Hitsteps subprocessors

This page identifies providers that may process customer data to deliver optional Hitsteps features. It should be read together with the Hitsteps privacy policy.

Last updated: 11 August 2026

Hitsteps AI

ProviderFeature and purposeDataProcessing locations and transfer safeguardsRetention
OpenAI Ireland Ltd.
Applicable OpenAI affiliates and OpenAI-listed subprocessors
Optional Hitsteps AI dashboard answers, authorized tool use, service security, and abuse prevention User question; bounded recent chat; analytics, account, website, and proposed-action information needed for the answer; pseudonymous safety identifier EEA and other OpenAI processing locations, which may include the United States. OpenAI’s Data Processing Addendum and the European Commission Standard Contractual Clauses apply where required. Hitsteps also applies minimization, authentication, access controls, TLS transport, bounded chat history, and pseudonymous identifiers. OpenAI states that default API abuse-monitoring logs may contain prompts and responses for up to 30 days, with stated legal and safety exceptions. API inputs and outputs are not used for model training by default unless Hitsteps explicitly opts in.

Current provider information: OpenAI API data controls, OpenAI Data Processing Addendum, and OpenAI subprocessor list.

MCP connections are separate

Hitsteps’ MCP server is available without the bundled Hitsteps AI. If a customer connects MCP to their own AI assistant, that AI provider processes data under the customer’s own relationship and instructions; it is not the bundled Hitsteps AI processing described above.