Sub-processors
Version 2026.2 · Last updated July 24, 2026
About This List
A sub-processor is a third party that processes personal data on our behalf so we can deliver RevDesk. This page is the authoritative, current list. It is incorporated by reference into Annex III of our Data Processing Agreement and referenced from our Privacy Policy.
Each sub-processor receives only the data it needs to perform its function, under a written contract imposing data-protection obligations no less protective than those we owe you. We remain responsible to you for their performance.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. No advertising or ad-retargeting network appears on this list, because we do not use one.
Notice of Changes
How we notify you before a sub-processor changes
We give at least 30 days' notice before a new sub-processor begins processing customer data, or before we replace an existing one. During that window you may object on reasonable data-protection grounds.
To receive these notices, email privacy@revdesk.com asking to be added to the sub-processor notification list. Notices also go to the billing contact on each workspace.
Each revision of this page carries a version number and a change date, shown at the top, so you can identify exactly which list was in effect at a given time.
Communications
Telnyx
Telephony carrier, SMS delivery, and A2P 10DLC registration
Telnyx
Telephony carrier, SMS delivery, and A2P 10DLC registration
Data Shared:
- Caller and recipient phone numbers
- Call audio in transit, and call recordings where recording is enabled
- SMS message content
- Business regulatory data submitted for 10DLC vetting (legal name, EIN, address)
Security:
SOC 2 Type II, ISO 27001. BAA in place for HIPAA-enabled workspaces.
Hiya
Caller-ID reputation and branded-calling analytics, provided through Telnyx
Hiya
Caller-ID reputation and branded-calling analytics, provided through Telnyx
Data Shared:
- The phone numbers you enroll for reputation monitoring
- Calling activity associated with those numbers
Security:
SOC 2 Type II. Data used only for number-reputation and branded-calling services.
Resend
Transactional and notification email delivery
Resend
Transactional and notification email delivery
Data Shared:
- Recipient email address and display name
- Message subject and body, including booking confirmations and account notifications
Security:
SOC 2 Type II. Sending domain is mail.revdesk.com.
AI and voice
LiveKit Cloud
Real-time media for browser-bridged calls only, where a phone leg and a browser leg share a session. Ordinary inbound and outbound AI calls do not use LiveKit Cloud: they run on the LiveKit stack our carrier operates inside its own network, so that media stays with Telnyx.
LiveKit Cloud
Real-time media for browser-bridged calls only, where a phone leg and a browser leg share a session. Ordinary inbound and outbound AI calls do not use LiveKit Cloud: they run on the LiveKit stack our carrier operates inside its own network, so that media stays with Telnyx.
Data Shared:
- Voice audio streams for browser-bridged calls
- AI agent session metadata
Security:
SOC 2 Type II. BAA in place for HIPAA-enabled workspaces.
Google
Gemini, a selectable speech-to-speech voice model, routed through Google Cloud Vertex AI. Also the optional Google Calendar and Sheets integrations.
Gemini, a selectable speech-to-speech voice model, routed through Google Cloud Vertex AI. Also the optional Google Calendar and Sheets integrations.
Data Shared:
- Call audio, when a Gemini voice is selected. The model listens and responds to the audio itself, so no separate transcription step is involved
- For connected Google Calendar or Sheets: calendar events, selected sheet contents, profile, and email, only with your OAuth consent
Security:
SOC 2, ISO 27001. Content submitted to the Gemini API is not used to train Google's models. Vertex AI routing keeps HIPAA workloads under the Google Cloud BAA.
OpenAI
Realtime, our default speech-to-speech voice model. Also embeddings for knowledge-base search, and internal admin tooling.
OpenAI
Realtime, our default speech-to-speech voice model. Also embeddings for knowledge-base search, and internal admin tooling.
Data Shared:
- Call audio. The Realtime model listens and answers in speech directly, and transcribes the conversation as it goes
- Knowledge-base content and agent search phrases, converted to embeddings for retrieval
- Admin tooling content, such as text submitted for translation or FAQ generation
Security:
SOC 2 Type II. API content is excluded from model training under the enterprise API terms.
Deepgram
Speech-to-text. Used in the modular voice pipeline, to transcribe recordings after a call, and briefly at the start of an outbound call to tell whether a person or a voicemail system answered.
Deepgram
Speech-to-text. Used in the modular voice pipeline, to transcribe recordings after a call, and briefly at the start of an outbound call to tell whether a person or a voicemail system answered.
Data Shared:
- Call audio, processed transiently for transcription. Only where the workspace has transcript saving enabled.
Security:
SOC 2 Type II. BAA in place, so transcription remains available to HIPAA-enabled workspaces. Speaker labels are scoped to a single call; no voiceprint is created or stored.
ElevenLabs
Text-to-speech voice synthesis, used only when you select an ElevenLabs voice
ElevenLabs
Text-to-speech voice synthesis, used only when you select an ElevenLabs voice
Data Shared:
- The AI's response text, converted to spoken audio and processed transiently
Security:
SOC 2 Type II. Content excluded from model training under the enterprise API terms.
