Data HQ Sub-processor List: VistaConnect and BlogPilot
Version: 3.0 Effective date: 2026-09-29 Owner: Data HQ Limited Review cycle: On any change, and at least annually
This page lists the sub-processors currently engaged by Data HQ Limited to deliver the VistaConnect platform and the BlogPilot content service. It is referenced by, and forms part of, the Data HQ Privacy Notice, the VistaConnect Non-Disclosure Agreement and the BlogPilot Data Processing Agreement.
The list is published at vista.datahq.co.uk/legal/sub-processors and is also linked from the BlogPilot website (blogpilot.datahq.co.uk).
Change notification
Data HQ will give at least 30 days' notice of any proposed addition or replacement of a sub-processor. Where we broaden what an existing sub-processor is used for, we will tell you before the change takes effect, though not necessarily 30 days before.
Notice is given by email to the email address held for your account, and the updated list is published on this page with its date. You are not asked to accept this list when you sign in.
Where you raise reasonable grounds to object, Data HQ will either withdraw the change or give you the right to stop using the affected feature. Both options remain open to you. Where the processing is intrinsic to how a feature works, it cannot be disabled for an individual account while that feature is in use, so the second option means ceasing to use that feature. For BlogPilot website tracking data, section 9 of the BlogPilot Data Processing Agreement also applies.
Current sub-processors
| Sub-processor | Purpose | Location | Transfer mechanism (if outside UK) |
|---|---|---|---|
| Microsoft Azure | Cloud hosting, PostgreSQL database, Azure Blob storage, Azure Communication Services (transactional email), Azure Log Analytics. For BlogPilot: hosting, BlogPilot website tracking data, and BlogPilot notification emails | UK South (primary); limited operational in EU / US | UK IDTA + Microsoft Data Processing Addendum |
| Microsoft 365 | Business email (including our sales@ and support@ mailboxes, and requests for BlogPilot demonstrations), office documents and Teams | United Kingdom | UK IDTA + Microsoft Data Processing Addendum |
| Stripe Payments Europe, Ltd. | Payment processing, subscription billing, invoice generation, for VistaConnect and BlogPilot | USA / Ireland | UK IDTA + UK Addendum to EU Standard Contractual Clauses |
| Microsoft Ireland Operations Ltd (Azure OpenAI Service) | AI text generation, analysis and search features. BlogPilot: chat assistant, ideas and outlines, drafting and editing of posts, email content and social media variants, writing image descriptions, and reading brand information from your website. VistaConnect: the List Builder assistant; Data Audit field-mapping assistance; Data Audit company-name classification, described below; Company Intelligence narrative features. Data HQ staff: the Lead Qualifier (internal sales research) | The service is hosted in the UK (UK South). Prompts and outputs may be processed in other Azure regions under Microsoft's Global deployment terms. Data held by the service is stored in the UK | UK IDTA |
| OpenAI OpCo, LLC | BlogPilot image generation and image editing | USA | EU Standard Contractual Clauses (Module Two) as amended by the UK Addendum, under OpenAI's Data Processing Addendum |
Microsoft 365. Microsoft 365 (email, documents and Teams) is hosted in Microsoft's United Kingdom data centres.
Azure OpenAI training. Data processed through the Azure OpenAI Service is subject to Microsoft's commitment that customer inputs and outputs are not used to train, retrain or improve the foundation models made available through the service, nor are they shared with other Microsoft customers or OpenAI. See Microsoft's published Azure OpenAI data handling terms for the current position.
Lead Qualifier web search. When Data HQ staff use the Lead Qualifier to research a company, search queries are sent to Microsoft's Grounding with Bing Search service. Microsoft provides it under the Grounding with Bing terms of use and the Microsoft Privacy Statement, not under Microsoft's data protection terms for Azure, and the queries may be processed outside the UK. This applies to staff use only, and only for company research.
OpenAI image generation (BlogPilot)
Blog images are generated and edited through OpenAI directly, not through Azure. When you ask BlogPilot for an image, we send the text description of the image to OpenAI's image service. When you ask for an existing image to be changed, we also send that image. We do not send your account details, your website access details or your website visitors' data.
