Every third party that can touch customer personal data while we provide the service. We add nothing to this list without 30 days' prior notice (announced on the changelog) and a right to object under the DPA. Several entries are optional — they only process data if you connect them.
Purpose: application and database hosting for the managed cloud.
Data: all service data.
Location: as listed on your account's region.
Purpose: CDN, TLS termination, DDoS protection.
Data: traffic metadata, cached static assets (no conversation storage).
Location: global edge, US HQ.
Purpose: transactional email (alerts, receipts, notifications).
Data: recipient addresses, notification content.
Location: per account configuration.
Purpose: AI assistant responses, summaries, QA scoring — only when you select Anthropic and supply your API key.
Data: conversation excerpts and knowledge-base passages needed to answer; card numbers are redacted before any AI call; no training on your data (zero-retention API terms available).
Location: US (EU endpoints available).
Purpose: same as above, when you select OpenAI.
Data: same minimization and redaction rules.
Location: US (EU endpoints available).
Purpose: delivering and receiving channel messages.
Data: message content, sender identifiers.
Purpose: SMS send/receive.
Data: phone numbers, message content.
Purpose: Telegram bot messaging.
Data: message content, chat identifiers.
Purpose: subscription payments for your account.
Data: billing contact and payment method — card details go directly to the provider and never touch our servers.
No analytics trackers, no advertising networks, no data brokers, no third-party session-replay services. Visitor analytics are first-party and stay inside the platform.
Last reviewed: August 2026 · Questions or objection requests: hello@example.com