Hey Support is a product of Mungozone Web Solutions LLP, an Indian limited liability partnership (LLPIN AAB-1685) with its registered office at SH 16/46, Ashok Bhawan, Kadipur PO Shivpur, Varanasi, Uttar Pradesh, India 221003 ("Mungozone", "we", "us", "our"). GrandWorks and Hey Support are trade names of Mungozone.
This Privacy Policy explains how we collect, use, share, and protect Personal Data when you visit our marketing websites (hey.support and grandworks.co), use the Hey Support platform (the "Service"), or interact with us by email or in person.
If you have questions, write to [email protected].
Definitions
Personal Data means any information that identifies, or could be used to identify, a natural person.
Customer means the organization or individual that subscribes to the Service.
Customer Content means the data Customers upload to or generate within the Service, including knowledge base materials, conversation logs, lead records, and configuration settings.
Visitor means an end-user who interacts with a Customer's chatbot.
Service means the Hey Support platform, the marketing websites at hey.support and grandworks.co, and related services we provide.
The two roles we play
We process Personal Data in two distinct roles, and your rights differ depending on which role applies.
As a data controller, we make decisions about how and why we process Personal Data. This applies to:
- Customers and prospects (account holders, billing contacts, team members)
- Visitors to our marketing websites
- People who contact us by email or in person
As a data processor, we process Personal Data on behalf of a Customer, following that Customer's instructions. This applies to:
- Visitors interacting with a Customer's chatbot
- End-users whose data the Customer uploads to the Service
When we act as a processor, the Customer is the controller. Visitors who want to exercise privacy rights for data processed by a Customer's chatbot should contact that Customer directly. We will assist Customers in responding.
Personal Data we collect
Information you provide
Account information. Name, email address, password (hashed before storage), workspace name, role.
Billing information. Company name, billing address, tax identifiers. Payment card details are collected and stored by Stripe; we do not see or store them.
Communications. The content of emails, support tickets, demo bookings, and other interactions you have with us.
Information we collect automatically
Usage data. Actions you take in the Service: chatbots created, knowledge sources added, conversations viewed, settings changed.
Device and connection data. IP address, browser type, operating system, referrer URLs, timestamps. Used for security and to operate the Service.
Error diagnostics. When something fails in the web Service, we send the error message, the stack trace, and which route failed to Sentry so we can fix it. Request bodies, query strings, cookies and IP addresses are removed before the report leaves our servers, so conversation content, knowledge base content and lead records are never included. We do not record sessions or capture screens.
Marketing site analytics. Google Analytics 4 on hey.support, plus analytics on grandworks.co. We measure page views, traffic sources, and aggregate engagement. These scripts load only after you opt in to analytics cookies, and advertising and personalization signals stay switched off. We also run Vercel Web Analytics and Speed Insights on the marketing site: they set no cookie and store no cross-session identifier, so they count page views and measure real-world page-load speed in aggregate only, and for that reason they run without asking. None of this runs on the chat widget or inside the app. No advertising trackers.
Information we receive from third parties
Authentication providers if you sign in via single sign-on (Enterprise plans, when available).
Payment processors. Stripe sends us subscription status, plan changes, and billing identifiers (never card data).
Public sources. Company information from publicly available registries when needed for account setup or compliance.
The Hey Support mobile apps
The Hey Support apps for iOS and Android are for Customers' own agents. They sign in with the same account as the web dashboard; there is no sign-up inside the app.
Push notification registration. If you turn notifications on, we store the device push token issued by Apple or Google, the platform (iOS or Android), a device identifier and device name, and the app version. We use these only to deliver handoff alerts to your device and to retire tokens that stop working. The record is deleted when you turn notifications off in the app, sign out, or the platform tells us the token is no longer valid.
Notification content. A handoff alert names the chatbot and the visitor where known, and may include a short excerpt of the visitor's message so you can judge urgency without opening the app. That excerpt passes through Apple's or Google's push infrastructure to reach your device.
Conversation content. The app displays the same conversations, leads, and visitor details as the web dashboard, over the same authenticated API. It is stored on your device only as a temporary in-memory cache, which is discarded when the app closes. Your sign-in session is held in the device's system keychain or keystore.