- Contract. Data HQ has accepted OpenAI's Data Processing Addendum. For a customer based in the UK, OpenAI's contracting party is OpenAI OpCo, LLC (USA), which processes UK data under the EU Standard Contractual Clauses as amended by the UK Addendum.
- No training. OpenAI does not use data sent through its API to train or improve its models unless the customer opts in. Data HQ has not opted in: sharing data with OpenAI to improve its models is switched off for our organisation.
- Retention. OpenAI keeps abuse-monitoring logs of requests for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect its services or any third party from harm. OpenAI does not keep the images or prompts as stored application data for these endpoints. Data HQ uses OpenAI's standard retention; we have not asked for any longer retention.
Company-name classification (Data Audit)
When you upload a file to the Data Audit, we group records that appear to be duplicates of one another. To do that safely we have to tell the difference between a real organisation name and something that is not one: a job title, a salutation, or filler such as "Unknown" or "N/A". Grouping records on a value that is not an organisation name would merge unrelated businesses in your results.
Most of this is decided against our own UK business database and a fixed list of known placeholder values. A small remainder cannot be decided that way, typically well-known trading names that differ from a company's registered name. For those, and only those, we send the name on its own to the Azure OpenAI Service and ask a single question: does this text denote an organisation, a person, a job title, or a placeholder?
What this means in practice:
- We send one name value only. We do not send any other field from your file: no address, email address, telephone number, contact name, or file metadata. In some cases that name may itself be personal data, for example where a sole trader trades under their own name.
- Each distinct name is cached after it is classified, so repeat occurrences are normally answered from our own store rather than sent again.
- We do not send a name we can already resolve from our own business database.
- The answer only ever suggests a grouping for your review. It cannot merge records on its own.
- If the service is unavailable, no grouping is suggested from this step and nothing is merged; the affected names simply remain ungrouped.
- This applies to the Data Audit only. It does not run in List Builder or Find Look-alikes.
This processing has formed part of the Data Audit since 17 August 2026 (version 2.1 of this list).
Microsoft's commitment that inputs are not used to train the foundation models, set out above, applies to this processing.
Not sub-processors
Services we connect to on your instructions. When you connect your own website (for example WordPress or Craft CMS) or a social media account to BlogPilot, we send content to it on your instructions. Those services are your own providers, not our sub-processors.
Public news sources. BlogPilot's news suggestions read public news feeds (for example BBC News and Google News). We send search terms about your industry to those feeds, not personal data.
BlogPilot website analytics. Visits to blogpilot.datahq.co.uk are measured with Data HQ's own BlogPilot tracking script. Data HQ is the controller of that data and no third party processes it.
What we do not do
- We do not sell your personal data.
- We do not share your uploaded audit data with any third party other than the sub-processors above.
- We do not use the Azure OpenAI Service to process files you upload through the Data Audit or Find Look-alikes features, beyond the field-mapping assistance and the company-name classification described above. Your file and its rows are never sent; only individual name values, as set out in that section.
- We do not send BlogPilot website tracking data to any AI provider.
Version history
| Version | Date | Notes |
|---|---|---|
| 2.0 | 2026-04-22 | Published as a standalone document with 30-day change-notice commitment |
| 2.1 | 2026-08-17 | Company-name classification added to the Azure OpenAI purpose, scoped to Data Audit and to individual name values. Change-notification method restated: acceptance on next sign-in, replacing the previous commitment to email and an on-platform banner. Clarified that processing intrinsic to a feature cannot be disabled for an individual account. |
| 3.0 | 2026-09-29 | Retitled "Data HQ Sub-processor List: VistaConnect and BlogPilot" and extended to BlogPilot. OpenAI OpCo, LLC (BlogPilot image generation and editing) and Microsoft 365 (business email) listed; both were already in use and had not been listed. Azure OpenAI purposes restated for BlogPilot, the List Builder assistant and the Lead Qualifier, and Lead Qualifier web search through Microsoft Bing described. Location of Azure OpenAI corrected: hosted in the UK (UK South), with processing that may take place in other Azure regions under Microsoft's Global deployment terms (previously given as West Europe / UK). Change-notification method restated: notice by email and publication of the updated list; the list is not accepted at sign-in. "Not sub-processors" section added. |
