Virtual Customer
Plans Log in Start free trial

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Notice
  • Data Processing Addendum
  • Workspace User Notice
  • Subprocessor List
  • AI Use Disclosure
  • Acceptable Use Policy
  • Security Overview
  • Refund Policy

Subprocessor List

Provider: Valiquest AB · Org.nr 559577-0347 · Stockholm, Sweden Service: Virtual Customer Version: v2 — 2026-08-14 Public URL: https://app.virtualcustomer.io/legal/subprocessors.html RSS feed: https://app.virtualcustomer.io/legal/subprocessors.rss Subscribe: info@valiquest.com

A "Subprocessor" is a third party that we engage to process Customer Personal Data on our behalf to deliver the Service. We commit to giving customers at least 30 days' notice before adding or replacing a Subprocessor (see DPA §7.1(c)).


How to read this list

For each Subprocessor we publish:

  • Provider — the contracting entity.
  • Service area — what part of Virtual Customer they support.
  • Categories of Personal Data processed — what they actually see.
  • Processing region(s) — where the data lives during processing.
  • Transfer mechanism — applicable when data leaves the EEA.
  • Last reviewed — the date Valiquest last reviewed the Subprocessor's data-protection posture.

If you would like additional detail (audit reports, written contracts, certificates), email info@valiquest.com.


Current and route-dependent Subprocessors (as at 2026-08-14)

"Route-dependent" means that the provider receives Customer Personal Data only when the Customer uses a feature whose configured runtime route calls that provider. The provider is nevertheless listed because that route can be selected in the Service.

1. Google Cloud / Firebase

  • Provider: Google Ireland Limited (EEA contracting entity), with onward processing by Google LLC where required.
  • Service area: Identity, database, file storage, serverless functions, hosting.
  • Categories of Personal Data processed: Account data, Customer Content, application logs.
  • Processing region(s): EU (Belgium, Netherlands) where regional services are available; US fallback for some services (e.g. specific Cloud Functions).
  • Transfer mechanism: EU SCCs 2021/914 (Module Three, Processor → Processor) where data leaves the EEA. Google's Data Processing Addendum applies.
  • Certifications cited by provider: ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, C5. (We rely on Google's own attestation; we do not independently audit.)
  • Last reviewed by Valiquest: 2026-08-14.

2. Railway

  • Provider: Railway Corporation.
  • Service area: Application runtime, container hosting, internal networking.
  • Categories of Personal Data processed: Application logs (which can incidentally contain Customer Content if logged). We mask known secret patterns before logging (see DPA Annex 2 §B).
  • Processing region(s): The selected Railway service region. Provider support, security, and onward processing may occur internationally as described in Railway's DPA.
  • Transfer mechanism: Railway's DPA incorporates the EU SCCs and the UK Addendum for covered transfers.
  • Certifications cited by provider: See Railway's current trust and compliance materials; Valiquest relies on provider attestations and does not independently certify Railway.
  • Last reviewed by Valiquest: 2026-08-14.

3. Stripe / Link

  • Provider: Stripe, including Link — acts as merchant of record for Stripe Managed Payments purchases.
  • Service area: Checkout, subscription billing, invoicing or receipts, tax (VAT / sales tax) handling, refunds, disputes, dunning, and customer billing support for Stripe Managed Payments purchases.
  • Categories of Personal Data processed: Billing email, billing address, tax identifiers if provided at checkout, payment-instrument metadata (Stripe/Link stores card details; Valiquest does not), invoice or receipt history, sales-tax-relevant data.
  • Processing region(s): Regions per Stripe checkout and account configuration.
  • Transfer mechanism: Stripe's applicable DPA, SCCs, and payment-service transfer mechanisms for the relevant contracting entity.
  • Certifications cited by provider: PCI-DSS Level 1, SOC 1/2 where available from Stripe's compliance resources.
  • Last reviewed by Valiquest: 2026-08-14.

