AI subprocessors

Model training and data retention

We do not let our AI subprocessors train models on customer data, and we limit what they retain to what is needed to process each request, with processing in the EU. Here is what is currently configured for each provider.

Version 6 · Published 22 September 2026 · Version history

OpenAI

Live today: powers messaging and content features. Conversation content may include personal data, so processing is pinned to the EU.

ControlStatusDetailsVerified
No training on API dataConfiguredOpenAI's published API policy: data sent to the API is not used to train or improve models unless a customer explicitly opts in. We have not opted in.Vendor documentation2026-09-02
EU data residencyConfiguredAll API traffic is routed to OpenAI's EU endpoint (eu.api.openai.com) from a project created with the Europe region, verified in our backend configuration and the project settings.Vendor documentation2026-09-02
Stored responses off (store=false)ConfiguredEvery request to OpenAI's Responses API carries store=false, so OpenAI keeps no retrievable copy of the prompt or the output once the request completes; without it, requests are kept as Response objects for 30 days. This is the shortest retention setting OpenAI offers on the API; its abuse-monitoring hold on API data under its data policy still applies. Verified in our backend configuration, where the setting sits on the shared model call settings and on the messaging agent.Vendor documentation2026-09-18

Deepgram

Speech-to-text runs against Deepgram's EU endpoint with training opted out on every request.

ControlStatusDetailsVerified
EU processingConfiguredAll transcription requests go to Deepgram's EU endpoint (api.eu.deepgram.com) and are processed entirely within EU AWS regions, verified in our configuration.Vendor documentation2026-09-18
No training (Model Improvement Program opt-out)ConfiguredEvery request carries mip_opt_out=true, which excludes it from Deepgram's Model Improvement Program; opted-out request data is retained only for the duration of processing.Vendor documentation2026-09-18

ElevenLabs

Speech synthesis runs in ElevenLabs' isolated EU environment in Zero Retention Mode.

ControlStatusDetailsVerified
EU data residency (isolated environment)ConfiguredSpeech synthesis runs in ElevenLabs' isolated EU residency environment, a fully separate EU workspace, verified in our configuration.Vendor documentation2026-09-02
Zero Retention ModeConfiguredEvery request runs in Zero Retention Mode (enable_logging=false), so request and response content is deleted once each request completes, verified in our configuration.Vendor documentation2026-09-02
No training on customer contentConfiguredElevenLabs' published policy: customer content is not used for training, and its agreements with third-party model providers expressly prohibit them from training on customer content.Vendor documentation2026-09-02

Version history

Every change to the subprocessor list or the evidence page is recorded here with a version number and publication date. Previous versions of either page are available to customers on request for the term of their DPA and for 24 months after it ends.

  1. Version 6Published 22 September 2026
    • PostHog entry corrected: product analytics events carry the signed-in user's account id, name and email address, so the entry no longer describes them as anonymous. No Customer Personal Data, patient data or message content is sent, session recording is off, and the marketing sites now load PostHog only after the visitor accepts analytics cookies.
    • HubSpot added: our own CRM and the demo scheduling on the marketing websites, EU1 region, contact and meeting details of people who book a demo, no Customer Personal Data.
    • Slack added: internal notifications to our team about signups, payments and demo bookings, United States, name and email address of the person concerned, no Customer Personal Data or PHI, DPF and Standard Contractual Clauses.
  2. Version 5Published 18 September 2026
    • EU DPA Data retention clause: files sent by data subjects in messaging conversations (images, voice messages, videos, documents) are retained for no longer than 90 days from receipt; the text derived from them stays with the conversation.
    • EU DPA Data retention clause and Annex A: contact lists a Customer uploads for a WhatsApp campaign (the file as uploaded and the cleaned list of numbers) are retained for no longer than 12 months from upload; the messages sent stay with the conversation.
    • Deepgram now transcribes customers' voice messages and videos (EU endpoint, Model Improvement Program opt-out); evidence re-verified.
    • Evidence page: OpenAI stored responses switched off (store=false) on every model call, including the content engine, the website scan, media tagging and the ads assistant, not only the messaging agent; verification date added.
  3. Version 4Published 14 September 2026
    • Neon (managed PostgreSQL, London, UK) removed as a subprocessor. The PostgreSQL database now runs on Railway in Amsterdam, Netherlands (EU West), alongside the application backend; the Railway entry is updated accordingly.
    • Customer data is now hosted exclusively in the European Union. Hosting statements in the trust center, the US DPA (Data hosting clause and Annex B), and the EU DPA (EU hosting subclause and Annex B) updated from the EU and UK to the EU.
  4. Version 3Published 6 September 2026
    • Version identifier, publication date, and this change log added to the subprocessor list and the evidence page.
    • OpenAI, ElevenLabs, LiveKit, and Deepgram marked as AI Subprocessors, matching the EU DPA definition.
    • EU DPA updated: subprocessor list attached as Annex C, 30-day notice for AI Subprocessor changes, notice for location and transfer mechanism changes, AI Subprocessor configuration warranty, Conversation Data retention periods.
  5. Version 2Published 2 September 2026
    • Evidence page published: model training and data retention controls configured at OpenAI, Deepgram, and ElevenLabs, each with a verification date.
  6. Version 1Published 27 August 2026
    • Subprocessor list first published: 12 subprocessors with purpose, processing location and region, data categories, agreement, safeguards, and transfer mechanism where applicable.