Data Processing Agreement

Version 2026-08-13. Effective 2026-08-13.

This Data Processing Agreement forms part of the agreement between HeyClients LLC, Grayling, Michigan, USA, and the customer using Heyla. It takes effect when the customer accepts it electronically or otherwise agrees to it. A person accepting it for an organisation confirms that they have authority to bind that organisation.

If mandatory transfer terms, this Data Processing Agreement, and the agreement governing use of Heyla conflict concerning the processing of Customer Personal Data, they apply in that order.

Roles and scope

The customer determines why and how Customer Personal Data is processed through Heyla and acts as controller where applicable. HeyClients LLC acts as processor when it processes that data on the customer's behalf. If the customer processes personal data for another controller, HeyClients LLC acts as the customer's subprocessor for that data.

Processing that HeyClients LLC undertakes for its own purposes, including account administration, billing, fraud prevention, security, and legal compliance, is outside the processor scope of this agreement and is governed by the Privacy Policy and applicable legal terms.

The processing covered by this agreement is described in the processing annex and continues for the period in which Heyla provides the service, subject to applicable retention and deletion requirements.

Documented instructions and restrictions

HeyClients LLC will process Customer Personal Data only to provide, secure, support, and maintain Heyla; to comply with the customer's lawful documented instructions; as described in the processing annex; or as otherwise required by applicable law. The customer's configuration and use of Heyla form part of its instructions.

HeyClients LLC will not sell Customer Personal Data, use it for targeted or cross-context advertising, or attempt to reidentify deidentified information. If law requires processing outside the customer's instructions, HeyClients LLC will notify the customer before processing unless law prohibits that notice.

The customer is responsible for ensuring that its instructions, collection of personal data, and use of Heyla comply with applicable law. If HeyClients LLC reasonably believes an instruction violates applicable data-protection law, it may suspend the affected processing while the parties address the issue.

Confidentiality

People authorised to process Customer Personal Data for Heyla are subject to appropriate confidentiality obligations, receive access only where necessary, and may process the data only as permitted by this agreement.

Security

HeyClients LLC will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The current measures are described in the security annex and may be updated as risks and technology change without materially reducing the overall protection of Customer Personal Data.

Data-subject and compliance assistance

Taking into account the nature of the processing and the information available to it, HeyClients LLC will provide reasonable assistance to help the customer respond to requests to access, correct, delete, restrict, object to, or export Customer Personal Data and meet applicable obligations concerning security, personal-data breaches, impact assessments, and consultations with supervisory authorities.

If HeyClients LLC receives a request relating to Customer Personal Data, it may notify the customer and direct the requester to the customer unless applicable law requires a different response.

Personal-data incidents

HeyClients LLC will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. Where reasonably available, information will include the affected data, approximate number of affected people or records, likely consequences, containment or remediation steps, and a contact for follow-up. Information may be provided in stages while the investigation continues.

Subprocessors

The customer gives HeyClients LLC general written authorisation to use the subprocessors listed in the Sub-processor Register. HeyClients LLC will require subprocessors to protect Customer Personal Data consistently with this agreement and remains responsible for their data-protection obligations to the extent required by applicable law.

Heyla will provide the account owner with at least 30 days' notice before a new subprocessor begins processing Customer Personal Data, except where an urgent change is required to protect Heyla or Customer Personal Data. The customer may object within 15 days on reasonable data-protection grounds. The parties will work in good faith to resolve the objection.

If Heyla cannot provide a suitable alternative after a reasonable objection, the customer may terminate the affected Heyla service before the new subprocessor begins processing its Customer Personal Data. Heyla will refund the unused prepaid portion of the affected subscription term. This is a specific data-processing remedy and not a general voluntary refund policy.

Access, export, deletion, and return

Customers may request access to, an export of, or deletion of their information through contact@heyclients.io. HeyClients LLC will provide reasonable assistance with lawful requests relating to Customer Personal Data.

At the end of the service, HeyClients LLC will delete or return Customer Personal Data as required by the customer's lawful instructions and applicable law. Customer Personal Data in backups remains protected and is deleted through the normal backup-expiration process. If a backup is restored, an applicable deletion request will be reapplied.

Limited billing, security, fraud-prevention, suppression, dispute, and compliance records may be retained where reasonably necessary or legally required, provided that processing is limited to those purposes.

