RevDesk
  • Pricing
Product
Features
AI Coworkers
Give every customer workflow an owner, tools, and a clear outcome.
Omnichannel Messaging
Calls, texts, and email with one customer history.
Deal Operations
Keep the record and next step current as work happens.
Coaching
Guide reps in the moment, dial in parallel, and coach from the real conversation.
Tools
RevDesk API & MCP
Connect your systems and build with RevDesk.
Voice AI
Turn more calls into booked and routed next steps.
Follow-Up & Reactivation
Keep the sequence moving, with clear stop rules.
Integrations
Connect lead sources, records, booking, channels, and operations.
Reporting & Insights
See the location, source, and work behind each result.
Site Optimization
Set a goal and RevDesk runs the winning tests on your site.
RevDesk Managed
We find leads, run outreach, and qualify interest. Your team closes.
Solutions
Built for
Automotive
Work every internet lead like your best BDC.
Health NetworkComing soon
A more connected path to care.
Healthcare Ops
Complete healthcare work end-to-end.
Growing Businesses
Reach more people, run the follow-up, and keep pipeline current.
AI Coworkers
Speed-to-Lead
Calls new form leads in seconds
Outbound Prospecting
Works your lists, warms, books
Customer Care
Reviews, referrals, follow-up care
Re-Engage
Wins back dormant pipeline
Site Optimization
Tests your website and ships the winner
RevDesk Managed
We build and operate outbound for you
Resources
Developers
RevDesk API, SDK, CLI, webhooks, and MCP
Blog
Field notes from useful AI
Changelog
What’s new in RevDesk
Docs
Platform documentation
Case studies
Stories from customers
Trust Center
Security, privacy, and eligible BAAs
Pricing
Login
LoginGet a free demoGet a demo

Sub-processors

Version 2026.5 · Last updated August 18, 2026

  • About This List

  • Apps You Connect

  • Notice of Changes

  • Communications

  • AI and voice

  • Infrastructure

  • Business operations

  • Contact Enrichment

  • HIPAA-Enabled Workspaces

  • Questions

About This List

A sub-processor is a third party that processes personal data on our behalf so we can deliver RevDesk. This page is the authoritative, current list. It is incorporated by reference into Annex III of our Data Processing Agreement and referenced from our Privacy Policy.

Each sub-processor receives only the data it needs to perform its function, under a written contract imposing data-protection obligations no less protective than those we owe you. We remain responsible to you for their performance.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. No advertising or ad-retargeting network appears on this list, because we do not use one.

Apps You Connect

The apps you connect to your workspace yourself, such as a calendar, a CRM, a spreadsheet, or a webhook, are not on this list, on purpose. A sub-processor is a vendor we chose and put into the data path for everyone. A connected app is your instruction: data reaches it because you asked it to, under that provider's own terms, and you can disconnect it at any time.

Keeping the two separate is what makes this list auditable. Everything here is a vendor we are answerable for; everything you connect is a flow you control.

Notice of Changes

How we notify you before a sub-processor changes

We give at least 30 days' notice before a new sub-processor begins processing customer data, or before we replace an existing one. During that window you may object on reasonable data-protection grounds.

To receive these notices, email privacy@revdesk.com asking to be added to the sub-processor notification list. Notices also go to the billing contact on each workspace.

Each revision of this page carries a version number and a change date, shown at the top, so you can identify exactly which list was in effect at a given time.

Communications

Telnyx

United States

Telephony carrier, SMS delivery, and A2P 10DLC registration

What it receives

  • Caller and recipient phone numbers
  • Call audio in transit, and call recordings where recording is enabled
  • SMS message content
  • Business regulatory data submitted for 10DLC vetting (legal name, EIN, address)

Security: SOC 2 Type II, ISO 27001. BAA in place for HIPAA-enabled workspaces.

Privacy policy

Hiya

United States

Caller-ID reputation and branded-calling analytics, provided through Telnyx

What it receives

  • The phone numbers you enroll for reputation monitoring
  • Calling activity associated with those numbers

Security: SOC 2 Type II. Data used only for number-reputation and branded-calling services.

