Last updated: 2026-04-19 · Version 0.1-draft
| Sub-processor | Purpose | Data type | Location | Compliance / DPA |
|---|---|---|---|---|
| Supabase | Database, authentication, storage | All Customer Data at rest | US (AWS us-east) | Privacy · DPA on request |
| Netlify | Web hosting + serverless functions | Application traffic | US | Privacy · DPA on request |
| Stripe | Subscription billing + payment processing | Payment card data, billing address | US | Privacy · PCI DSS L1 |
| Resend | Transactional email delivery | Email addresses, message bodies | US | Privacy |
| Sub-processor | Purpose | Data type | Training opt-out? |
|---|---|---|---|
| Anthropic (Claude) | Primary AI text generation for every employee | Prompts + responses (transient) | Yes — API tier disables training |
| OpenAI (GPT-4o) | Fallback AI text generation | Prompts + responses (transient) | Yes — API tier disables training |
| ElevenLabs | Voice synthesis (Kendra + Marcus voice notes + Jordan audio briefings) | Voice samples (if customer opts into cloning), text for TTS | Yes |
| Sub-processor | Purpose | Data type |
|---|---|---|
| Retell AI | Voice AI infrastructure (Kendra answers calls) | Call audio, transcripts, metadata |
| Twilio | Phone number lookups (caller intel), SMS if opted in | Phone numbers, lookup metadata |
| Sub-processor | Purpose | Data type |
|---|---|---|
| Tavily | Web search (Marcus prospect discovery + Aria trend scan) | Search queries |
| Firecrawl | Web page scraping | Target URLs |
These sub-processors receive data only when the customer explicitly connects them via OAuth:
- Google (Gmail + Calendar) — customer's inbox + calendar events
- Microsoft (Outlook + M365) — customer's inbox + calendar events [app in development]
- HubSpot — contacts, deals
- Slack — message posting to customer's workspace
- QuickBooks / Xero / FreshBooks — invoices, payments [app in development]
- Calendly / Cal.com — meeting bookings [app in development]
| Sub-processor | Purpose | Opt-in required? |
|---|---|---|
| PostHog | Product analytics (opt-out via cookie banner) | EU/CA visitors: yes |
1. Evaluate compliance posture (DPA available, SOC 2, GDPR-compliant)
2. Sign DPA
3. Update this list at least 30 days before processing begins
4. Notify customers who have requested notification
If you object to a new sub-processor, email privacy@yourkendra.com within 14 days of our notice. We'll work with you to find an alternative or offer termination with pro-rated refund.
END · VERSION 0.1-DRAFT · PENDING ATTORNEY REVIEW