Skip to main content
Platform Review
PricingSign in
HeyGen assessment

HeyGen procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for HeyGen
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow By using our Services, you understand that your personal information may be processed and stored on servers, and transferred to third parties, outside your country of residence, including the United States. The personal information that you provide to us and that we collect from you will be transferred to, stored at, or processed in, countries outside your country of residence, such as to the United States. Your personal information is also processed by staff operating outside the EEA, UK or Switzerland who work for us or one of our third-party service providers or partners. We process the personal information that you provide to us in countries outside your country of residence in order to provide our Services, perform our contract with you, and provide our website’s functionality. We also use standard contractual clauses (SCCs) as relevant for certain transfers of personal information to third countries, unless the transfer is to a country that has been determined to provide an adequate level of protection for individuals’ rights and freedoms for their personal information. We require that third parties to whom we transfer personal data comply with the Data Privacy Framework principles. We use standard contractual clauses (SCCs) to ensure adequate protection for personal data transferred outside the EU, UK, and Switzerland.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), HeyGen commits to resolve complaints about our collection or use of your personal information transferred to the U.S. pursuant to the EU-U.S. DPF, the UK extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. EU, UK, and Swiss individuals with inquiries or complaints should first contact HeyGen’s Data Protection Officer: [email protected] . HeyGen has further committed to refer unresolved DPF Principles-related complaints to a U.S.-based independent dispute resolution mechanism, BBB NATIONAL PROGRAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by HeyGen, please visit https://bbbprograms.org/programs/all-programs/dpf-consumers for more information and to file a complaint. This service is provided free of charge to you. If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/s/article/ANNEX-I-introduction-dpf Below are the contact details for the relevant authorities depending on your location:Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown If you are located within the EEA or the EU, you can contact the the Irish Data Protection Commission, accessible here .Captured 2026-08-12Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow For purposes of this Privacy Policy, HeyGen's role as controller or processor depends on the specific processing activity. HeyGen acts as a data processor when processing personal data on behalf of, and under the instructions of, our customers in connection with their use of the Services (e.g., processing Customer inputs, generating outputs, and hosting content on behalf of a Customer). HeyGen acts as a data controller when processing personal data for its own independently determined purposes, including account administration, platform security, service improvement, AI model training, analytics, and marketing, as further described in Section 4. Where HeyGen acts as a processor, the applicable Customer is the controller and determines the purposes and means of processing; HeyGen processes such data only in accordance with the Customer's documented instructions and applicable data processing agreement. HeyGen complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. HeyGen has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow If you have any questions about our Services or this Privacy Policy, please email us at [email protected] . Please ensure that your query is clear, particularly if it is a request for information about the data we hold about you. If you think we have infringed applicable data privacy or protection laws, you can complain to your local data protection supervisory authority in which you are based or where you think we have infringed data protection laws. Of course, we hope you will contact us first so we can resolve any issues. If you are a HeyGen enterprise customer who is processing personal data of people other than your own and wish to enter into a DPA, please contact [email protected] .Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow If you are located in Switzerland, you can contact the Federal Data Protection and Information Commissioner:Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslowHeyGen complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. HeyGen has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. HeyGen has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown If you are located in the UK, you can contact the Information Commissioner's Office:Captured 2026-08-12Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslowDPF. HeyGen has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program and to view our certification, please visit https://www.dataprivacyframework.gov .Captured 2026-06-07Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Our Data Protection Officer and representative in the European Economic Area, UK and Switzerland is:Captured 2026-08-12Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Our relevant supervisory authority in the European Economic Area and the European Union is the Irish Data Protection Commission, accessible here . As described in section 1 “Introduction”, HeyGen, Inc. is usually the processor of your personal data. We are the controller only if we process data for our own legitimate purposes. We are a domestic corporation established in the United States. Our address and contact is: Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmediumWe only keep your personal information for as long as we need to provide our products and services as described in this Privacy Policy and/or for as long as we have your permission to keep it. In determining the length of time we retain information, we consider various criteria, including whether we need the information to continue to administer your account, provide the Services, maintain output and content that you have generated, resolve a dispute, enforce our contractual agreements, prevent harm, promote safety, security and integrity, or protect ourselves, including our rights, property and products. We conduct reviews when appropriate to ascertain whether we still need to keep your information. After you delete the information or the account, it is kept in the backups for the purpose of disaster recovery for 30 days and then automatically and permanently erased.