| Subprocessor | Purpose | Data | Location | DPA |
|---|---|---|---|---|
| Telnyx | Telephony and messaging (numbers, SMS/MMS, voice, 10DLC registration) | Phone numbers, message bodies, call metadata, carrier registration details | United States | DPA |
| OpenRouter | Fallback model routing when the primary model provider is unavailable | Prompt and completion content for the affected request, including conversation context | United States | Privacy |
| E2B | Isolated cloud sandboxes for background agent tasks (the 'cloud computer') | Task briefs, any files or data the task is given, produced deliverables | United States | Privacy |
| Composio | Connected-app actions on the operator's behalf across third-party tools | OAuth tokens and the request/response payloads of actions the operator authorizes | United States | Privacy |
| Intuit QuickBooks | Accounting sync — invoices, expenses, and payouts (operator-authorized OAuth) | Invoice, expense, customer and payout records for the connected company file | United States | Privacy |
| Square | Optional catalog and customer import for operators migrating from Square | Service catalog, customer records, appointment history at import time | United States | Privacy |
| Upstash | Rate limiting (abuse prevention on public endpoints) | Hashed request identifiers and counters. No message or customer content. | United States | Privacy |
| Manus | Website generation for the operator's optional booking site | Business name, services, hours, branding supplied for the generated site | United States | Privacy |
| Vapi | Voice AI infrastructure (real-time call orchestration) | Call audio, transcripts, phone numbers, assistant prompts | United States | DPA |
| Twilio | Telephony (PSTN inbound/outbound, SMS, number provisioning) | Phone numbers, SMS bodies, call metadata, caller IDs | United States | DPA |
| Stripe | Subscription billing + Stripe Connect Express payouts | Operator + affiliate billing metadata, transaction records, KYC. No card numbers stored by Deskwise. | United States | DPA |
| Clerk | Authentication and session management | Email, name, hashed credentials, session tokens, IP | United States | DPA |
| Supabase | Primary Postgres database hosting | All Operator and caller application data (transcripts, appointments, contacts, audit log) | United States (AWS us-east) | DPA |
| Resend | Transactional email (auth, receipts, support replies) | Recipient email addresses, message subject and body, delivery metadata | United States | DPA |
| Vercel | Application hosting, edge runtime, request routing | Request logs, IP, user agent, headers; no application data persisted at this layer | United States | DPA |
| Anthropic | Large language model (Claude) for agent reasoning and tool calls | Call transcripts and prompts at inference time. Zero-retention / no-training-on-content mode. | United States | DPA |
| OpenAI | Speech models and a fallback LLM, primarily reached through Vapi's voice pipeline (ElevenLabs / OpenAI Realtime) | Spoken audio and transcript turns at inference time. Zero-retention / no-training-on-content mode. | United States | DPA |
| Sentry | Error monitoring and performance tracing | Stack traces, user IDs, request URLs, browser metadata. PHI is scrubbed before send. | United States | DPA |
| Plausible Analytics | Cookieless, privacy-friendly product analytics for marketing pages | Aggregated page views, referrer, country. No personal identifiers, no cookies. | European Union | DPA |
- Telnyx
- Purpose
- Telephony and messaging (numbers, SMS/MMS, voice, 10DLC registration)
- Data
- Phone numbers, message bodies, call metadata, carrier registration details
- Location
- United States
- DPA
- DPA
- OpenRouter
- Purpose
- Fallback model routing when the primary model provider is unavailable
- Data
- Prompt and completion content for the affected request, including conversation context
- Location
- United States
- DPA
- Privacy
- E2B
- Purpose
- Isolated cloud sandboxes for background agent tasks (the 'cloud computer')
- Data
- Task briefs, any files or data the task is given, produced deliverables
- Location
- United States
- DPA
- Privacy
- Composio
- Purpose
- Connected-app actions on the operator's behalf across third-party tools
- Data
- OAuth tokens and the request/response payloads of actions the operator authorizes
- Location
- United States
- DPA
- Privacy
- Intuit QuickBooks
- Purpose
- Accounting sync — invoices, expenses, and payouts (operator-authorized OAuth)
- Data
- Invoice, expense, customer and payout records for the connected company file
- Location
- United States
- DPA
- Privacy
- Square
- Purpose
- Optional catalog and customer import for operators migrating from Square
- Data
- Service catalog, customer records, appointment history at import time
- Location
- United States
- DPA
- Privacy
- Upstash
- Purpose
- Rate limiting (abuse prevention on public endpoints)
- Data
- Hashed request identifiers and counters. No message or customer content.