Privacy policy

Resend

United States

Transactional and notification email delivery

What it receives

  • Recipient email address and display name
  • Message subject and body, including booking confirmations and account notifications

Security: SOC 2 Type II. Sending domain is mail.revdesk.com.

Privacy policy

AI and voice

LiveKit Cloud

United States

Real-time media and the runtime the voice agent itself runs in. It carries browser-bridged calls, where a phone leg and a browser leg share a session, and it currently also serves ordinary inbound and outbound AI calls. The LiveKit stack our carrier operates inside its own network remains configured and can serve either direction; which one is live is a routing setting, so treat this entry as covering all AI call audio.

What it receives

  • Voice audio streams for the calls it carries
  • AI agent session metadata
  • On outbound calls, the answering party's first few seconds of audio pass through LiveKit Inference for answering-machine detection, which routes them to a Deepgram speech-to-text model and a Google classification model

Security: SOC 2 Type II. BAA in place for HIPAA-enabled workspaces.

Privacy policy

Google

United States

Gemini, a selectable speech-to-speech voice model, routed through Google Cloud Vertex AI. Also the optional Google Calendar and Sheets integrations.

What it receives

  • Call audio, when a Gemini voice is selected. The model listens and responds to the audio itself, so no separate transcription step is involved
  • On outbound calls, the transcript of the first few seconds of whatever answered, passed to a small Gemini model that classifies it as a person or a machine. This runs whichever voice you selected
  • For connected Google Calendar or Sheets: calendar events, selected sheet contents, profile, and email, only with your OAuth consent

Security: SOC 2, ISO 27001. Content submitted to the Gemini API is not used to train Google's models. Vertex AI routing keeps HIPAA workloads under the Google Cloud BAA.

Privacy policy

OpenAI

United States

Realtime, our default speech-to-speech voice model. Also every text feature in the product (the in-app assistant, summaries, drafting, and knowledge-base embeddings) and internal admin tooling.

What it receives

  • Call audio. The Realtime model listens and answers in speech directly, and transcribes the conversation as it goes
  • Knowledge-base content and agent search phrases, converted to embeddings for retrieval, and passages summarized at indexing time so a search can find them
  • Text you send to the in-app assistant, plus the workspace records it reads while answering you
  • Task and campaign message drafts, activity summaries, and admin tooling content such as text submitted for translation or FAQ generation

Security: SOC 2 Type II. API content is excluded from model training under the enterprise API terms. BAA in place for HIPAA-enabled workspaces, which covers the text features as well as the voice model.

Privacy policy

Deepgram

United States

Answer classification on outbound calls. It transcribes the first few seconds of whatever answers the phone, so the agent can tell a person from a voicemail system and time its message past the beep. That is now its only role: your conversation is transcribed by the speech-to-speech model handling the call, and recordings are not sent anywhere for transcription after a call ends.

What it receives

  • The answering party's first few seconds of audio on an outbound call, processed transiently. Nothing is retained by Deepgram, and the stream is closed as soon as the detection window ends.

Security: SOC 2 Type II. BAA in place, so transcription remains available to HIPAA-enabled workspaces. Speaker labels are scoped to a single call; no voiceprint is created or stored.

Privacy policy

Infrastructure

Vercel

United States

Application hosting and encrypted file storage (Vercel Blob)

What it receives

  • Application traffic served through our hosting
  • Call recordings, voicemail audio, and uploaded files stored in Vercel Blob

Security: SOC 2 Type II. Encrypted at rest, hosted in US regions on AWS.

Privacy policy

Neon

United States

Managed Postgres, the primary data store

What it receives

  • Account data, workspace content, contact records, call metadata, and transcripts

Security: SOC 2 Type II, GDPR compliant. Encrypted at rest with automated encrypted backups.

Privacy policy

Upstash

United States

Managed Redis used as a cache for dashboard counters and rate limiting

What it receives

  • Aggregate counters and short-lived cache keys. No call content is cached.

Security: SOC 2 Type II. Encrypted in transit and at rest.

Privacy policy

Trigger.dev

United States

Background job orchestration for scheduled and asynchronous work

What it receives

  • Task payloads, which can include contact identifiers and message content

Security: SOC 2 Type II. Payloads are retained only for the job-run history window.

