What is a sub-processor
When Klarivox processes personal data on behalf of a customer (acting as a data processor under the GDPR), we sometimes need to engage trusted third parties — for example, our cloud-hosting provider or our AI model provider — to help us deliver the service. Those third parties are called sub-processors.
Every sub-processor we engage is bound by a written contract that requires them to: (a) process personal data only on our documented instructions, (b) maintain appropriate security and confidentiality measures, and (c) impose equivalent obligations on any further sub-processors. We also assess each sub-processor's data-protection and security posture before engagement and on an ongoing basis.
This page has two lists, because two different relationships are involved. The first covers sub-processors of customer data — third parties that may process personal data uploaded to or generated by the Klarivox platform on our customers' behalf. These are the sub-processors incorporated into Annex III of our Data Processing Agreement, and changes to them carry the notice and objection rights described below.
The second covers other service providers we use to run our own business — billing, website analytics, our own CRM and internal tools. Klarivox is the controller for that data, not a processor, so those providers are disclosed here for transparency but are not part of Annex III. For an explanation of which data each role applies to, see our Privacy Policy.
Sub-processors of customer data
The following sub-processors may process personal data that customers upload to, or that is generated by, the Klarivox platform. Locations refer to where the sub-processor's primary data-processing facilities are situated. Where data is transferred outside the European Economic Area, the legal mechanism is set out in the International transfers section.
| Sub-processor | Purpose | Data categories | Location | Mechanism |
|---|---|---|---|---|
| Infrastructure & platform | ||||
| UpCloud Oy | Cloud hosting, storage, compute, networking | All customer-uploaded data; account data; logs | EU regions | EEA — no transfer |
| AI & machine learning | ||||
| Mistral AI | Large language model inference for theme extraction and summarisation | Content passed to the model from customer-uploaded data | EU | EEA — no transfer · zero-retention |
| Communications | ||||
| Mailgun Technologies, Inc. (Sinch Email) | Transactional email delivery for account, authentication, billing, and service notifications sent to workspace users | Recipient name and email address; sender address; email subject and message body; delivery status, timestamps, bounce information, and related event metadata. No customer-uploaded conversation content. | EU infrastructure; limited non-EEA administrative and support access | EEA storage · DPF · SCCs |
Mailgun Technologies, Inc. was added to this table and took effect on August 18, 2026. Its EU-domain message-content retention is configured to zero. See the change log.
Other service providers
These providers support our own business operations. None of them has access to customer-uploaded data, and they are not sub-processors under Annex III of the Data Processing Agreement. We list them so that our processing as a controller is transparent too.
| Provider | Purpose | Data categories | Location | Mechanism |
|---|---|---|---|---|
| Analytics | ||||
| Google Ireland Ltd. (Google Analytics 4) | Website analytics for getklarivox.com | IP address (anonymised), cookies, browsing events | Ireland & United States | SCCs · DPF |
| Billing & finance | ||||
| Stripe Payments Europe Ltd. | Subscription billing and payment processing | Billing contact details, payment metadata, VAT information | Ireland & United States | SCCs · DPF |
| Internal business operations | ||||
| HubSpot, Inc. | CRM and marketing automation | Contact data of prospects and customers | United States, Germany | SCCs · DPF |
| Slack Technologies, LLC | Internal collaboration | Account holders' workspace identifiers. No customer-uploaded data. | United States, Ireland | SCCs · DPF |
International transfers
Where personal data is accessed or transferred outside the European Economic Area, we ensure that the transfer complies with Chapter V of the GDPR and rely on one or more of the following:
- An adequacy decision under Article 45, including the EU–U.S. Data Privacy Framework for actively certified U.S. recipients.
- Standard Contractual Clauses under Article 46 (Commission Implementing Decision 2021/914), included in our data-processing agreement where applicable.
- Supplementary measures — including encryption in transit and at rest, access controls, and pseudonymisation — informed by a Transfer Impact Assessment where required.
Mailgun processes messages, domain metadata, and event logs in its EU infrastructure. Its EU-region configuration does not exclude limited access by authorised personnel outside the EEA for administration, security, or support.
We do not transfer customer-uploaded conversation data to any sub-processor that has not signed a current Data Processing Agreement with Klarivox.
How we notify customers of changes
When Klarivox directly engages a new sub-processor, or replaces an existing one, we provide active customers with at least 30 days' prior written notice, typically by email to the workspace administrator and by updating this page. When an existing sub-processor changes one of its further sub-processors, we pass that notice on without undue delay after receiving it and, where reasonably possible, before the change takes effect.
Customers have the right to object to a proposed change for legitimate data-protection reasons before it takes effect. If we cannot accommodate a reasonable objection, the customer may terminate the affected subscription as set out in their Data Processing Agreement with Klarivox.
To subscribe to email notifications of sub-processor changes, email privacy@getklarivox.com with the subject line "Subscribe — subprocessor updates."
Change log
Every change to the "Sub-processors of customer data" table is recorded here, with the date notice was given and the date the change takes effect. Entries remain on this page so that customers have a durable record of what changed and when.
| Notice given | Effective | Change |
|---|---|---|
| August 18, 2026 | August 18, 2026 | Added — Mailgun Technologies, Inc. (Sinch Email). Transactional email delivery using Mailgun's EU infrastructure. Messages, domain metadata, and event logs are processed regionally in the EU, with message-content retention configured to zero. Limited non-EEA administrative, security, or support access is covered by the EU–U.S. Data Privacy Framework while applicable and the EU Standard Contractual Clauses, Module 3. |
| August 10, 2026 | August 10, 2026 | Initial publication. UpCloud Oy (cloud hosting) and Mistral AI (model inference) listed as sub-processors of customer data. |
Questions
If you have questions about a specific sub-processor, want a copy of the relevant Standard Contractual Clauses, or wish to subscribe to change notifications, please email privacy@getklarivox.com.
For complete details of how Klarivox processes personal data — including the distinction between data Klarivox controls and data we process on behalf of customers — see our Privacy Policy and (for customers) your signed Data Processing Agreement.