Subprocessor List

This Subprocessor List is published by the Company. The Company's full identity, address, and legal contact details appear at the bottom of this page. This document describes the categories of providers the Company engages to operate the Service, along with the categories of data they may process in that capacity. It is intended for any Customer who has entered into an agreement with the Company for use of the Platform, as well as anyone seeking to understand how data flowing through the Service is handled by third parties.

> In plain language: when you use the Platform, you (the Customer) remain responsible for the data of your own contacts and end users — this is referred to as acting as a "data controller." The Company acts as your primary processor: it processes that data on your behalf, under your instructions, within the scope of your agreement with it. To deliver the Service, the Company itself relies on a limited number of specialized providers — hosting, payments, artificial intelligence, communications, among others — referred to as "subprocessors." This page lists them, describes their role, and specifies the conditions under which each one comes into play.

Table of Contents

  1. Our due diligence approach
  2. Table of current subprocessors
  3. Subprocessing and notice of change
  4. Links to the other documents

1. Our due diligence approach

The Company does not retain a provider lightly. Before a new subprocessor is added to this list, it is evaluated on, among other things:

  • the nature and sensitivity of the data it would be called on to process, as well as the actual necessity of that processing to deliver the feature in question;
  • the technical and organizational security measures it maintains, including, where applicable, any certifications or attestations recognized in its industry — the mention of a certification specific to a given provider does not constitute any representation by the Company as to its own certifications;
  • its contractual data protection framework, its reputation, and its stability as a provider;
  • its ability to honor the commitments the Company itself must meet toward its Customers.

Each subprocessor retained is bound by a contractual agreement that imposes data protection obligations suited to its role — including as to the purpose and duration of processing, applicable security measures, notification in the event of a security incident affecting Customer data, and the deletion or return of data at the end of the contractual relationship. These agreements also impose a strict confidentiality obligation on the subprocessor: it may use the data entrusted to it only to perform the services agreed with the Company, and may neither exploit it for its own purposes nor disclose it to unauthorized third parties.

The Company periodically reviews the list of its subprocessors and their compliance with these requirements, and removes any provider that ceases to meet them.

2. Table of current subprocessors

The table below presents, by category, the subprocessors the Company engages in operating the Service. The core infrastructure (database, authentication, storage, and application hosting) is operated in North America, through our cloud infrastructure providers. Certain categories of subprocessors below — notably artificial intelligence model providers, voice synthesis providers, video avatar generation providers, and the third-party messaging gateway — may process data outside that region; the Data Residency & Transfers document addresses this point category by category.

| Provider (category) | Role | Data categories involved | Condition of use |
|---|---|---|---|
| Database, authentication, and file storage infrastructure provider | Hosting of account data and content | Identity data, content, and uploaded files | Always, for all Customers |
| Web application and server function hosting provider | Application hosting and execution of server-side processing | Data flowing through the application | Always, for all Customers |
| Payment processing provider | Billing and payment processing (PCI-DSS Level 1 certified) | Billing and payment data | Customers with a paid subscription |
| Artificial intelligence model providers (real-time language and voice processing) | Powering AI-driven conversational and voice features | Content of exchanges submitted to AI features | When the relevant AI features are enabled and in use |
| Voice synthesis provider | Text-to-speech conversion for voice features | Text submitted for voice conversion | When voice features are enabled |
| Video avatar generation provider | Generation of animated video representations | Content submitted for avatar generation | When this feature is enabled |
| Third-party messaging and communications gateway (professional networks, instant messaging, email, calendar) | Connection and synchronization of third-party accounts the Customer chooses to link to the Platform | Messages, metadata, and content of connected accounts | Only if the Customer voluntarily connects a third-party account |
| Asynchronous processing orchestration provider | Reliable execution of background processing and automations | Data necessary to execute the requested processing | Internal infrastructure, always active |
| Mapping services provider | Mapping and address autocomplete | Location queries entered by the User | Location-related features, when used |

Some of the categories above apply only to optional features of the Service. When a Customer or User does not enable a given feature — for example, video avatars, voice synthesis, or connecting a third-party account — the subprocessor corresponding to that feature processes no data for that Customer.

3. Subprocessing and notice of change

The Company reserves the right to retain new subprocessors, or to terminate its relationship with an existing subprocessor, as the Service evolves. It undertakes to keep this list current and to inform Customers of any addition or removal of a subprocessor listed above, within a reasonable period before the new subprocessor begins operating.

Where a Customer has, under its contractual agreement with the Company, a right to object to the addition of a new subprocessor, that right is exercised in accordance with the terms, timelines, and procedure set out in the Data Processing Agreement entered into with the Company. This page constitutes the notification mechanism provided for that purpose; it does not, however, replace the precise contractual terms applicable between the Company and each Customer, which remain governed by the Data Processing Agreement.

Customers are invited to consult this page periodically, or to subscribe to it where that mechanism is offered, to stay informed of any changes.

4. Links to the other documents

This Subprocessor List is part of a broader set of legal documents governing data processing on the Platform. For a complete understanding of the Company's commitments, please also consult:

  • the Privacy Policy, which describes in general terms how and why personal data is processed on the Platform;
  • the Data Processing Agreement, which sets out the precise contractual terms governing the Company's use of subprocessors, including the Customer's rights in that regard;
  • the Security Overview, which describes the technical and organizational security measures maintained by the Company and, to the extent applicable, by its subprocessors;
  • the Data Residency & Transfers document, which specifies where data is hosted and processed, as well as the framework applicable to international transfers where relevant.

In the event of a discrepancy between this page and the Data Processing Agreement regarding the contractual terms applicable to a Customer, the Data Processing Agreement prevails.