Subprocessors
The categories of third party that process customer data on our behalf. The full named list, with each AI provider's retention posture, is available on request and attached to the DPA at signature.
Last updated: 14 August 2026
Legal status of this page
This page is published for information and is accurate as at the date shown; it is not a warranty and creates no rights on its own. Our binding obligations on subprocessor engagement, flow-down, 30-day notice and objection are set out in the Data Processing Addendum, and that document governs.
01How to get the full list
The complete, named subprocessor list - every entity, its role, its location and its data-retention posture - is provided to customers and prospects on request, under NDA, from privacy@gethesperai.com. It is also attached to the Data Processing Addendum at contract signature. This page discloses the categories publicly.
Every subprocessor is bound by written obligations no less protective than our Data Processing Addendum, including the prohibition on using customer data to train models. We remain fully liable to the customer for the acts and omissions of our subprocessors.
We give at least 30 days' notice before adding or replacing a subprocessor that processes customer data. To receive that notice by email, write to privacy@gethesperai.com. Customers may object on reasonable data-protection grounds under section 6 of our DPA, and may terminate without penalty if we cannot resolve the objection.
02Categories
| Category | Purpose | Location | Customer data processed |
|---|---|---|---|
| Cloud infrastructure | Hosting, compute, storage, database and key management. Our primary provider is Amazon Web Services, Inc. | United States | All customer data |
| AI model providers | Large language model inference for document analysis, extraction and narrative generation | United States | Claim file content submitted for analysis, and the resulting output |
| Document processing | Optical character recognition and document structure extraction | United States | Submitted documents |
| Monitoring and error tracking | Application performance monitoring and diagnostics | United States | Diagnostic data, configured to scrub customer data |
| Support tooling | Customer support ticketing and communication | United States | Support correspondence, and anything a customer includes in a ticket |
| Billing | Invoicing and payment processing | United States | Billing contact and payment data only. No claim file data. |
03AI providers: retention posture
Every AI provider we use is engaged on enterprise terms with model training disabled and zero or minimum data retention. Customer data is never used to train, fine-tune, retrain or evaluate any model made available to anyone other than the customer it came from. This is contractual under MSA § 6.4 and DPA § 6.4, and it is flowed down to each provider by written agreement.
Where a provider offers a training, improvement-retention or human-review-for-improvement feature, we affirmatively disable it. The named providers and their specific retention terms are in the full list available on request.
Prompts and outputs containing customer data are treated as customer data for every purpose - encryption, access control, logging and deletion.
04Not subprocessors
The following are not Hesper subprocessors, because we access them as the customer's agent, using the customer's own credentials, under the customer's own licence:
- ISO ClaimSearch / Verisk
- National Insurance Crime Bureau (NICB)
- State motor vehicle records providers
- NMVTIS
- Any other industry database for which the customer holds the licence
We do not resell, sublicense or provide access to any of these sources. Customers are responsible for maintaining their own licence, credentials and permissible-purpose determination for each (MSA § 4.5).
Governed by section 6 of our Data Processing Addendum. For the full named list under NDA, or to subscribe to change notifications, write to privacy@gethesperai.com.