On this page
A subprocessor is a company we engage to process personal data on your behalf in order to run the service. This page is the authoritative list. It is incorporated by reference into the Terms of Service and into the Data Processing Addendum, and it is the list to which the objection right in the DPA applies.
The list below is derived from the outbound integrations that actually exist in the product. If a vendor is not on this page, we do not send your data to it.
1. Core subprocessors
These are engaged for every customer. They cannot be switched off while you use the service.
| Subprocessor | What it does for us | Data categories it receives |
|---|---|---|
| Hyvor Relay | Delivers every email sent through the platform (SMTP relay and delivery events). | Sender and recipient addresses, cc/bcc, subject, message body (HTML and text) and attachments. |
| Stripe | Processes subscription payments, checkout and the billing portal. | Billing contact and payment details collected by Stripe itself, plus customer and subscription identifiers. We never receive or store card numbers. |
| Cloudflare | Turnstile anti-abuse challenge on the signup form. | Challenge token and the technical signals Turnstile collects in the browser. No account data is sent. |
| Spamhaus (DBL) and SURBL | Domain reputation and blocklist checks for your sending domains. | The sending domain name only, sent as a DNS query. No personal data. |
2. Subprocessors engaged by your own choices
These are engaged only when you connect the corresponding channel, integration or feature. If you never connect it, no data of yours reaches that vendor.
| Subprocessor | What it does for us | Data categories it receives |
|---|---|---|
| Meta Platforms (Instagram, WhatsApp Cloud API, Messenger, Facebook Ads, Conversions API) | Sends and receives messages on the Instagram, WhatsApp and Messenger channels you connect, reads ad spend insights, and reports conversion events back to your ad account. | Platform user identifiers (Instagram-scoped id, page-scoped id, WhatsApp phone number in E.164), message content and media, public profile fields returned by the API (username, display name, profile picture), and — for conversion reporting — the click identifier of the ad that started the conversation. |
| TikTok | Sends and receives direct messages on the TikTok account you connect. | TikTok open id, username and display name, and message content. |
| Telegram | Sends and receives messages through the Telegram bot you connect. | Telegram chat id and message content. |
| Google (OAuth, Calendar, Sheets) | Reads free/busy availability from the calendar you connect and appends rows to the spreadsheet an automation step targets. | The Google account email and granted scopes; calendar id and time window (read-only); and, for the spreadsheet step, whatever contact fields you choose to map into the row. |
| Mailchimp, ActiveCampaign, GetResponse, MailerLite, Klaviyo, Drip, Moosend, SendGrid | One-way import of an existing contact list from the platform you are migrating from, when you connect it. | Outbound: the API key you supply. Inbound: contact email addresses, names and subscription status read from that platform. |
| AI model provider | Powers the AI assistants that draft email templates, landing pages and automations, and generates the embeddings used to search your knowledge files. | The prompt you write and the content it references — including the text of knowledge files you upload. Contact lists and message history are not sent. |
| Pexels | Searches royalty-free stock imagery from inside the AI builders. | Only the generated search phrase. No personal data. |
| Browser push services (Google FCM, Mozilla, Apple) | Delivers web push notifications to the browser that subscribed. | The subscriber endpoint issued by that browser vendor and the encrypted notification payload. |
The AI model provider currently configured for the platform is [AI PROVIDER]. The product is built against a provider-neutral interface, so this can change; a change is announced as described in "Changes and your right to object".
When you connect a channel, that provider is also a controller in its own right for the account and the platform identifiers it already holds. Its own terms and privacy policy apply to you and to the people who message you there, in addition to ours.
3. Hosting and infrastructure
The application, its PostgreSQL database, its Redis cache, its message bus and its ClickHouse analytics store run on infrastructure we operate ourselves at [HOSTING PROVIDER AND REGION]. These components are not managed data services resold by a third party; the hosting provider supplies the machines and the network.
Support ticket attachments are stored on that same infrastructure, on the application's own disk. They are not placed in a third-party object storage service.
4. What we deliberately do not use
Stating the absences is as useful as stating the list. As of the date at the top of this page, the product contains no integration with any of the following, and none of them receives your data:
- No third-party product analytics or session-recording tool (no Google Analytics, no PostHog, no Mixpanel, no session replay) in the application.
- No third-party error-tracking or APM vendor (no Sentry, no Datadog, no New Relic).
- No advertising network, data broker or audience-enrichment provider.
- No third-party object storage provider for your files.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
5. How we engage a subprocessor
Before a vendor is added, we assess what data it would receive, whether the same outcome is achievable with less data, and what its own data protection commitments are. We engage each subprocessor under a written contract that binds it to obligations no less protective than those we owe you, including confidentiality, security measures and assistance with data subject rights.
Credentials for every connected integration are encrypted at rest with AES-256-GCM before being stored, and we send each subprocessor only the data it needs for the purpose listed above.
6. Changes and your right to object
You give general authorisation for us to engage the subprocessors listed here and to replace or add to them as the service evolves. Before a new subprocessor starts processing your data, we will update this page and the date at the top of it, and we will give at least 30 days' notice by email to the account address.
If you have a reasonable, data-protection-related objection to a new subprocessor, tell us at [DPO EMAIL] within those 30 days. We will work with you in good faith to find an alternative — for example, disabling the feature that requires it. If no reasonable alternative exists, you may terminate the affected part of the service without penalty, with a pro-rata refund of fees already paid for the unused period.
To be notified of changes, ask to be added to the subprocessor notice list at the address above.
7. Contact
Questions about this list: [DPO EMAIL]. Controller: [LEGAL ENTITY NAME], [CNPJ], [REGISTERED ADDRESS].
This document is a template generated from how the product actually works. It is not legal advice and must be reviewed by a qualified lawyer before it is relied on with real customers.