International transfers

Where required, the parties incorporate the European Commission Standard Contractual Clauses adopted under Decision 2021/914. Module Two applies when the customer is a controller and HeyClients LLC is a processor. Module Three applies when the customer is a processor and HeyClients LLC is a subprocessor.

For transfers governed by UK data-protection law, the current UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses applies. If a transfer mechanism becomes invalid or unavailable, the parties will cooperate in good faith to implement a lawful replacement.

Information and audits

HeyClients LLC will make available information reasonably necessary to demonstrate compliance with this agreement. The customer will first use current security, compliance, and other documentation Heyla makes available.

If that information is reasonably insufficient, the customer may conduct one audit in a 12-month period, unless a personal-data breach or regulator request reasonably requires another audit. An audit must be limited to relevant systems and records, use reasonable advance notice, occur during normal business hours, protect other customers and confidential information, avoid unreasonable disruption, and be performed by the customer or a non-competitor independent auditor subject to confidentiality.

Sensitive and regulated data

Free-form conversations may contain health, wellness, financial, relationship, or other sensitive information. Customers are responsible for having an appropriate legal basis and condition for processing it and for limiting collection to what is necessary.

Heyla is not offered as a HIPAA-compliant service unless HeyClients LLC expressly agrees otherwise in writing. Customers must not intentionally use Heyla to process government identification documents, payment-card authentication data, genetic data, biometric identifiers used for unique identification, precise geolocation, criminal-offence data, or children's data unless HeyClients LLC expressly agrees in writing and required safeguards are in place.

Liability

Each party's liability arising from this agreement is subject to the exclusions and limitations in the Terms of Service, except where applicable data-protection law prevents that limitation. Nothing limits a data subject's rights or either party's direct obligations under applicable data-protection law.

Version and acceptance

The published version and effective date identify the Data Processing Agreement that applies. Acceptance is recorded against that exact effective version. A materially updated version may require a new acceptance.

See the Terms of Service, Privacy Policy, Sub-processor Register, and data deletion instructions. Questions or requests concerning this agreement may be sent to contact@heyclients.io.

Annex 1: Processing details

Parties

Data importer and processor: HeyClients LLC, Grayling, Michigan, USA. Contact: contact@heyclients.io.

Data exporter and controller or processor: the customer and any permitted affiliates identified through the agreement, order, or Heyla account. The account owner is the customer's data-protection contact unless another contact is designated.

Subject matter and duration

Processing supports connected-provider ingestion, opportunity assessment, conversation management, suggested-message drafting, human-approved sending, follow-up management, appointment and purchase signals, and customer-directed access, export, or deletion of Customer Personal Data.

Processing is continuous or event-driven while Heyla provides the service and continues only for applicable retention periods after the service ends, subject to lawful deletion requests and records retained for legal, security, suppression, dispute, or compliance purposes.

Data subjects

Data subjects may include customers and their authorised users, leads, contacts, social-media users, email correspondents, commenters, purchasers, appointment attendees, and people represented in customer-provided content.

Categories of personal data

Customer Personal Data may include:

Processing operations and purposes

Operations may include collection, receipt, recording, organisation, retrieval, consultation, analysis, inference, generation, display, human-approved transmission, storage, restriction, export, deletion, destruction, and security measures necessary to protect Customer Personal Data.

Heyla processes Customer Personal Data on the customer's behalf to ingest and organise customer-controlled data; show conversations; identify and explain potential sales opportunities; match contacts to offers; prepare suggested messages; support follow-ups and appointments; carry out customer-approved actions; protect Customer Personal Data; and respond to instructions for access, export, or deletion.

During the human-approval version of Heyla, customer-facing messages are not sent without the customer's approval. Heyla does not independently initiate cold Instagram direct messages.

Frequency

Processing may occur continuously or when a connected provider, customer action, scheduled workflow, or inbound event supplies new information or triggers an authorised action.

Annex 2: Technical and organisational measures

Heyla maintains technical and organisational measures designed to protect personal data, including:

These measures are reviewed and updated as the service, risks, and available safeguards change.

Annex 3: Rights and compliance assistance

Taking into account the nature of the processing and the information available to it, HeyClients LLC will use appropriate measures to assist the customer with:

Assistance remains subject to applicable law and to reasonable measures necessary to protect other customers, confidential information, and the security of Heyla.