Sub-processor List
A "sub-processor" is a third-party company that Call-e uses to help deliver the Services and that may process customer data on our behalf (for example, the cloud that stores recordings, or the AI provider that generates notes). We publish this list so customers know exactly who is in the chain of custody for their data and on what terms. Our Data Processing Addendum (DPA) incorporates this list, and we will give notice before adding a new sub-processor so customers can review it. To be notified of changes to this list, contact us at privacy@call-e.io.
We require every sub-processor, by written contract, to: (a) protect the confidentiality and security of customer data; (b) process it only to provide their service to us; and (c) not use customer data to train their own publicly available AI models.
Infrastructure & platform
| Sub-processor | Purpose | Data processed | Region |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, file storage, and transactional email | All application data; recordings, transcripts, attachments; invitation emails | US (Oregon) |
| Vercel | Frontend application hosting / delivery | Application content; request logs | US / global CDN |
AI & transcription
| Sub-processor | Purpose | Data processed | Trains on your data? | Region |
|---|---|---|---|---|
| AssemblyAI | Speech-to-text transcription and speaker labeling | Meeting audio; resulting transcripts | No — contractually prohibited | US |
| OpenAI | AI generation (notes, scorecards, guidance) | Transcript text and assembled prompts | No — contractually prohibited | US |
| Anthropic | AI generation (notes, scorecards, guidance) | Transcript text and assembled prompts | No — contractually prohibited | US |
| Google (Generative AI) | AI generation (notes, scorecards, guidance) | Transcript text and assembled prompts | No — contractually prohibited | US |
We use one or more of OpenAI, Anthropic, and Google for AI generation.
Identity, integrations & operations
| Sub-processor | Purpose | Data processed | Region |
|---|---|---|---|
| Auth0 (Okta) | Authentication and identity | User name, email, sign-in events | US |
| Zoom | Meeting creation and recording retrieval | Meeting metadata; connection credentials; recordings retrieved for processing | Zoom data centers |
| Recall.ai | Meeting recording via the notetaker bot, where the customer uses it | Meeting audio/video captured by the bot; meeting metadata | US |
| GoHighLevel | CRM context sync (read-only) where a customer connects it | Contact details and message context the customer chooses to connect | Vendor-managed |
| Inngest | Background job orchestration for our processing pipeline | Job and event metadata (identifiers only) | US |
| Datadog | Logging, monitoring, and product analytics | Application logs; product usage and session recordings; user name and email | US |
| PostHog | Product analytics and session replay | Product usage and session recordings; user name and email | US |
| Statsig | Feature management / configuration | User and organization identifiers | US |
| Pylon | In-app customer support chat | User name and email | US |
| Stripe | Billing and payments | Billing contact name and email; payment method and transaction data | US |