{
  "version": "v0.1",
  "updated": "2026-08-23",
  "subprocessors": [
    {
      "name": "Meta Platforms",
      "purpose": "WhatsApp message delivery",
      "data": "Message content, phone numbers",
      "jurisdiction": "Global"
    },
    {
      "name": "Supabase",
      "purpose": "Database and dashboard authentication",
      "data": "All customer data",
      "jurisdiction": "Germany (EU)"
    },
    {
      "name": "Render",
      "purpose": "API hosting",
      "data": "All customer data, in transit and in memory",
      "jurisdiction": "Germany (EU)"
    },
    {
      "name": "Hetzner Online GmbH",
      "purpose": "Automation execution — Windmill, from module 9",
      "data": "Automation run data",
      "jurisdiction": "Germany (EU)"
    },
    {
      "name": "Cloudflare",
      "purpose": "DNS, frontend hosting, object storage",
      "data": "Media, exports, traffic metadata",
      "jurisdiction": "Global (object storage configurable to the EU)"
    },
    {
      "name": "Stripe",
      "purpose": "Payments",
      "data": "Billing details",
      "jurisdiction": "USA and EU"
    },
    {
      "name": "OpenAI",
      "purpose": "AI generation",
      "data": "Message content, only when the customer enables AI",
      "jurisdiction": "USA"
    },
    {
      "name": "Anthropic",
      "purpose": "AI generation fallback",
      "data": "Message content, only when the customer enables AI",
      "jurisdiction": "USA"
    },
    {
      "name": "OpenRouter",
      "purpose": "AI model gateway, when a non-primary model is selected",
      "data": "Message content, only when the customer enables AI",
      "jurisdiction": "USA"
    },
    {
      "name": "Google",
      "purpose": "Sheets, Calendar and Forms connectors",
      "data": "Only what the customer's automation sends",
      "jurisdiction": "Global"
    },
    {
      "name": "Resend",
      "purpose": "Transactional email",
      "data": "Email addresses",
      "jurisdiction": "USA"
    },
    {
      "name": "Sentry",
      "purpose": "Error tracking",
      "data": "Metadata and identifiers only — never message content",
      "jurisdiction": "USA and EU"
    },
    {
      "name": "Better Stack",
      "purpose": "Uptime monitoring",
      "data": "Endpoint availability only",
      "jurisdiction": "USA"
    }
  ]
}