Crash diagnostics. If the app crashes we send the error message, the stack trace, the app version, and the device model to Sentry so we can fix it. We do not attach screenshots or the view hierarchy, and conversation content is not included.
The apps contain no advertising trackers and no third-party analytics.
Customer Content (processor role)
When acting as a processor, we handle Customer Content as Customers configure it. This may include Personal Data about Visitors: names, email addresses, phone numbers, IP addresses, message content, voice recordings (if voice features are enabled), and any other information Visitors share with the chatbot or Customers enter manually.
How we use Personal Data
We use Personal Data to:
- Provide, operate, and improve the Service
- Process payments and manage subscriptions
- Communicate with Customers about their accounts, billing, and the Service
- Provide customer support
- Send transactional emails (account confirmations, invoices, security alerts, invitation links)
- Send marketing communications, where permitted and with the ability to unsubscribe
- Detect, investigate, and prevent fraudulent or abusive use
- Comply with legal obligations
- Enforce our Terms of Service and other agreements
We do not use Customer Content to train AI models. This is a binding commitment, repeated in Section 12.
Legal bases for processing (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the legal bases we rely on are:
Contract. To provide the Service to Customers, including processing necessary to fulfill our agreement with them.
Legitimate interests. To secure the Service, prevent fraud, communicate with Customers about their accounts, and improve the Service. We balance these interests against your rights.
Consent. For marketing communications where required by law. You can withdraw consent at any time.
Legal obligation. To comply with applicable laws, court orders, and regulatory requirements.
If you are in India, we rely on lawful purposes under the Digital Personal Data Protection Act, 2023. If you are in California, we process Personal Data for the business purposes described in this policy.
International data transfers
The Service is operated from infrastructure in the United States. If you access the Service from outside the United States, your Personal Data is transferred to and processed in the United States and, where applicable to subprocessors, other jurisdictions.
For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs) as supplemented by the UK Addendum where applicable. The SCCs are incorporated into our Data Processing Agreement.
For transfers from India under the Digital Personal Data Protection Act, 2023, we comply with applicable restrictions on transfers to notified countries as they come into force.
If you are an Enterprise Customer who requires data residency in a specific region, contact us.
Data retention
We retain Personal Data only as long as we need it to provide the Service or to meet legal obligations.
Account data. Retained for the life of your subscription. Deleted within ninety days of account closure, except where we are required to retain it longer.
Customer Content. Retained per the Customer's configuration and per our Data Processing Agreement. Deleted on Customer request within fourteen days, including from backups.
Marketing site analytics. Retained for fourteen months, then aggregated.
Billing records. Retained for seven years to comply with tax and accounting law, even after account closure. Card data is held by Stripe per its retention rules.
Backups. Daily backups, seven-day point-in-time recovery. Deletions reach backups by rotation rather than by editing them: once you delete something, every backup still containing it ages out within the recovery window, so it is gone from all backups within fourteen days. If we ever restore from a backup, re-applying any deletions made after that backup was taken is a required step of the restore, and we hold the records needed to do it.
Audit and security logs. Retained for one year (audit) and ninety days (operational), with PII redacted at write time where practical.
Webhook delivery payloads. When a Customer forwards chat events to their own systems, we keep a copy of what was sent so delivery failures can be diagnosed. The payload is scrubbed after thirty days and the delivery record is deleted after ninety.
Data deletion requests. Kept for seven years as proof that a request was made and honoured, which we may be asked to certify. The record holds a one-way hash of the address rather than the address itself; the readable copy is destroyed as soon as the request completes.
Customers can configure custom retention on Enterprise plans.
Your rights
Depending on where you live, you have some or all of the following rights:
- Access. Request a copy of the Personal Data we hold about you
- Correction. Ask us to correct inaccurate or incomplete data
- Deletion. Ask us to delete your Personal Data
- Restriction. Ask us to limit how we process your data
- Portability. Receive your data in a portable format
- Objection. Object to processing based on our legitimate interests
- Withdrawal of consent. Withdraw consent for any processing based on consent
- Lodge a complaint with your supervisory authority
To exercise any of these rights, write to [email protected]. We respond within thirty days, sometimes sooner.
