Privacy policy
Last updated: April 13, 2026
1. Who is responsible for the processing of your data?
The entity responsible for processing your personal data is GEMSSY TECHNOLOGIES SOCIEDAD LIMITADA (hereinafter, "Heepsy," "we," "us," or "our"), with NIF B-95808937, and registered office at Kukulu Bidea 45, 48180 Loiu, Vizcaya, Spain.
We are the owner and operator of the website www.heepsy.com (the "Website") and the Heepsy Influencer Search application available through ChatGPT (the "App").
Access and/or use of the Website or App attributes the condition of User (the "User" or "you"), and implies acceptance of this Privacy Policy.
You may contact us at the following email address: [email protected].
We are the owner and operator of the website www.heepsy.com (the "Website") and the Heepsy Influencer Search application available through ChatGPT (the "App").
Access and/or use of the Website or App attributes the condition of User (the "User" or "you"), and implies acceptance of this Privacy Policy.
You may contact us at the following email address: [email protected].
2. Legal basis for data processing
We are entitled to process your data to carry out the provision of our services. The legal bases for processing include:
We take the protection of your privacy and personal data very seriously. Your personal information is kept secure and treated with the utmost care.
(1) Legitimate interest in providing the search functionality you request.
(2) Consent, where applicable, for the use of our services.
(3) Compliance with legal obligations.
(2) Consent, where applicable, for the use of our services.
(3) Compliance with legal obligations.
We take the protection of your privacy and personal data very seriously. Your personal information is kept secure and treated with the utmost care.
3. Data collected, purposes, and categories
3.1. Data collected through the Website (www.heepsy.com)
When you use our Website, we may collect:
3.2. Data collected through the ChatGPT App (Heepsy Influencer Search)
When you use the Heepsy Influencer Search App within ChatGPT, we collect and process the following data:
Tool inputs (data you provide through search queries):
Tool outputs (data returned in search results):
For each influencer returned, the App provides the following publicly available information sourced from Heepsy's database:
Operational data collected by the App:
Data NOT collected by the App:
3.3. Purposes of data processing
Your data is processed for the following purposes:
When you use our Website, we may collect:
(1) Account registration data: email address, name, and password for account creation and authentication.
(2) Payment information: processed through third-party payment processors; we do not store payment card details.
(3) Usage data: pages visited, features used, and interaction patterns to improve our services.
(4) Communication data: messages sent through our support channels.
(2) Payment information: processed through third-party payment processors; we do not store payment card details.
(3) Usage data: pages visited, features used, and interaction patterns to improve our services.
(4) Communication data: messages sent through our support channels.
3.2. Data collected through the ChatGPT App (Heepsy Influencer Search)
When you use the Heepsy Influencer Search App within ChatGPT, we collect and process the following data:
Tool inputs (data you provide through search queries):
- Platform selection (Instagram, YouTube, or TikTok)
- Category or niche keywords (e.g., "fitness," "tech," "fashion")
- Geographic location for filtering influencers (e.g., "Los Angeles," "Spain")
- Follower count range (minimum and/or maximum)
- Engagement rate range (minimum and/or maximum)
- Business account filter (true/false)
- Sort preference (relevance, followers, or engagement)
- Result limit (number of results to return)
- Category or niche keywords (e.g., "fitness," "tech," "fashion")
- Geographic location for filtering influencers (e.g., "Los Angeles," "Spain")
- Follower count range (minimum and/or maximum)
- Engagement rate range (minimum and/or maximum)
- Business account filter (true/false)
- Sort preference (relevance, followers, or engagement)
- Result limit (number of results to return)
Tool outputs (data returned in search results):
For each influencer returned, the App provides the following publicly available information sourced from Heepsy's database:
- Username (public social media handle)
- Full name (as displayed on the influencer's public profile)
- Bio (public profile biography)
- Follower count (public metric)
- Engagement rate (calculated from public engagement data)
- Categories/keywords (content classification based on public posts)
- Location (as displayed on the influencer's public profile)
- Business account status (whether the account is registered as a business)
- External profile URL (link to the influencer's public social media profile)
- Full name (as displayed on the influencer's public profile)
- Bio (public profile biography)
- Follower count (public metric)
- Engagement rate (calculated from public engagement data)
- Categories/keywords (content classification based on public posts)
- Location (as displayed on the influencer's public profile)
- Business account status (whether the account is registered as a business)
- External profile URL (link to the influencer's public social media profile)
Operational data collected by the App:
- IP address: used solely for rate limiting (60 requests per minute) to ensure fair use and prevent abuse. IP addresses are stored in volatile memory only and are automatically purged every 60 seconds. They are never written to persistent storage, logs, or shared with third parties.
