VistaConnect
    VistaConnectPrinted from https://vista.datahq.co.uk/legal/sub-processors on 2026-09-03

    VistaConnect Sub-processor List

    Version: 2.1 Effective date: 2026-08-17 Owner: Data HQ Limited Review cycle: On any change, and at least annually

    This page lists the sub-processors currently engaged by Data HQ Limited to deliver the VistaConnect platform. It is referenced by, and forms part of, the VistaConnect Privacy Notice and Non-Disclosure Agreement.

    Change notification

    Data HQ will give at least 30 days' notice of any proposed addition or replacement of a sub-processor. Where we broaden what an existing sub-processor is used for, we will tell you before the change takes effect, though not necessarily 30 days before.

    From version 2.1 onward, notice is delivered by requiring your acceptance of the updated document the next time you sign in to the VistaConnect platform, recorded with its date. This replaces the email-and-banner method described in version 2.0.

    Where you raise reasonable grounds to object, Data HQ will either withdraw the change or give you the right to stop using the affected feature. Both options remain open to you. Where the processing is intrinsic to how a feature works, it cannot be disabled for an individual account while that feature is in use, so the second option means ceasing to use that feature.

    Current sub-processors

    Sub-processorPurposeLocationTransfer mechanism (if outside UK)
    Microsoft AzureCloud hosting, PostgreSQL database, Azure Blob storage, Azure Communication Services (transactional email), Azure Log AnalyticsUK South (primary); limited operational in EU / USUK IDTA + Microsoft Data Processing Addendum
    Stripe Payments Europe, Ltd.Payment processing, subscription billing, invoice generationUSA / IrelandUK IDTA + UK Addendum to EU Standard Contractual Clauses
    Azure OpenAI ServiceAI-assisted features (Blog Bot article and LinkedIn generation; Data Audit field-mapping assistance; Data Audit company-name classification, described below; Company Intelligence narrative features)West Europe / UKUK IDTA

    Azure OpenAI training. Data processed through the Azure OpenAI Service is subject to Microsoft's commitment that customer inputs and outputs are not used to train, retrain or improve the foundation models made available through the service, nor are they shared with other Microsoft customers or OpenAI. See Microsoft's published Azure OpenAI data handling terms for the current position.

    Company-name classification (Data Audit)

    When you upload a file to the Data Audit, we group records that appear to be duplicates of one another. To do that safely we have to tell the difference between a real organisation name and something that is not one — a job title, a salutation, or filler such as "Unknown" or "N/A". Grouping records on a value that is not an organisation name would merge unrelated businesses in your results.

    Most of this is decided against our own UK business database and a fixed list of known placeholder values. A small remainder cannot be decided that way, typically well-known trading names that differ from a company's registered name. For those, and only those, we send the name on its own to the Azure OpenAI Service and ask a single question: does this text denote an organisation, a person, a job title, or a placeholder?

    What this means in practice:

    • We send one name value only. We do not send any other field from your file — no address, email address, telephone number, contact name, or file metadata. In some cases that name may itself be personal data, for example where a sole trader trades under their own name.
    • Each distinct name is cached after it is classified, so repeat occurrences are normally answered from our own store rather than sent again.
    • We do not send a name we can already resolve from our own business database.
    • The answer only ever suggests a grouping for your review. It cannot merge records on its own.
    • If the service is unavailable, no grouping is suggested from this step and nothing is merged; the affected names simply remain ungrouped.
    • This applies to the Data Audit only. It does not run in List Builder or Find Look-alikes.

    This processing forms part of the Data Audit from the effective date shown above.

    Microsoft's commitment that inputs are not used to train the foundation models, set out above, applies to this processing.

    What we do not do

    • We do not sell your personal data.
    • We do not share your uploaded audit data with any third party other than the sub-processors above.
    • We do not use the Azure OpenAI Service to process files you upload through the Data Audit or Find Look-alikes features, beyond the field-mapping assistance and the company-name classification described below. Your file and its rows are never sent; only individual name values, as set out in that section.

    Version history

    VersionDateNotes
    2.02026-04-22Published as a standalone document with 30-day change-notice commitment
    2.12026-08-17Company-name classification added to the Azure OpenAI purpose, scoped to Data Audit and to individual name values. Change-notification method restated: acceptance on next sign-in, replacing the previous commitment to email and an on-platform banner. Clarified that processing intrinsic to a feature cannot be disabled for an individual account.

    Questions about this document? Email legal@datahq.co.uk.