Sub-processors.
Every third party that processes your data when you use AIVA. We list all of them, what they do, where they sit, and how they're certified — so your security review can be done in an afternoon, not a month.
The short version, before the table:
- We use 20 sub-processors total. Every one is named below, with purpose and region.
- Customer data stays in the EU (Frankfurt) by default unless you opt in to US routing.
- AI model providers (OpenAI, Anthropic) run under zero-data-retention contracts — your data is never used to train models.
- We give 30 days' notice before adding or replacing a sub-processor. You can object — see section 06.
- This list is updated within 7 days of any change. Subscribe to the change feed and we'll email you.
Core infrastructure.
These vendors run the platform itself — hosting, observability, billing, transactional email. None of them have access to your conversation content; only AWS (encrypted at rest, encryption keys held by us) and Sentry (with PII scrubbing) touch it incidentally.
| Sub-processor | Purpose | Region | Certifications |
|---|---|---|---|
| Amazon Web Services | Application hosting, primary database, object storage | EU (Frankfurt), US (Virginia) | SOC 2 · ISO 27001 · HIPAA |
| Cloudflare | CDN, DDoS protection, edge cache | Global | SOC 2 · ISO 27001 |
| Stripe | Payment processing, billing, subscriptions | US, EU (Ireland) | PCI DSS · SOC 2 |
| Sentry | Error tracking and performance monitoring | EU (Frankfurt) | SOC 2 · ISO 27001 |
| Plausible Analytics | Cookieless website analytics — aggregate only, no session replay or personal data | EU (Germany) | GDPR-compliant · EU-hosted |
| Postmark | Transactional email delivery | US | SOC 2 |
Voice & SMS.
These carriers route messages and calls between you, your customers, and AIVA. They see message content in transit — same as any other telecom carrier — but never store it longer than required by their own retention windows (typically 7–30 days, configurable).
Speech-to-text (Deepgram) and text-to-speech (ElevenLabs) operate on audio streams in real time. Audio is not retained for training under our contracts with either vendor.
| Sub-processor | Purpose | Region | Certifications |
|---|---|---|---|
| Twilio | Voice calls, SMS | US, EU (Ireland) | SOC 2 · ISO 27001 · HIPAA · PCI |
| Plivo | Voice & SMS — Indian carrier routing | India, US | SOC 2 · ISO 27001 |
| Exotel | Indian voice & SMS — Tier 1 carrier routing | India | ISO 27001 · CMMI L5 |
| Deepgram | Speech-to-text (transcription for voice) | US | SOC 2 · HIPAA |
| ElevenLabs | Text-to-speech (AIVA voice synthesis) | US, EU | SOC 2 |
AI model providers.
These vendors host the foundation models AIVA uses for reasoning, retrieval, and generation. OpenAI and Anthropic run under zero-data-retention contracts — your inputs and outputs are not stored, logged for training, or accessible to vendor staff. The specific data terms for each provider are listed in the table below.
We route conversations to whichever model performs best for your use case. You can request a pin to a specific provider for compliance reasons.
| Sub-processor | Purpose | Region | Certifications |
|---|---|---|---|
| OpenAI | Conversational reasoning (zero-data-retention) | US | SOC 2 — ZDR enabled, no training on customer data |
| Anthropic | Conversational reasoning (zero-data-retention) | US | SOC 2 — ZDR enabled, no training on customer data |
| Voyage AI | Embeddings for retrieval / RAG | US | SOC 2 — no training on customer data |
| Cohere | Re-ranker for retrieval (failover) | US, Canada | SOC 2 |
Internal tools.
AIVA staff use these tools to run the company. They do not process your customers' conversation data — they hold metadata only (your contract terms, our internal tickets, the marketing site).
We list them because some compliance reviews ask. If you don't care about AIVA's internal stack, skip this section.
| Sub-processor | Purpose | Region | Certifications |
|---|---|---|---|
| Google Workspace | Internal email, docs, calendars for AIVA staff | Global | SOC 2 · ISO 27001 · ISO 27017 |
| Linear | Engineering issue tracking (no customer data) | US | SOC 2 |
| GitHub | Source code, deployment, CI | US | SOC 2 · ISO 27001 |
| Vercel | Marketing site (aivachat.io) hosting only | Global | SOC 2 |
| HubSpot | CRM for AIVA sales — never your customer data | EU, US | SOC 2 · ISO 27001 |
How we notify you of changes.
We give 30 days' written notice before adding a new sub-processor or replacing an existing one — sent to the email address on your billing account.
You can also subscribe to the standalone change feed (RSS or email digest). New entries appear here within 7 days of any change.
- Email digest — subscribe via support@aivachat.io
- RSS feed —
aivachat.io/sub-processors/feed.xml - Or follow the changelog — sub-processor changes always appear there too
Your right to object.
If you object to a new sub-processor on reasonable data-protection grounds, you have two options:
- We work with you to find an acceptable alternative — usually we can route around the vendor for affected customers.
- You can terminate without penalty within 30 days of the change going live. We'll refund any pre-paid annual fees pro-rata and help you export your data.
Object by emailing support@aivachat.io. We respond within 5 business days.
This list is governed by the Data Processing Addendum, section 04 (“Sub-processors”). Read that for the full contractual terms.