What is a sub-processor

When Klarivox processes personal data on behalf of a customer (acting as a data processor under the GDPR), we sometimes need to engage trusted third parties — for example, our cloud-hosting provider or our AI model provider — to help us deliver the service. Those third parties are called sub-processors.

Every sub-processor we engage is bound by a written contract that requires them to: (a) process personal data only on our documented instructions, (b) maintain appropriate security and confidentiality measures, and (c) impose equivalent obligations on any further sub-processors. We also assess each sub-processor's data-protection and security posture before engagement and on an ongoing basis.

This page has two lists, because two different relationships are involved. The first covers sub-processors of customer data — third parties that may process personal data uploaded to or generated by the Klarivox platform on our customers' behalf. These are the sub-processors incorporated into Annex III of our Data Processing Agreement, and changes to them carry the notice and objection rights described below.

The second covers other service providers we use to run our own business — billing, website analytics, our own CRM and internal tools. Klarivox is the controller for that data, not a processor, so those providers are disclosed here for transparency but are not part of Annex III. For an explanation of which data each role applies to, see our Privacy Policy.

Sub-processors of customer data

The following sub-processors may process personal data that customers upload to, or that is generated by, the Klarivox platform. Locations refer to where the sub-processor's primary data-processing facilities are situated. Where data is transferred outside the European Economic Area, the legal mechanism is set out in the International transfers section.

Sub-processor Purpose Data categories Location Mechanism
Infrastructure & platform
UpCloud Oy Cloud hosting, storage, compute, networking All customer-uploaded data; account data; logs EU regions EEA — no transfer
AI & machine learning
Mistral AI Large language model inference for theme extraction and summarisation Content passed to the model from customer-uploaded data EU EEA — no transfer · zero-retention
Communications
Mailgun Technologies, Inc. (Sinch Email) Transactional email delivery for account, authentication, billing, and service notifications sent to workspace users Recipient name and email address; sender address; email subject and message body; delivery status, timestamps, bounce information, and related event metadata. No customer-uploaded conversation content. EU infrastructure; limited non-EEA administrative and support access EEA storage · DPF · SCCs

Mailgun Technologies, Inc. was added to this table and took effect on August 18, 2026. Its EU-domain message-content retention is configured to zero. See the change log.

Other service providers

These providers support our own business operations. None of them has access to customer-uploaded data, and they are not sub-processors under Annex III of the Data Processing Agreement. We list them so that our processing as a controller is transparent too.

Provider Purpose Data categories Location Mechanism
Analytics
Google Ireland Ltd. (Google Analytics 4) Website analytics for getklarivox.com IP address (anonymised), cookies, browsing events Ireland & United States SCCs · DPF
Billing & finance
Stripe Payments Europe Ltd. Subscription billing and payment processing Billing contact details, payment metadata, VAT information Ireland & United States SCCs · DPF
Internal business operations
HubSpot, Inc. CRM and marketing automation Contact data of prospects and customers United States, Germany SCCs · DPF
Slack Technologies, LLC Internal collaboration Account holders' workspace identifiers. No customer-uploaded data. United States, Ireland SCCs · DPF
EEA — no transfer Data stays within the EEA; no third-country transfer mechanism required SCCs · DPF Transferred outside the EEA under EU Standard Contractual Clauses, and the EU–U.S. Data Privacy Framework where the recipient is certified

International transfers

Where personal data is accessed or transferred outside the European Economic Area, we ensure that the transfer complies with Chapter V of the GDPR and rely on one or more of the following:

  • An adequacy decision under Article 45, including the EU–U.S. Data Privacy Framework for actively certified U.S. recipients.
  • Standard Contractual Clauses under Article 46 (Commission Implementing Decision 2021/914), included in our data-processing agreement where applicable.
  • Supplementary measures — including encryption in transit and at rest, access controls, and pseudonymisation — informed by a Transfer Impact Assessment where required.

Mailgun processes messages, domain metadata, and event logs in its EU infrastructure. Its EU-region configuration does not exclude limited access by authorised personnel outside the EEA for administration, security, or support.

We do not transfer customer-uploaded conversation data to any sub-processor that has not signed a current Data Processing Agreement with Klarivox.

How we notify customers of changes

When Klarivox directly engages a new sub-processor, or replaces an existing one, we provide active customers with at least 30 days' prior written notice, typically by email to the workspace administrator and by updating this page. When an existing sub-processor changes one of its further sub-processors, we pass that notice on without undue delay after receiving it and, where reasonably possible, before the change takes effect.

Customers have the right to object to a proposed change for legitimate data-protection reasons before it takes effect. If we cannot accommodate a reasonable objection, the customer may terminate the affected subscription as set out in their Data Processing Agreement with Klarivox.

To subscribe to email notifications of sub-processor changes, email privacy@getklarivox.com with the subject line "Subscribe — subprocessor updates."

Change log

Every change to the "Sub-processors of customer data" table is recorded here, with the date notice was given and the date the change takes effect. Entries remain on this page so that customers have a durable record of what changed and when.

Notice given Effective Change
August 18, 2026 August 18, 2026 Added — Mailgun Technologies, Inc. (Sinch Email). Transactional email delivery using Mailgun's EU infrastructure. Messages, domain metadata, and event logs are processed regionally in the EU, with message-content retention configured to zero. Limited non-EEA administrative, security, or support access is covered by the EU–U.S. Data Privacy Framework while applicable and the EU Standard Contractual Clauses, Module 3.
August 10, 2026 August 10, 2026 Initial publication. UpCloud Oy (cloud hosting) and Mistral AI (model inference) listed as sub-processors of customer data.

Questions

If you have questions about a specific sub-processor, want a copy of the relevant Standard Contractual Clauses, or wish to subscribe to change notifications, please email privacy@getklarivox.com.

For complete details of how Klarivox processes personal data — including the distinction between data Klarivox controls and data we process on behalf of customers — see our Privacy Policy and (for customers) your signed Data Processing Agreement.