Privacy Policy - HeyOS & HEY Suite Products
(HeyOS, HeyProof, HeyFileDrop, HeyMetrica, HeyBionic, HeyChecker, HeyToolKit, and all HEY-branded platforms)
Last updated: 10th Dec 2025
1. Data Controller
The Data Controller for all HEY-branded platforms is:
Start Me Hub Srl
Via Galasso da Carpi 1
62100 Macerata (MC) - Italy
VAT: IT01935510436
Email: support@heyos.net
This Privacy Policy applies to all services operating within the HEY Suite, including HeyOS, HeyProof, HeyFileDrop, HeyMetrica, HeyBionic, HeyChecker, HeyToolKit, and any future HEY-branded tools.
2. Personal Data We Collect
2.1 Data You Provide
- Name, email address, account credentials
- Billing and invoicing information (company name, VAT, address)
- Content you upload or generate within the platform
- Support requests and direct communications
2.2 Automatically Collected Data
- IP address, device identifiers
- Browser type, operating system, language
- Usage logs, event data, widget interactions
- Cookies and similar tracking technologies
2.3 Third-Party Data (Optional Integrations)
Only when you explicitly connect them, such as:
- Payment services
- Analytics integrations
- Social media or external tools
We process only what is necessary for the requested functionality.
3. Legal Basis for Processing (GDPR)
- Art. 6(1)(b) GDPR - Contract performance
- To create your account, deliver HEY services, provide support.
- Art. 6(1)(c) GDPR - Legal obligation
- For accounting, tax, and regulatory compliance.
- Art. 6(1)(f) GDPR - Legitimate interest
- To ensure security, prevent abuse, improve user experience.
- Art. 6(1)(a) GDPR - Consent
- For marketing, cookies, optional integrations, and non-essential tracking.
4. How We Use Personal Data
We use personal data to:
- Operate and improve HeyOS and HEY Suite services
- Manage subscriptions, payments, and billing
- Enable widgets, analytics, proof pop-ups, and integrations
- Provide customer support
- Send service-related notifications
- Monitor security and enforce compliance
- Optimize platform performance and stability
We do not sell personal data.
5. Data Sharing & Processors
We share data only with GDPR-compliant Data Processors, including:
- Hosting and server providers
- Payment processors (Stripe, Paddle, LemonSqueezy, etc.)
- Email delivery platforms
- Analytics services
- Customer support systems
All processors operate under a Data Processing Agreement (DPA).
Data may also be shared when legally required (court orders, government authorities).
6. International Transfers
If data is transferred outside the EU/EEA, we use:
- EU Commission Standard Contractual Clauses (SCCs)
- Additional safeguards when necessary
We ensure equivalent GDPR-level protection.
7. Data Retention
We retain data only as needed:
- Account data: until you delete your account
- Billing & tax data: 10 years (Italian law)
- Logs & analytics: typically 6-24 months
- Customer support communications: up to 24 months
After retention periods expire, data is securely deleted or anonymized.
8. Your GDPR Rights
You may request:
- Access to your personal data
- Rectification of inaccurate data
- Deletion ("right to be forgotten")
- Restriction of processing
- Objection to legitimate-interest processing
- Data portability
- Withdrawal of consent at any time
To exercise these rights, contact: support@heyos.net
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali).
9. Cookies & Tracking
HEY platforms may use:
- Strictly necessary cookies
- Functional cookies
- Analytics cookies (with consent)
- Third-party cookies (only if integrations are enabled)
Cookie preferences can be managed via your browser or our cookie banner.
A dedicated Cookie Policy is available and supplements this document.
10. Security Measures
To protect your data, we implement:
- SSL/TLS encryption
- Firewall and access-control systems
- Encrypted backups
- Regular security testing and monitoring
- Role-based administrative access
- Infrastructure redundancy
No online service can be 100% secure, but we follow industry best practices.
11. Third-Party Integrations
Depending on the HEY product you use, integrations may include:
- Analytics and tracking tools
- Notification and proof widgets
- External login systems
- Payment services
- Social and sharing tools
Integrations are always optional and require consent or explicit activation.
12. Children's Data
HEY Suite services are not intended for individuals under 16.
We do not knowingly collect data from minors.
13. Changes to This Policy
We may update this Privacy Policy to reflect:
- Legal requirements
- Platform changes
- New services in the HEY Suite
We will notify users of significant changes via email or in-app notices.
The latest version is always available on our website.
14. Contact Information
For any questions regarding this Privacy Policy or your personal data:
Start Me Hub Srl
Via Galasso da Carpi 1
62100 Macerata (MC) - Italy
Email: support@heyos.net