If you are a Visitor whose data was processed via a Customer's chatbot, contact that Customer first. We assist Customers but cannot answer requests about another organization's data on your behalf.
Visitors: delete your chat data
If you have chatted with an assistant powered by Hey Support and do not know which business to contact, you can start a request at hey.support/delete-my-data.
Because we are the processor and the business running the chatbot is the controller, that request is routed rather than executed by us. We email you a single-use link to confirm you control the address; once you confirm, we identify every business whose assistant holds data linked to it, notify them, and give each one a control that permanently deletes your conversations, messages, lead details and bookings. They have one month to respond. When they have all acted, we email you a written record of what was removed and when.
Two limits worth stating plainly. Anonymous conversations, where you never gave an email address, cannot be linked to you and so cannot be found this way. And questions you asked that a business chose to save as part of its chatbot's own training material are that business's content rather than a record about you; those are retained, and the business can remove them directly.
California residents (CCPA / CPRA)
In addition to the rights above, California residents have the right to know what categories of Personal Data we collect, the purposes for collecting it, the sources, and the categories of recipients. We do not sell or share Personal Data for cross-context behavioral advertising. You may exercise these rights through a verifiable consumer request to [email protected].
We do not discriminate against you for exercising your rights.
India residents (DPDP Act)
Under the Digital Personal Data Protection Act, 2023, you have the right to access, correct, and erase your Personal Data, and to nominate another person to exercise these rights in case of incapacity. You may also withdraw consent. Write to [email protected].
Security
We protect Personal Data with administrative, technical, and physical safeguards. Details are available on request at [email protected]. Highlights:
- TLS 1.3 in transit, AES-256 at rest
- Row-level security in the database
- Sqids-encoded IDs in URLs and API responses
- HMAC-signed outbound webhooks with secret rotation
- API keys hashed (SHA-256) before storage
- Cross-team isolation enforced at every endpoint
- SOC 2 Type I (Q3 2026), Type II (Q1 2027)
No system is impenetrable. We will notify affected Customers without undue delay if a breach occurs and we will notify supervisory authorities where required.
AI and your data
This section repeats and emphasizes commitments above because they are central to Hey Support.
We do not train AI models on Customer Content. Not on your knowledge base, not on conversation messages, not on Visitor inputs, not on assistant responses.
Our subprocessors do not train on Customer Content either. OpenAI processes Service traffic under its API agreement, which excludes API traffic from training. Cartesia does the same for voice traffic.
Customer Content stays scoped to the Customer's workspace. It is not shared across Customers. It is not used to improve other Customers' chatbots.
You can delete Customer Content at any time. Single chunks, single sources, single conversations, or the entire workspace. Hard delete propagates to backups within fourteen days.
If we ever change this position, we will notify Customers materially in advance and give them the option to terminate without penalty.
Marketing communications
We send marketing emails only with consent where required by law, and we always include a one-click unsubscribe link. Transactional emails (security alerts, invoices, account notifications) are operational and cannot be unsubscribed without closing the account.
We do not run advertising on the marketing site or in the Service.
Children
The Service is not directed at children under sixteen. We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data to us, write to [email protected] and we will delete it.
Third-party links
The Service may contain links to third-party websites and services. We are not responsible for their privacy practices. Review their policies before sharing data.
Changes to this Policy
We may update this Policy from time to time. Material changes are announced by email to account holders at least thirty days before they take effect. The "Last updated" date at the top reflects the most recent revision. Continuing to use the Service after a change means you accept the updated Policy.
Contact us
For privacy questions, data requests, or anything else covered by this Policy:
Email: [email protected]
Postal address: Mungozone Web Solutions LLP, SH 16/46, Ashok Bhawan, Kadipur PO Shivpur, Varanasi, Uttar Pradesh, India 221003
We do not currently have a designated Data Protection Officer. If you are in the European Economic Area or United Kingdom and would like to engage a DPO contact, write to [email protected] and we will arrange it.
For complaints, you may contact your local supervisory authority. In the European Economic Area and the United Kingdom, contact details are on your national authority's website.