Overview of PII Handling

dx0 — Overview of PII Handling

This document is a summary for customers and prospects. It is not a substitute for our Privacy Policy, Data Processing Addendum (DPA), Security Page, or Sub-processor list — those remain the authoritative sources and are linked at the end.


General compliance and security posture

HappySoup Ltd is (trading as dx0) an Irish company and operates strictly within the GDPR framework. Our contracts, Terms of Service, DPAs, and related documentation have all been drafted in accordance with European law, with a documented legal basis for each type of processing we carry out — set out in full in our Terms.
HappySoup Ltd is also ISO 27001 certified (Certificate No. 26ISMS-1158), confirming that our information security management practices have been independently validated by external auditors.


What dx0 does

dx0's core functionality is to retrieve configuration metadata from source systems (currently Salesforce, with support for additional systems planned) and use AI to explain that configuration so operators can understand how their system is set up.


Two categories of PII

In the course of providing this service, dx0 may process:

  1. Our customer's own PII — e.g. Salesforce usernames and emails of the people using dx0.
  2. PII belonging to our customer's own end clients — where such data is contained within the source system being analyzed (e.g. Salesforce).

Full detail on the types of data processed and the legal basis for each is set out in our Privacy Policy — we don't duplicate that detail here.


AI processing

  • Our official AI provider is OpenAI. Inference occurs in the United States, as no global AI provider currently offers local (EU) inference.
  • OpenAI is engaged as a formal sub-processor, under a signed Data Processing Addendum between HappySoup/dx0 and OpenAI.
  • OpenAI retains logs for 30 days. There is currently no data residency option for these logs.
  • For EU customers, transfers to OpenAI rely on the Standard Contractual Clauses (SCCs).


How PII reaches the AI — general use

dx0 has an AI interface, which means users can input free text or content of their choosing. We cannot intercept or filter what a user chooses to paste or upload (e.g. an email address, or a screenshot of a spreadsheet). Per our Terms of Service, customers are responsible for using dx0 in line with their own organization's policies on safe AI use — including any internal rules on PII minimization.
Separately, some legitimate product queries will surface PII as part of the answer. For example, asking "which users can modify account records in Salesforce" will return Salesforce usernames, which are PII. This is expected, normal product behavior.


Agentic Data Access — a distinct, opt-in feature

This is a separate, specific feature, not part of default behavior:

  • It allows the AI agent to autonomously query Salesforce data on the customer's behalf (useful for implementations like Field Service, CPQ, etc.).
  • It is disabled by default and only activated with the customer's written confirmation. It never runs silently or behind the scenes.
  • When enabled, PII (emails, phone numbers, Social Security numbers, passwords, etc.) is stripped on our servers before any data reaches OpenAI. We refer to this stripping mechanism internally as the "dx0 Trust Layer".
  • Outside this specific feature, this stripping layer does not apply, because other data accessed by dx0 in normal use is treated as configuration metadata rather than PII requiring this control.


Where processing happens

  • Our own server-side processing takes place in the European region, hosted via Render, which is also a listed sub-processor.


For EU customers — staying GDPR compliant

  • Terms of Service acceptance: our Terms of Service are typically accepted electronically at signup, or at the point of payment via our Stripe payment link — rather than through a separately countersigned document.
  • DPA: our DPA is incorporated by reference into those Terms of Service. If you need a separately signed DPA for your own records or vendor management process, you can request this from us directly — it doesn't change the terms, just the form.
  • Sub-processor records: to stay compliant on your end, we recommend recording HappySoup Ltd (trading as dx0) as a sub-processor in your own internal records, where applicable.
  • Assessments: Legitimate Interest Assessments and other documentation covering specific categories of processing are available on request.


Contracts and documentation available

  • Privacy Policy — details on data types, purposes, and legal basis. https://dx0.io/privacy
  • Data Processing Addendum (DPA) — normally incorporated into our Terms of Service; available as a standalone signed document on request. https://dx0.io/dpa
  • Security Page — our broader security posture (ISO 27001, etc.). https://dx0.io/infosec
  • Sub-processor list — current list, including OpenAI and Render. https://dx0.io/subprocessors
  • Legitimate Interest Assessments (LIAs) — available on request, covering specific categories of processing.


Questions

For anything beyond this summary, please refer to the linked documents above, or contact us directly.

Updated on: 17/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!