions, Outlook add-in document access, and related collaboration features when a Customer connects its Microsoft tenant;
  • Slack — notifications and interactive workflows when a Customer connects its Slack workspace;
  • Registration, program, accounting, and membership systems — for example EventsAir, Capstan, Stripe (tenant commerce), Xero, and membership or CE write-back providers; and
  • Custom SSO — identity providers configured by the Customer for End User sign-in to a tenant portal.

The integrations available in Hey ema may change over time. Material additions of Hey ema-engaged Sub-processors that Process Customer Data on Hey ema's behalf will be notified under §7 of the DPA. Customer-configured integrations are outside that notification process unless Hey ema begins Processing through a new centrally operated Sub-processor.

4. Affiliates

By Loci Pty Ltd may engage Affiliates as Sub-processors on the same terms as third-party Sub-processors. The current list of relevant Affiliates is: none currently listed.