1.What this page lists
In short: A provider is a Subprocessor when it processes Organization content on our behalf. Providers that process personal data for their own purposes — such as our billing provider — are listed for transparency with that role stated.
Hectile relies on a small number of providers for application hosting, database and file storage, transactional email and subscription billing. Sign-in and account security are functions of the Hectile application itself, running on the hosting, database and email providers below rather than through a separate identity service. Each provider processes only what its function requires. Hectile cannot operate without these providers, and this list will never be empty.
2.Directory
3.AI model provider
Hectile’s AI features — AI Quick Create and suggested line descriptions, notes and terms — send each request from Hectile through Vercel’s AI Gateway to Anthropic’s model, for model execution only. The Gateway passes requests only to Anthropic. Only what the action needs is sent: for AI Quick Create, the text of the request (up to 2,000 characters), the document type and the names of the Organization’s tax profiles; for a suggested line description, the text of that line; and for a suggested note or terms text, the document type, the brief given and the current note or terms text. Customer, Item and Brand records are not sent; Hectile matches the customer and Items a user names itself. Hectile keeps no copy of a request or of the model’s response: for each AI action it records only the feature used, the AI actions counted, token counts and the outcome. Each provider’s retention and use of request content is governed by its published terms.
4.Processing locations and transfers
Zealsync is established in India, and the providers above operate infrastructure in more than one country, so Organization data may be processed outside India. Transfers to these providers are governed by the data-protection terms that apply between Zealsync and each provider. Hectile does not offer a choice of data-residency region.
5.Changes to this list
When we add or replace a provider that processes Organization content, we update this page and notify Organization Admins by email or in the application at least 30 days before the new provider begins processing; the “Last updated” date at the top shows the latest change. Organizations may object on reasonable data-protection grounds within that period as described in section 6 of the Data Processing Addendum.
6.Contact
Questions about a provider on this list: Contact Legal.