1. Status and scope
This document is a draft for founder and legal review. It is not legal advice and does not create a commitment until approved and published.
A provider appearing in code or configuration is not proof that it is active in every deployment. Confirm contracts, legal names, processing locations, and data terms before publication.
2. Core infrastructure
Supabase: PostgreSQL, authentication client, and Storage; account, Workspace, Conversation, transcript, recording/TTS where used, and execution data; region [PRIMARY_HOSTING_REGION].
3. Voice and telephony
Twilio: telephony, Phone Numbers, callbacks, and media paths where configured. Deepgram: speech recognition path. ElevenLabs: speech synthesis path. Provider locations and active configuration require confirmation.
4. AI and model providers
Cerebras and Groq appear in LLM paths; OpenAI appears in current or configurable LLM/STT/TTS paths; Sarvam appears in optional Indic STT/LLM/TTS paths. Prompts, audio/text, Knowledge context, and generated output may be involved.
5. Email and payments
Resend appears in email delivery paths. Dodo appears in billing webhook handling. Processing locations, retention, and contract terms require confirmation.
6. Not established by this audit
AWS, Stripe, Razorpay, HubSpot, Capsule, Mailchimp, Discord, Zendesk, Help Scout, and Google Sheets are not listed as active subprocessors from this audit. Retired or optional code requires separate evidence.
7. Contact and updates
Subprocessor questions and notices: [LEGAL_EMAIL]. The approved notice period and update process are [SUBPROCESSOR_NOTICE].