- Location
- United States
- DPA
- Privacy
- Manus
- Purpose
- Website generation for the operator's optional booking site
- Data
- Business name, services, hours, branding supplied for the generated site
- Location
- United States
- DPA
- Privacy
- Vapi
- Purpose
- Voice AI infrastructure (real-time call orchestration)
- Data
- Call audio, transcripts, phone numbers, assistant prompts
- Location
- United States
- DPA
- DPA
- Twilio
- Purpose
- Telephony (PSTN inbound/outbound, SMS, number provisioning)
- Data
- Phone numbers, SMS bodies, call metadata, caller IDs
- Location
- United States
- DPA
- DPA
- Stripe
- Purpose
- Subscription billing + Stripe Connect Express payouts
- Data
- Operator + affiliate billing metadata, transaction records, KYC. No card numbers stored by Deskwise.
- Location
- United States
- DPA
- DPA
- Clerk
- Purpose
- Authentication and session management
- Data
- Email, name, hashed credentials, session tokens, IP
- Location
- United States
- DPA
- DPA
- Supabase
- Purpose
- Primary Postgres database hosting
- Data
- All Operator and caller application data (transcripts, appointments, contacts, audit log)
- Location
- United States (AWS us-east)
- DPA
- DPA
- Resend
- Purpose
- Transactional email (auth, receipts, support replies)
- Data
- Recipient email addresses, message subject and body, delivery metadata
- Location
- United States
- DPA
- DPA
- Vercel
- Purpose
- Application hosting, edge runtime, request routing
- Data
- Request logs, IP, user agent, headers; no application data persisted at this layer
- Location
- United States
- DPA
- DPA
- Anthropic
- Purpose
- Large language model (Claude) for agent reasoning and tool calls
- Data
- Call transcripts and prompts at inference time. Zero-retention / no-training-on-content mode.
- Location
- United States
- DPA
- DPA
- OpenAI
- Purpose
- Speech models and a fallback LLM, primarily reached through Vapi's voice pipeline (ElevenLabs / OpenAI Realtime)
- Data
- Spoken audio and transcript turns at inference time. Zero-retention / no-training-on-content mode.
- Location
- United States
- DPA
- DPA
- Sentry
- Purpose
- Error monitoring and performance tracing
- Data
- Stack traces, user IDs, request URLs, browser metadata. PHI is scrubbed before send.
- Location
- United States
- DPA
- DPA
- Plausible Analytics
- Purpose
- Cookieless, privacy-friendly product analytics for marketing pages
- Data
- Aggregated page views, referrer, country. No personal identifiers, no cookies.
- Location
- European Union
- DPA
- DPA
Notes
- US-only service. Deskwise serves United States operators only. All Operator and caller application data is held in the United States. The one exception is Plausible Analytics (marketing-site analytics), which is EU-hosted and receives only cookieless, aggregated, non-identifying page-view data.
- LLM zero-retention. Anthropic and OpenAI are invoked in zero-retention / no-training-on-content modes where the provider supports them. Prompt and completion content is not retained by the model provider beyond the inference call and is not used to train base models.
- No card data. All card numbers are handled by Stripe (PCI DSS Level 1). Deskwise does not see, store, or process full PANs.
- HIPAA. Deskwise runs healthcare verticals in a PHI-safe scheduling mode, so no subprocessor above processes Protected Health Information on our behalf. Do not submit PHI to the Service. Compliance questions: contact@deskwise.co.
Changes
We may add, replace, or remove subprocessors as the Service evolves. Material changes are communicated to Operators by email at least 30 days before they take effect, where reasonably practicable.
Questions
Privacy questions and subprocessor inquiries: contact@deskwise.co. Related pages: Privacy Policy, Terms, Security.
Vellor Systems LLC · Cheyenne, Wyoming, USA