Sub-processors

Sub-processors

The third parties involved in running Tephlo, what each one is used for, which data reaches it, and where it operates. This list is part of the Data Processing Agreement.

Last updated 15 August 2026Revision Draft 1.0Effective [EFFECTIVE DATE]

In plain language

Running an AI assistant on WhatsApp and Telegram means other companies are involved: one generates the answers, two carry the messages, one hosts the database, one sends email, one stores files. They are all listed below.

  • Several are off by default — voice transcription, document image reading, web search and error monitoring only apply if they have been switched on.
  • No analytics, advertising or tracking company appears on this list, because none is used.
  • These providers operate internationally. We cannot promise data stays in one country, and this page says where each one is based rather than implying more precision than exists.

Active sub-processors

These are involved in normal operation of every workspace, unless noted otherwise.

In use — all workspaces
ProviderPurposeData categoriesLocation
OpenRouterGenerating the assistant’s replies. Every AI answer goes through this provider, which routes the request on to the selected model provider.The customer’s message and recent conversation, the passages retrieved from the workspace’s knowledge base, and the workspace’s instructions to the assistant.Whatever a customer writes in a message can therefore reach this provider.United States, and the country of whichever model provider it routes to.
OpenAITurning knowledge base text and customer questions into search vectors, so an answer can be found in the right document.Knowledge base text uploaded by the workspace, and the text of customer questions used to search it.This is the default. A deployment can be configured to take search vectors from OpenRouter instead, in which case this row does not apply.United States.
Meta Platforms (WhatsApp Business Cloud API)Receiving and delivering WhatsApp messages. Required for the WhatsApp channel.Customer phone numbers and the full content of messages in both directions.Global infrastructure operated by Meta.See the note on channels below — with your own WhatsApp number, Meta is your provider, not our sub-processor.
TelegramReceiving and delivering Telegram messages. Required for the Telegram channel.Telegram user identifiers and the full content of messages in both directions.Global infrastructure operated by Telegram.
CloudflareObject storage for files customers send and for brand assets; hosting for the public marketing, documentation and legal sites.Uploaded files and their extracted text; brand images. The public sites involve only ordinary connection data.Storage region set when the bucket was created: [STORAGE REGION]. Site hosting is distributed.
Heroku (Salesforce)Application hosting, the managed PostgreSQL database, and the managed key-value store used for queues and short-lived state.All application data at rest, including conversations, knowledge bases and accounts.Region chosen at provisioning: [HOSTING REGION].Confirm the live deployment before this page is published as final; the platform can also be self-hosted, in which case this row is replaced by the operator’s own infrastructure.
MailtrapDelivering operational email: signup verification, team invitations, password resets and escalation alerts.Staff names and email addresses, and the content of those emails.Escalation alerts carry no customer message content — they say a conversation needs a person and link to the console.Endpoint configured per deployment (EU or US): [EMAIL REGION]. A workspace deployment may instead use its own SMTP provider.

Optional — off unless switched on

These are disabled by default. Each requires the platform to be configured for it and, where it affects conversations, the workspace to opt in. If they are off for your workspace, no data reaches them.

Optional — enabled per deployment or per workspace
ProviderPurposeData categoriesLocation
OpenAI (speech to text)Transcribing voice notes so the assistant can answer them.The audio of a voice note, and the resulting transcript.United States.
OpenAI (image reading)Reading text from scanned PDF pages that contain no selectable text.Images of the pages of a document a customer sent.United States.
TavilyWeb search, for question types a workspace has allowed the assistant to look up.A search query derived from the customer’s question.United States.
SentryError monitoring — collecting crash reports so faults get fixed.Error type, stack trace and technical context. Message content, identifiers, tokens and addresses are redacted before logging.Region of the configured project: [ERROR MONITORING REGION].
Telegram GatewayDelivering password-reset codes to a staff member’s phone, where they have chosen that method.A staff phone number and a short one-time code.Global infrastructure operated by Telegram.

A note on messaging channels

Who contracts with WhatsApp and Telegram matters. Most workspaces connect their own WhatsApp Business account or their own Telegram bot. In that case the provider processes under your relationship with them and their terms apply to you directly — they are not our sub-processor, and we cannot influence what they do with the message. Where a workspace uses a number the platform shares between businesses, the relationship is ours and the row above applies. Either way, the provider necessarily sees every message sent over its own channel.

What is deliberately absent from this list

  • No analytics provider. The marketing, documentation and legal sites load no analytics script — their content security policy blocks third-party scripts entirely.
  • No advertising or tracking network, no advertising pixels, and no data brokers.
  • No third-party fonts or CDNs on the public sites; everything is served from our own origin.
  • No payment processor, because the platform does not take payments in-product and never receives card details.
  • No AI model training on your data. Conversations are sent to a provider to generate a reply; they are not contributed to model training by us.

Changes and objections

Before a new sub-processor begins processing customer data, this page is updated and workspace administrators are notified by email, with [SUB-PROCESSOR NOTICE PERIOD] notice. If you object on reasonable data protection grounds, section 7 of the Data Processing Agreement sets out what happens next.

Verify before you rely on this. Provider locations and configuration change. The rows above describe how the platform is built and which providers it is designed to use; the regions marked as gaps must be confirmed against the live deployment before this page is treated as a final compliance record.

Contact

General questions about this document go to support@tephlo.com. Questions about personal data, including requests from individuals, should go to the data protection contact at [DATA PROTECTION CONTACT]; until that address is published, the general address above reaches the same team.

Postal address: [REGISTERED COMPANY NAME], [REGISTERED ADDRESS].