Sub-processors
Last updated: 24 July 2026
Product: AI Call Agent (United Kingdom)
Contact: support@aicallagent.ai
This page lists sub-processors (and key service providers) that AI Call Agent engages to operate the Service and that may process personal data on our behalf or on behalf of our business customers. It supplements our Privacy Policy.
Where you are the controller of call-recipient or lead data and we act as your processor, these parties may act as our sub-processors for that processing. Where we are the controller (e.g. your account data as a customer), they process data on our instructions as described in the Privacy Policy.
Counsel note: Entity legal names, exact transfer mechanisms, and executed DPAs should be confirmed with counsel (Monday 19.3 / R-018). This list reflects systems currently used to run the product.
1. How we use this list
| Topic | Practice |
|---|---|
| Updates | We keep this register current when we add or replace a material sub-processor. |
| Notice | We aim to give at least 30 days’ notice of material additions (email to the account contact and/or an in-product notice), except where a change is required urgently for security or continuity. |
| Objections | If your DPA or order form allows objection to a new sub-processor, email support@aicallagent.ai within the notice period with the reason. We will discuss alternatives where reasonably practicable. |
| Transfers | Many providers process data in the United States or other countries. Where UK adequacy does not apply, we rely on appropriate safeguards (e.g. UK IDTA / UK Addendum to SCCs) as described in the Privacy Policy and our contracts with providers. |
2. Current sub-processors
| Sub-processor | Purpose | Categories of personal data (typical) | Location / region (typical) |
|---|---|---|---|
| Vercel, Inc. | Application hosting, edge delivery, optional Web Analytics (with cookie consent) | Account/usage data necessary to run the app; analytics events if consented | Global (incl. US/EU edge) |
| Neon, Inc. | Managed Postgres database | Account, company, leads/contacts, calls metadata, billing records, compliance metadata | Cloud region configured for the project (commonly AWS / US or EU) |
| Twilio Inc. | Telephony (PSTN), phone numbers, regulatory / KYC bundles | Phone numbers, call metadata, recordings/audio where configured, KYC documents submitted for number compliance | US / global |
| Vapi (Vapi AI, Inc.) | Voice AI orchestration, assistants, tool calls | Audio, transcripts, conversation content, tool payloads, call metadata | US |
| OpenAI, L.L.C. (typically via Vapi or customer BYOK) | Large language model inference | Prompt/conversation context derived from calls and agent configuration | US |
| Deepgram, Inc. (typically via Vapi) | Speech-to-text | Audio / voice data for transcription | US |
| ElevenLabs, Inc. (typically via Vapi) | Text-to-speech | Text content for synthesis | US / as configured |
| Stripe, Inc. | Payment processing (Checkout / billing) | Billing contact details, payment method tokens (we do not store full card numbers) | Global (PCI) |
| Amazon Web Services, Inc. / S3-compatible object storage (e.g. DigitalOcean Spaces where configured) | Object storage for media and private compliance uploads | Uploaded files (e.g. KYC documents), blog/media assets | Region of the configured bucket |
| Microsoft Corporation (Azure / Microsoft Graph) | Transactional email delivery where configured | Email addresses and message content for product/ops emails | As per Azure region / Graph |
| Cal.com, Inc. | Scheduling (when Cal.com is selected) | Booking/attendee details, calendar configuration | As per Cal.com |
| Calendly, LLC | Scheduling (when Calendly is connected) | Booking/attendee details, OAuth calendar data as authorised | As per Calendly |
| Google LLC | Google Calendar / Workspace APIs (when connected); optional Tag Manager / analytics tags with cookie consent | Calendar availability and booking-related data; analytics cookies/events if consented | Global (incl. US) |
| Microsoft Corporation | Outlook / Microsoft Calendar (when connected via supported integrations) | Calendar availability and booking-related data as authorised | Global (incl. US/EU) |
| Upstash, Inc. (optional) | Distributed rate limiting | IP addresses and rate-limit keys | As per Upstash region |
Providers marked “typically via Vapi” process data because voice traffic is routed through Vapi’s platform to those model/STT/TTS services as configured for an agent.
3. Not listed here
- Your own CRM, calendar, or tools that you connect beyond the integrations above.
- Purely internal staff tools that do not process customer personal data as a production dependency.
- One-off professional advisers (lawyers, accountants) engaged under confidentiality, disclosed under the Privacy Policy where applicable.
4. Related documents
- Privacy Policy
- Terms of Service
- GDPR / data subject rights (see Privacy Policy and our legal pack)
- Engineering inventory (internal):
docs/security/THIRD_PARTY_TOOLS.md
5. Change log
| Date | Change |
|---|---|
| 2026-07-24 | Initial public sub-processor register published (Monday 19.9 / 22.2). |