Trust
Sub-processors
Every third party customer data can reach, separated into the ones every workspace uses and the ones only a workspace that connected them uses.
Used by every workspace
| Service | Purpose | Data involved |
|---|---|---|
| Infrastructure hosting | Runs the application and the databases behind it. The provider is named in the signed data processing addendum. | All stored data, at rest on servers OrhanAI operates: accounts, workspaces, agents, conversations, leads and uploaded files. |
| Google (Gemini API) | Generates answers and computes the embeddings that make trained knowledge searchable. | Visitor messages, the trained knowledge retrieved to answer them, and any image or document a visitor attaches. |
| Brevo | Sends transactional email. | Recipient email address and the contents of the message, such as a verification code or a ticket reply. |
| Stripe | Takes payment and holds subscription state. | Billing email, workspace identifier and payment details. Card numbers are entered on Stripe and never reach OrhanAI. |
| Object storage | Stores uploaded training files, chat image attachments and blog media. Self-managed, alongside the application. | The uploaded files themselves. |
| Vector search | Holds the embeddings that make trained knowledge searchable. Self-managed, alongside the application. | Trained knowledge chunks and their embeddings. |
Used only when you connect them
None of these receive anything until someone in your workspace connects the integration. Disconnecting it stops the flow.
| Service | Purpose | Data involved |
|---|---|---|
| Google (sign in) | Optional sign in with a Google account. | Name and email address, for workspace users who choose it. |
| Meta (WhatsApp) | Delivers agent replies on WhatsApp. | Message content and the sender's WhatsApp number, for workspaces that connect the channel. |
| Meta (Messenger and Instagram) | Delivers agent replies on a connected Facebook Page or Instagram account. | Message content and the sender's platform identifier, for workspaces that connect the channel. |
| Google (Gmail) | Reads unanswered inbox mail and replies in the same thread. | Email content and sender address, for workspaces that connect the channel. |
| Google Calendar | Reads availability and books appointments. | Attendee name, email, and the booking details, for workspaces that connect a calendar. |
| Cal.com | Reads availability and books appointments. | Attendee name, email, and the booking details, for workspaces that connect it. |
| Pipedrive | Syncs captured leads into a customer's CRM. | Lead name, email, phone and conversation context, for workspaces that connect it. |
| Salesforce | Syncs captured leads into a customer's CRM. | Lead name, email, phone and conversation context, for workspaces that connect it. |
| Sentry | Collects application errors, when configured by the operator. | Error messages and stack traces. Not conversation content. |
Changes to this list
This page is generated from the same list the application is checked against, so a new integration cannot ship without appearing here. Customers with a signed data processing addendum are notified before a new sub-processor starts handling their data.
Questions, or an objection to a sub-processor, go to links@orhanai.com.