← Back to portal
Esta página de manejo de datos se mantiene en inglés como versión
vinculante. Para una copia en español o cualquier consulta, escribe a
advisory@hamkee.net.
Data handling & subprocessors
Last updated: May 2026. This page is a plain-language summary of how Hamkee Advisory handles customer data, and which third parties touch that data in the course of providing the service. It is not a contract; the binding terms are in the DPA referenced below.
What data we process
- Documents you upload (PDF, DOCX, Markdown, HTML, plaintext) — extracted to text and embedded into a per-customer corpus.
- Conversation messages — both your inputs and the team's outputs are stored under your account.
- Account profile — name, email, industry pack preference, tone preference.
- Operational metadata — booking times, session windows, token-usage totals.
What we do NOT collect
- Payment card numbers — billing flows through a PCI-compliant payment processor (not yet wired in v1; will be Stripe).
- Tracking cookies for advertising. We use a session cookie + a CSRF cookie only.
- Biometric data, location data, or any data category not strictly necessary to deliver advisory output.
Subprocessors
Hamkee Advisory uses the following third-party services to deliver the advisory product. When you upload documents or send messages, text fragments may be transmitted to one or more of these processors as part of an LLM call. The table notes which processors see content, which see only metadata, and what data-handling commitments we hold from each.
| Subprocessor | Purpose | Data exposed | Retention | BAA / DPA |
| Anthropic (Claude API) |
Synthesis + specialist reasoning |
Prompt text (document excerpts + conversation history + the user's current message) |
Zero retention (enterprise tier, default) |
DPA in place. BAA available for HIPAA-handling customers on request. |
| OpenAI (API) |
Specialist reasoning (selected agents); embeddings |
Prompt text + document text for embeddings |
Zero retention for the API; 30 days for embeddings logs |
DPA in place. BAA available via OpenAI's Enterprise tier or Azure OpenAI for HIPAA customers. |
| Google (Gemini API via Vertex AI) |
Specialist reasoning (selected agents) |
Prompt text |
Zero retention (Vertex AI default) |
DPA in place. BAA available via GCP's HIPAA-compliant services for HIPAA customers. |
| AWS |
Compute + storage hosting (the application + your uploaded files at rest) |
All customer content, encrypted at rest with AWS-managed KMS |
Per your account retention policy (configurable; default 24 months for uploads, indefinite for conversation history) |
AWS BAA in place under our Standard Contractual Clauses. |
| Postgres + pgvector (self-hosted on AWS) |
Application database + vector store |
Conversation rows, document chunks, embeddings |
Per customer retention policy; deleted on account closure |
Not a third party — operated by Hamkee under our own controls. |
No customer data is used to train any third-party AI model. The LLM providers above offer "zero retention" / "no training" terms that we contractually invoke on every request.
For compliance-sensitive customers
If you handle PHI, financial data subject to GLBA, or any information your own contracts prohibit transmitting to third parties, contact
advisory@hamkee.net. We offer:
- BAA execution for HIPAA-handling customers.
- Tenant routing through Azure OpenAI / AWS Bedrock so prompt text stays inside your own cloud tenant (additional cost).
- Per-conversation processing modes that limit which subprocessors see content.
- Custom retention policies, including immediate-purge on conversation close.
How to act on this
- Read the per-upload notice. Before each upload the portal shows which subprocessors will see the file.
- Request a BAA. Email advisory@hamkee.net with your covered-entity status.
- Audit your token usage. The cost pill in the chat header is also a usage check: it shows the input + output tokens per conversation.
- Delete an account. Settings → Profile → "Delete my account" triggers cascade deletion of conversations, uploads, and chunks within 30 days; backups expire in 90.
Questions about this page or our data-handling commitments: advisory@hamkee.net. We respond within 2 business days.