Data NOT collected by the App:
- We do not collect, store, or process chat history or conversation content.
- We do not collect precise user geolocation (GPS coordinates or addresses).
- We do not collect personal identifiers such as social security numbers, government IDs, or payment information.
- We do not collect authentication secrets, API keys, or passwords through the App.
- We do not return internal identifiers, session IDs, trace IDs, timestamps, or debug/telemetry data in tool responses.
- We do not collect precise user geolocation (GPS coordinates or addresses).
- We do not collect personal identifiers such as social security numbers, government IDs, or payment information.
- We do not collect authentication secrets, API keys, or passwords through the App.
- We do not return internal identifiers, session IDs, trace IDs, timestamps, or debug/telemetry data in tool responses.
3.3. Purposes of data processing
Your data is processed for the following purposes:
(1) Service delivery: to execute influencer searches as requested by the User through the App or Website.
(2) Rate limiting and abuse prevention: to ensure fair usage and protect the service from abuse using IP-based request throttling.
(3) Service improvement: aggregated, anonymized usage statistics to improve search quality.
(4) Commercial communications (Website only): with your consent, to send information about Heepsy's services by email or equivalent electronic means.
(2) Rate limiting and abuse prevention: to ensure fair usage and protect the service from abuse using IP-based request throttling.
(3) Service improvement: aggregated, anonymized usage statistics to improve search quality.
(4) Commercial communications (Website only): with your consent, to send information about Heepsy's services by email or equivalent electronic means.
4. Categories of recipients
Your data may be shared with the following categories of recipients:
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
(1) OpenAI: when you use the Heepsy Influencer Search App through ChatGPT, your search queries and results are processed through OpenAI's platform in accordance with OpenAI's own privacy policy and terms of service.
(2) Infrastructure providers: we use Google Cloud Run for hosting. These providers process data on our behalf under data processing agreements.
(3) Elasticsearch service providers: search queries are processed through our Elasticsearch infrastructure to retrieve influencer data.
(2) Infrastructure providers: we use Google Cloud Run for hosting. These providers process data on our behalf under data processing agreements.
(3) Elasticsearch service providers: search queries are processed through our Elasticsearch infrastructure to retrieve influencer data.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
5. Data retention
- Tool inputs and outputs (ChatGPT App): search queries are processed in real time and are not stored persistently by Heepsy. No search history is maintained on our servers.
- Rate limiting data: IP addresses used for rate limiting are stored in volatile memory for a maximum of 60 seconds and then automatically deleted.
- Website account data: personal data provided through the Website is kept as long as you maintain an active account or until you request deletion.
- Communication data: support communications are retained for as long as necessary to resolve your inquiry, and in compliance with legal retention obligations.
- Rate limiting data: IP addresses used for rate limiting are stored in volatile memory for a maximum of 60 seconds and then automatically deleted.
- Website account data: personal data provided through the Website is kept as long as you maintain an active account or until you request deletion.
- Communication data: support communications are retained for as long as necessary to resolve your inquiry, and in compliance with legal retention obligations.