Cartesia
Text-to-speech voice synthesis, used only when you select a Cartesia voice
Cartesia
Text-to-speech voice synthesis, used only when you select a Cartesia voice
Data Shared:
- The AI's response text, converted to spoken audio and processed transiently
Security:
Content processed transiently for synthesis and excluded from model training.
Anthropic
Internal tooling only, such as drafting assistance. Never part of the live call path.
Anthropic
Internal tooling only, such as drafting assistance. Never part of the live call path.
Data Shared:
- Text-only content for the specific tool invocation
Security:
SOC 2 Type II. API content excluded from training. Excluded from HIPAA-enabled workspaces.
Infrastructure
Vercel
Application hosting and encrypted file storage (Vercel Blob)
Vercel
Application hosting and encrypted file storage (Vercel Blob)
Data Shared:
- Application traffic served through our hosting
- Call recordings, voicemail audio, and uploaded files stored in Vercel Blob
Security:
SOC 2 Type II. Encrypted at rest, hosted in US regions on AWS.
Neon
Managed Postgres, the primary data store
Neon
Managed Postgres, the primary data store
Data Shared:
- Account data, workspace content, contact records, call metadata, and transcripts
Security:
SOC 2 Type II, GDPR compliant. Encrypted at rest with automated encrypted backups.
Upstash
Managed Redis used as a cache for dashboard counters and rate limiting
Upstash
Managed Redis used as a cache for dashboard counters and rate limiting
Data Shared:
- Aggregate counters and short-lived cache keys. No call content is cached.
Security:
SOC 2 Type II. Encrypted in transit and at rest.
Trigger.dev
Background job orchestration for scheduled and asynchronous work
Trigger.dev
Background job orchestration for scheduled and asynchronous work
Data Shared:
- Job payloads for the tasks being run, which can include contact identifiers and message content
Security:
SOC 2 Type II. Payloads are retained only for the job-run history window.
Sentry
Error and performance monitoring
Sentry
Error and performance monitoring
Data Shared:
- Stack traces, request context, and diagnostic metadata
- Identifiers such as a user or organization id where they appear in an error's context
Security:
SOC 2 Type II. Configured to scrub credentials and request bodies from captured events.
Business operations
Stripe
Payment processing and subscription billing
Stripe
Payment processing and subscription billing
Data Shared:
- Payment card information, stored by Stripe and never by us
- Billing address and email
Security:
PCI DSS Level 1 certified.
PostHog
Product analytics for the marketing site and the application
PostHog
Product analytics for the marketing site and the application
Data Shared:
- Product usage events, pages viewed, and features used
- Browser, device, and approximate location derived from IP
- A pseudonymous identifier, and the account identifier once you are signed in
Security:
SOC 2 Type II. No call audio, transcript, or message content is sent to PostHog.
FullEnrich
Contact and company data enrichment, used only when you run enrichment on a contact
FullEnrich
Contact and company data enrichment, used only when you run enrichment on a contact
Data Shared:
- The contact identifiers you submit for enrichment, such as name, company, and domain
- Enriched business-contact attributes are returned to us and cached against your contact record
Security:
Enrichment runs only on your instruction. Because enrichment returns data sourced from third parties, see the enrichment note on the sub-processor page for your notice obligations.
Contact Enrichment
FullEnrich is different from every other entry on this list, and deserves to be called out separately. Every other sub-processor receives data you already hold. Enrichment acquires new personal data about a person from third-party sources and returns it to your workspace.
Enrichment runs only when you ask for it, on the contacts you select. But because the resulting data was not collected from the individual directly, running enrichment can trigger obligations that are yours as the controller, not ours as the processor.
Your obligations when you enrich a contact
- Under GDPR Article 14, where personal data is not obtained from the data subject, you must generally inform them within a reasonable period, and identify the categories of data and its source.
- You must have a lawful basis for the enrichment itself, not only for holding the original contact record.
- Enriched attributes are subject to the same access, correction, and deletion rights as any other personal data you hold about that person.
Enriched attributes are cached against your contact record so a repeat lookup does not re-query the provider. Deleting the contact deletes the cached enrichment with it.
HIPAA-Enabled Workspaces
Workspaces with HIPAA mode enabled run against a restricted subset of this list. Turning HIPAA mode on limits AI model routing to providers covered by a Business Associate Agreement, blocks installation of integrations that are not BAA-covered, locks the call recording disclosure on, and caps recording retention at 30 days.
Anthropic is used only for internal tooling and never appears in the live call path; it is excluded from HIPAA-enabled workspaces entirely. For the full posture and to request a BAA, see the HIPAA section of our Privacy Policy.
Questions
Questions about a sub-processor, a transfer mechanism, or an objection to a planned change go to privacy@revdesk.com. Certifications and audit reports are available through the RevDesk Trust Center.