LEGAL
Service Providers and Data Flows
1. Reading this page
Provider functions depend on the enabled service and data flow. A provider processing Customer Data on HY’s instructions may be a subprocessor; a provider used for HY’s own account, billing or security activities may have a different role. Contractual roles, processing locations and applicable transfer safeguards must be established for the relevant flow. For enquiries about the processing locations, safeguards or retention applicable to a particular service, contact privacy@hyaiplatform.com.
2. Railway
Application hosting. Application requests, service data and technical/error logs may pass through the hosting infrastructure, including Customer Data needed for the service.
3. Supabase
Database and file storage. Customer and business records, messages, order/invoice data and uploaded files may be stored where the configured backend uses Supabase.
4. Vercel
Website hosting and production website analytics. Website request/device information, usage measurements and demo-form submissions may pass through the website infrastructure. This is distinct from the application’s Customer Data storage.
5. OpenAI
AI response generation. Message content and the necessary business context, product, price, stock and order information may be sent to generate responses and recommendations. This page makes no claim about a particular model-training or retention setting.
6. Meta
WhatsApp, Instagram and Messenger connectivity. Messages, platform identifiers, timestamps and attachments are exchanged for connected messaging features. Meta’s role depends on the particular platform service and its own terms.
7. Cloudflare
DNS and email routing. Technical request information and emails routed to HY contact addresses may be processed where those services are configured. This is distinct from outbound email delivery.
8. Email delivery providers
Email delivery. Email delivery providers can deliver messages through SMTP or an email API according to the configured service. Email data may include sender/recipient addresses, names, subjects, message bodies and attachments. Invoice/accountant sends can include full PDF invoices, Excel financial summaries or ZIP packages, including identity/contact/address/tax information and invoice, payment and balance details. System messages may include account notifications and sign-in codes. The actual scope depends on the configured message and provider path.
9. Customer-selected integrations
Amazon, Trendyol, Hepsiburada and n11 may exchange order/buyer information and product, stock and price information with HY under the Customer’s connected accounts. These are third-party integrations and are not automatically HY subprocessors. Customer-connected payment providers likewise require a flow-specific role assessment. Mysoft e-document and finance flows must be assessed separately from payment-link services.
10. Services not currently enabled
Customer-connected Stripe/iyzico payment-link collection is not currently live; GoCardless is planned. Google Maps delivery-address validation is not currently enabled. Roles, notices and transfer arrangements must be established before enabling a new flow.
11. Contact
For provider or data-flow enquiries, contact privacy@hyaiplatform.com. Read this page with the Privacy Notice and the applicable Customer DPA.