6. Veracity of the data provided and data of minors
The User guarantees that the personal data provided is true and is responsible for communicating to us any modification thereof. We reserve the right to exclude from our services any User who has provided false data.
The User guarantees that he or she is at least 16 years old. Our App is not designed for or marketed to children under 13.
The User guarantees that he or she is at least 16 years old. Our App is not designed for or marketed to children under 13.
7. Rights of the User in relation to their data
Under applicable data protection regulations (including the GDPR), you have the right to:
You can exercise all these rights by contacting us at: [email protected]. Please indicate the reason for your request and provide a copy of your identification document.
You can also send your request by ordinary mail to:
GEMSSY TECHNOLOGIES SOCIEDAD LIMITADA
Kukulu Bidea 45, 48180 Loiu, Vizcaya, Spain
Without prejudice to any other administrative appeal or legal action, you have the right to submit a claim to a Supervisory Authority, in particular in the Member State where you have your usual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data is not in accordance with applicable regulations.
(1) Access your personal data.
(2) Request the correction of inaccurate data.
(3) Request its deletion (right to be forgotten).
(4) Request a limitation of the processing of your data.
(5) Oppose the processing of your data.
(6) Request data portability.
(7) Not be subject to automated individual decisions.
(2) Request the correction of inaccurate data.
(3) Request its deletion (right to be forgotten).
(4) Request a limitation of the processing of your data.
(5) Oppose the processing of your data.
(6) Request data portability.
(7) Not be subject to automated individual decisions.
You can exercise all these rights by contacting us at: [email protected]. Please indicate the reason for your request and provide a copy of your identification document.
You can also send your request by ordinary mail to:
GEMSSY TECHNOLOGIES SOCIEDAD LIMITADA
Kukulu Bidea 45, 48180 Loiu, Vizcaya, Spain
Without prejudice to any other administrative appeal or legal action, you have the right to submit a claim to a Supervisory Authority, in particular in the Member State where you have your usual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data is not in accordance with applicable regulations.
8. Data security
The protection of the privacy and personal data of our Users is very important to us. We maintain security levels of personal data protection in accordance with applicable regulations and have established all technical means at our disposal to prevent the loss, misuse, alteration, unauthorized access, and theft of data.
Our App implements the following security measures:
In those services that require registration, the User is responsible for maintaining the confidentiality of their password and for all activities that occur in the session initiated with their credentials.
Our App implements the following security measures:
- Content Security Policy (CSP) headers to prevent cross-site scripting and injection attacks.
- Rate limiting to prevent abuse.
- TLS encryption for all data in transit.
- Non-root container execution in our hosting environment.
- Input validation and sanitization on all search parameters.
- Rate limiting to prevent abuse.
- TLS encryption for all data in transit.
- Non-root container execution in our hosting environment.
- Input validation and sanitization on all search parameters.
In those services that require registration, the User is responsible for maintaining the confidentiality of their password and for all activities that occur in the session initiated with their credentials.
9. International data transfers
Your data may be processed in servers located outside your country of residence, including in the United States (through Google Cloud and OpenAI infrastructure). Such transfers are conducted in compliance with applicable data protection regulations, including the use of Standard Contractual Clauses or other appropriate safeguards where required.
10. Changes to this Privacy Policy
We reserve the right to review this Privacy Policy at any time. Any material changes will be communicated to Users through our Website or App. We encourage you to check this Privacy Policy regularly to read the most recent version.
11. Links to third-party websites
Our Website and App may contain links to third-party websites and services (including social media platforms such as Instagram, YouTube, and TikTok). We are not responsible for the privacy practices of these third-party services, and we advise you to read their privacy policies.
12. Contact
If you have any questions about this Privacy Policy or the processing of your data, please contact us at: [email protected].
13. Acceptance and Consent
The User declares to have been informed of the conditions on the protection of personal data, accepting and consenting to the treatment thereof by Heepsy, in the manner and for the purposes indicated in this Privacy Policy.