Privacy policy
How we collect, use, and protect personal data when you use Hebno.
Last updated 16 August 2026
1. Who we are and scope
Hebno("Hebno", "we", "us") provides a controlled AI work platform for consultancies. Platform data is hosted in the EU or the US, as the customer organisation selected when the workspace was created. We operate from Denmark. For our registered legal name and address, write to support@hebno.com.
This privacy policy explains how we handle personal data when we act as controller: when you visit the marketing website, contact us, or hold an account with us (identity, billing, and similar account administration).
When your organisation uses Hebno to process personal data about its staff or clients (prompts, files, chat history, membership inside the workspace), we act as a processoron that organisation's instructions. That processing is governed by the data processing agreement, not by the controller sections below, except where we say otherwise.
2. What we collect
Website and contact
- Information you submit in forms (name, email, company, message content).
- Technical data such as IP address, browser type, and pages viewed, as recorded in server logs needed to operate and secure the site.
- Essential cookies described in Section 11.
Your account with us
- Account and profile - name, work email, organisation, role, authentication identifiers.
- Organisation administration - team structure, enabled models, seat assignment, and similar settings your administrators configure.
- Billing - seat counts, plan, invoices, and payment references. Card numbers are handled by Stripe; we do not store full card details.
- Support - tickets, emails, and notes needed to help you.
- Security logs - sign-in events, administrative changes, and security signals.
Workspace content (prompts, uploads, connected files, and model outputs) is processed for your organisation as described in the DPA. We store it so history, review, and attribution work. We do not use it to train a model.
3. How we use personal data
As controller, we use personal data to:
- Create and administer accounts, authenticate users, and provide support.
- Bill per seat, measure included credits, and invoice usage at provider cost after the allowance (see the terms).
- Respond to demos, sales, and support requests.
- Secure the Service, prevent abuse, and meet legal duties.
- Contact business users about the Service in a measured way, where permitted. You can object or unsubscribe.
We do not use your inputs or outputs to train any AI model. Providers process inference under their own terms for the models your organisation has switched on.
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not use automated decision-making that produces legal or similarly significant effects about an individual without human involvement.
4. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies to us as controller:
- Contract - to provide the account, billing, and support you request.
- Legitimate interests - to secure systems, prevent abuse, understand how the marketing site is used at a technical level, and contact relevant business people about Hebno. You may object where that right applies.
- Consent - if we ever use optional analytics or marketing cookies, or send marketing that requires consent. We do not currently set non-essential cookies.
- Legal obligation - bookkeeping, tax, and other duties that require us to keep or disclose records.
5. Retention
We keep controller data only as long as needed for the purposes above:
- Account data - for the subscription and up to 90 days after closure for billing queries and support, unless law requires longer.
- Invoices and bookkeeping - for the period Danish accounting rules require (typically five years).
- Workspace content - until you or your organisation delete it in the product, and after the subscription ends as set out in the DPA (deletion from production within 30 days; backups up to 90 days).
- Sign-in and admin logs - typically up to 12 months.
- Marketing contacts - until you unsubscribe or we no longer have a lawful basis.
6. Sharing and subprocessors
We share data with service providers under contracts that require appropriate safeguards. Model providers receive prompts and responses only for models your organisation enables, over a direct API connection. Optional connectors receive data only when that source is connected, as described in the DPA.
Business customers receive at least 30 days' notice of new subprocessors that materially affect processing, as described in the DPA.
Platform infrastructure
These providers host and operate the Hebno application. They receive Customer Personal Data as needed to run the platform (for example the database, encrypted file storage, authentication, email, and billing). They do not run model inference.
Optional connectors
Customer may connect third-party systems and custom connectors. Those providers are used only when that source is connected. Hebno searches and retrieves material the user or the Service is permitted to use, under the permissions that account already has. Material used in a conversation is stored in the organisation's private storage. Custom connectors that call Customer's own systems remain under Customer's control.
AI model providers (direct connection)
When you enable a model, inference requests are sent directly to that provider's API. Each enabled provider is a separate subprocessor and only receives data for the models you have turned on. Models are off by default.
OpenAI, Anthropic, and xAI process inference in the United States. Google may process in the US, the EU, or other regions it operates. Mistral can process in the EU. DeepSeek processes in China. Enabling a provider is your instruction to send prompts, retrieved or attached content used in that turn, and responses to that provider's locations. You can keep inference in the EU by enabling only EU-resident providers.
7. International transfers
Platform hosting and primary storage follow the EU or US choice recorded when the workspace was created. Ancillary services (edge delivery, email, payments) may process limited data outside that region, as listed above.
When your organisation enables a model provider, inference runs where that provider runs: the United States for OpenAI, Anthropic, and xAI; the US, EU, or other regions Google operates; the EU where you enable only EU-resident providers such as Mistral; China if you enable DeepSeek. That transfer is your organisation's instruction. See the DPA.
For transfers we arrange from the EEA, we use appropriate safeguards, including the European Commission's standard contractual clauses where required. For transfers from the UK, we use the UK International Data Transfer Addendum or another mechanism approved by the UK Information Commissioner.
8. Security
Measures include:
- Platform hosting in the EU or the US, as selected for the workspace.
- No training on customer inputs or outputs by Hebno.
- AES-256 encryption at rest; TLS 1.2 or higher in transit.
- Owner, admin, and member roles. Connected sources keep existing account permissions.
- Sign-in, admin, and usage records. Encryption of customer-supplied API keys at rest.
More detail: hebno.com/security. Report security concerns to support@hebno.com.
9. Your rights
Depending on where you are, you may have rights to access, correct, delete, restrict, or port personal data, to object to certain processing, and to withdraw consent. You may complain to a supervisory authority. Our lead authority in Denmark is Datatilsynet. UK residents may also contact the Information Commissioner's Office.
Write to support@hebno.com. If you use Hebno through your employer, requests about workspace content should go to your organisation as controller first. We will redirect or support that organisation as the DPA requires.
10. Children
The Service is for business use. It is not directed at anyone under 18. We do not knowingly collect their data. Contact us if you believe we have.
11. Cookies and similar technologies
We use essential cookies and similar storage to run the Service: authentication and session (including Supabase auth), security (including OAuth state for connectors), and preferences such as last sign-in method. These are required for the product to work.
We do not currently set analytics or advertising cookies on the marketing site. If we add them, we will describe them here and obtain consent where the law requires it.
You can block cookies in your browser. Blocking essential cookies will stop sign-in and similar functions from working.
12. Additional notices
United States (including California)
We do not sell personal information as those laws define a sale. We do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information to infer characteristics about you. If you are a California resident and believe we hold your personal information as a business, write to support@hebno.com. Most product data is held for your organisation as a service provider or processor.
Sources
We collect data from you, from administrators at your organisation who invite you, and from the providers listed in Section 6 when they return authentication, payment, or inference results.
13. Contact and changes
Privacy questions: support@hebno.com.
We may update this policy on this page and change the "Last updated" date. Material changes that affect contracted customers follow the terms of service or your order.