Privacy policy

Sentry

United States

Error and performance monitoring

What it receives

  • Stack traces, request context, and diagnostic metadata
  • Identifiers such as a user or organization id where they appear in an error's context

Security: SOC 2 Type II. Configured to scrub credentials and request bodies from captured events.

Privacy policy

Business operations

Stripe

United States

Payment processing and subscription billing

What it receives

  • Payment card information, stored by Stripe and never by us
  • Billing address and email

Security: PCI DSS Level 1 certified.

Privacy policy

PostHog

United States

Product analytics for the marketing site and the application

What it receives

  • Product usage events, pages viewed, and features used
  • Browser, device, and approximate location derived from IP
  • A pseudonymous identifier, and the account identifier once you are signed in

Security: SOC 2 Type II. No call audio, transcript, or message content is sent to PostHog.

Privacy policy

Bytemine

United States

Business-contact search and enrichment, used only when you search for new leads or run enrichment on a contact

What it receives

  • The search criteria you enter when looking for new leads, such as industry, job title, and location
  • The contact identifiers you submit for enrichment, such as name, company, and domain
  • Enriched business-contact attributes are returned to us and cached against your contact record

Security: Operated by SPS Consulting LLC. Search and enrichment run only on your instruction. Because the attributes returned are licensed from third-party sources rather than collected from the individual, see the enrichment note on the sub-processor page for your notice obligations.

Privacy policy

Contact Enrichment

Bytemine is different from every other entry on this list, and deserves to be called out separately. Every other sub-processor receives data you already hold. Enrichment acquires new personal data about a person from third-party sources and returns it to your workspace.

Enrichment runs only when you ask for it, on the contacts you select. But because the resulting data was not collected from the individual directly, running enrichment can trigger obligations that are yours as the controller, not ours as the processor.

Your obligations when you enrich a contact

  • Under GDPR Article 14, where personal data is not obtained from the data subject, you must generally inform them within a reasonable period, and identify the categories of data and its source.
  • You must have a lawful basis for the enrichment itself, not only for holding the original contact record.
  • Enriched attributes are subject to the same access, correction, and deletion rights as any other personal data you hold about that person.

Enriched attributes are cached against your contact record so a repeat lookup does not re-query the provider. Deleting the contact deletes the cached enrichment with it.

HIPAA-Enabled Workspaces

Workspaces with HIPAA mode enabled run against a restricted subset of this list. Turning HIPAA mode on pins voice to providers covered by a Business Associate Agreement and swaps a selected voice that is not, routes Gemini through Google Cloud Vertex AI so it falls under the Google Cloud BAA, keeps call recordings and transcripts out of outbound webhooks and the public API, and applies a minimum-necessary 30-day default to call-recording retention that you can adjust per number afterwards.

Sub-processors outside the call path are not BAA-covered

The BAA-covered set is the call path and the stores behind it. Product analytics, error monitoring, and contact enrichment are not part of it, and they are not covered by a BAA.

In practice: do not run enrichment on a contact whose record is PHI, and treat anything you put into a support ticket or a custom event as leaving the covered boundary. We do not send call audio, transcripts, or message content to any of them.

The text features inside the workspace (the in-app assistant, message and email drafting, and the passage summaries written when your knowledge base is indexed) run on the same BAA-covered model provider as the voice path, so they are inside the covered boundary rather than beside it. For the full posture and to request a BAA, see the HIPAA section of our Privacy Policy.

Questions

Questions about a sub-processor, a transfer mechanism, or an objection to a planned change go to privacy@revdesk.com. Certifications and audit reports are available through the RevDesk Trust Center.

RevDesk
Product
AI CoworkersOmnichannel MessagingDeal OperationsPricing
Solutions
AutomotiveHealthcareGrowing Businesses
Resources
AutomotiveGrowing BusinessesHealthcare OpsHealth NetworkBlogChangelogDocs
Company
AboutContactCareersPartnersAffiliateSecurityTrust Center

Ask your AI assistant about RevDesk

revdesk.com/llms.txt
© RevDesk™ 2026 · Cell Labs, Inc.Privacy Policy·Terms of ServiceRevDesk™ is a trademark of Cell Labs, Inc. All other marks are property of their respective owners.