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslowIf you submit a request to delete your information, we strive to take steps to delete that information within 72 hours of your request, unless we are required or permitted to retain such information under applicable law.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tierslow We only keep your personal information for as long as we need to provide our products and services as described in this Privacy Policy and/or for as long as we have your permission to keep it. In determining the length of time we retain information, we consider various criteria, including whether we need the information to continue to administer your account, provide the Services, maintain output and content that you have generated, resolve a dispute, enforce our contractual agreements, prevent harm, promote safety, security and integrity, or protect ourselves, including our rights, property and products. We conduct reviews when appropriate to ascertain whether we still need to keep your information. After you delete the information or the account, it is kept in the backups for the purpose of disaster recovery for 60 days and then automatically and permanently erased. If you submit a request to delete your information, we strive to take steps to delete that information within 72 hours of your request, unless we are required or permitted to retain such information under applicable law. For additional information, see “Summary of Your Rights” below.Captured 2026-08-12Open source →Finding permalink →
Data retentionAll applicable tiersmedium We only keep your personal information for as long as we need to provide our products and services as described in this Privacy Policy and/or for as long as we have your permission to keep it. In determining the length of time we retain information, we consider various criteria, including whether we need the information to continue to administer your account, provide the Services, maintain output and content that you have generated, resolve a dispute, enforce our contractual agreements, prevent harm, promote safety, security and integrity, or protect ourselves, including our rights, property and products. We conduct reviews when appropriate to ascertain whether we still need to keep your information. After you delete the information or the account, it is kept in the backups for the purpose of disaster recovery for 30 days and then automatically and permanently erased. If you submit a request to delete your information, we strive to take steps to delete that information within 72 hours of your request, unless we are required or permitted to retain such information under applicable law. For additional information, see “Summary of Your Rights” below.Captured 2026-06-07Open source →Finding permalink →
Data retentionAll applicable tiersmedium If you do not access or use our Services for a continuous period of six (6) months (the “Inactivity Period”), and you are under the Free Plan, HeyGen may, upon reasonable notice, delete your account. For the purposes of this provision, “inactivity” means no measurable usage of the Services of any kind during the Inactivity Period.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We only disclose your personal information as described in this Privacy Policy. Unless otherwise described, we will never sell your personal information to anyone for monetary consideration. You are in control of your personal information at all times. In certain circumstances, we may disclose your personal information to third parties for the purposes described in this Privacy Policy, including: Vendors and Service Providers. We may contract with third parties who help us provide the Services, including for payment processing, cloud storage, chatbot operation, voice transcriptions, image generation, system administration, security, customer relationship management, delivery of goods, search engine facilities, data analytics, advertising, and marketing. In some cases, these third parties may require access to some or all of your information. We will take all reasonable steps to ensure that your information will be handled safely and securely, such as through data protection agreements. In some cases we may be legally liable for such onward transfers to third-parties. You can access list of our subprocessors here . With direction or consent. We may also disclose information to third parties, including other users of the Services, when you request, direct or consent to us doing so, such as when you make output or other content available to others, through your use of login integrations and social media widgets or with your consent. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmediumInformation From Third Parties ### We may obtain information about you from outside sources, including: Integration partners. Information we receive when you connect HeyGen to an integration service. Login integrations. Information we receive when you choose to access the Services through a login integration or a Single Sign On service. Social media platforms. Information we receive from social media platforms, such as when you interact with us on YouTube, TikTok or Instagram. Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium As described above, we are not responsible for the privacy or security of, information found on, or any practices employed by any third-party applications, websites, or services linked to or from our Service. Although we may provide links to third-party websites or platforms, or display content, data, applications or materials from third parties, our Privacy Policy does not apply to those third-party sites or materials, and your browsing and interaction on any third-party site, application, or service, including those that have a link on our Services, are subject to that third party's own terms and policies. The current list of sub-processors can be found here . We reserve the right to engage new sub-processors, provided that they meet a high level of security and data protection. We enter into Data Protection Agreements with all of our sub-processors.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Affiliates. We may disclose information to our affiliates or others within our corporate group. Legal reasons. In certain circumstances, we may be legally required to share certain data held by us, which may include your personal information, for example, where we are involved in legal proceedings or where we are cooperating or complying with the requirements of legislation, a court order, a governmental authority or law enforcement. We may also disclose information to comply with applicable law, to enforce our contractual arrangements and policies, or protect or defend the Services, our rights and the rights of our users or others. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may also compile statistics about the use of our Site, including data on traffic, usage patterns, user numbers, sales, and other information. All such data will be anonymized and will not include any personally identifying information. We may occasionally share such data with third parties, such as prospective investors, affiliates, partners, and advertisers. Data will only be shared and used within the bounds of the law.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may, from time to time, expand or reduce our business, and this may involve the sale and/or the transfer of control of all or part of our business, which could take various forms, such as an asset sale, merger, bankruptcy or other business transaction. Personal information provided by users will, where it is relevant to any part of our business so transferred, be transferred along with that part, and the new owner or newly controlled party will, under the terms of this Privacy Policy, be permitted to use the information for the purposes for which it was originally collected by us. We may also disclose personal information to third parties assisting with such a business transaction, such as legal advisors involved in the due diligence process. If any of your personal information is transferred in this manner, you will be contacted in advance and informed of the changes.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium This section provides additional information to residents of California, Colorado or other U.S. states that have passed a law similar to the California Consumer Privacy Act (“CCPA”). For purposes of this section, “personal information” also includes “sensitive personal information” as those terms are defined under the CCPA. The following table sets out the categories of personal information (sensitive information denoted by *) we collect and disclose (if applicable), including our practices over the past 12 months. Category of Personal Information for which recipient(s) are: Vendors and service providers, with your direction or consent (e.g., to other users), with our affiliates. Identifiers, such as name, contact information, IP address and other device identifiers Personal information under the California Customer Records statute, such as name Internet and similar network activity information, such as information regarding your interactions with the Services, Input and UGC Category of Personal Information for which recipient(s) are: Vendors and service providers, with our affiliates.Captured 2026-06-07Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown By using our Services, you understand that your personal information may be processed and stored on servers, and transferred to third parties, outside your country of residence, including the United States. The personal information that you provide to us and that we collect from you will be transferred to, stored at, or processed in, countries outside your country of residence, such as to the United States. Your personal information is also processed by staff operating outside the EEA, UK or Switzerland who work for us or one of our third-party service providers or partners. We process the personal information that you provide to us in countries outside your country of residence in order to provide our Services, perform our contract with you, and provide our website’s functionality. We also use standard contractual clauses (SCCs) as relevant for certain transfers of personal information to third countries, unless the transfer is to a country that has been determined to provide an adequate level of protection for individuals’ rights and freedoms for their personal information. We require that third parties to whom we transfer personal data comply with the Data Privacy Framework principles. We use standard contractual clauses (SCCs) to ensure adequate protection for personal data transferred outside the EU, UK, and Switzerland.Captured 2026-08-12Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Certain features of the Services allow you to initiate interactions between the Services and third-party services or platforms, such as YouTube, TikTok, Instagram and email integrations (“Social Features”). Social Features include features that allow you to access our pages on third-party platforms, and from there “like” or “share” our content, or to access our Services through a login integration. Use of Social Features may allow a third party to collect and/or use your information. If you use Social Features, information you post or make accessible may be publicly displayed by the third-party service. Both we and the third party may have access to information about you and your use of both the Services and the third-party service. For more information, see the section below.Captured 2026-06-07Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.