4. Flowise

  • Provider: FlowiseAI Inc. (open-source project; we self-host the container, and rely on official builds for updates). Note: where we use the Flowise Cloud control plane, FlowiseAI Inc. is the contracting entity; otherwise no third-party processing occurs from Flowise itself.
  • Service area: Conversational engine container, executed inside our Railway runtime.
  • Categories of Personal Data processed: Customer Content (prompts, transcripts) routed through the conversational engine.
  • Processing region(s): Co-located with our Railway runtime.
  • Transfer mechanism: Same region as Railway; no separate transfer.
  • Certifications cited by provider: None (open-source project; we treat self-hosted Flowise as part of our own runtime).
  • Last reviewed by Valiquest: 2026-08-14.
  • Note: Where Flowise calls out to LLM providers (OpenAI / Anthropic / Google), those calls are listed as separate Subprocessors below.

5. OpenAI

  • Provider: OpenAI Ireland Ltd (EEA contracting entity), with onward processing by OpenAI, L.L.C. (US).
  • Service area: LLM inference for selected conversational and analysis features.
  • Categories of Personal Data processed: Customer Content sent to the model (prompts, conversation context). API tier: OpenAI does not use API inputs or outputs to train models; data is retained for abuse monitoring for up to 30 days unless zero-data-retention has been negotiated.
  • Processing region(s): US (OpenAI does not currently offer in-region EU processing for all API endpoints).
  • Transfer mechanism: EU SCCs 2021/914 (Module Three) via OpenAI's standard DPA.
  • Certifications cited by provider: SOC 2 Type II.
  • Last reviewed by Valiquest: 2026-08-14.

6. Anthropic

  • Provider: Anthropic, PBC (US).
  • Service area: LLM inference for selected conversational and analysis features.
  • Categories of Personal Data processed: Customer Content sent to the model. API tier: Anthropic does not use API inputs or outputs to train models; retention for trust-and-safety monitoring per Anthropic Commercial Terms.
  • Processing region(s): US.
  • Transfer mechanism: EU SCCs 2021/914 (Module Three) via Anthropic's DPA.
  • Certifications cited by provider: SOC 2 Type II.
  • Last reviewed by Valiquest: 2026-08-14.

7. Google AI / Gemini

  • Provider: Google LLC (US) under the Generative AI / Gemini API service. EEA contracting via Google Ireland Limited where applicable.
  • Service area: LLM inference for selected conversational and analysis features.
  • Categories of Personal Data processed: Customer Content sent to the model. Paid tier: Google does not use prompts to train models; retention per Generative AI Terms of Service.
  • Processing region(s): The Google service region and global support/onward-processing footprint described in Google's applicable service terms and DPA; the exact route depends on the selected model endpoint.
  • Transfer mechanism: EU SCCs 2021/914 (Module Three) via Google's DPA.
  • Certifications cited by provider: ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3.
  • Last reviewed by Valiquest: 2026-08-14.

8. LiveKit Cloud

  • Provider: LiveKit, Inc.
  • Service area: Real-time WebRTC audio/data transport, room signalling, session administration, and route-dependent LiveKit Inference fallback.
  • Categories of Personal Data processed: Live audio, transcripts or prompt/output content passed through an enabled inference route, room/session identifiers, connection metadata, and operational logs. Agent observability is a separate configurable feature.
  • Processing region(s): LiveKit's global edge network. Regional routing can be configured; inference requests are processed in LiveKit and the selected underlying model provider's service footprint.
  • Transfer mechanism: LiveKit's DPA and applicable SCCs/UK safeguards for transfers outside the EEA/UK.
  • Operational note: LiveKit documents zero data retention for LiveKit Inference by default; observability retention is separate and must be configured and disclosed according to the active plan.
  • Last reviewed by Valiquest: 2026-08-14.

9. Deepgram (route-dependent)

  • Provider: Deepgram, Inc.
  • Service area: Direct speech-to-text and supported text-to-speech routes.
  • Categories of Personal Data processed: Live or recorded audio sent for transcription or speech generation, generated transcript/text, language and request metadata.
  • Processing region(s): Deepgram's service infrastructure and subprocessors described in its DPA/subprocessor materials.
  • Transfer mechanism: Deepgram's DPA and applicable SCCs/other lawful transfer safeguards.
  • Operational note: Only enabled routes send data to Deepgram; Valiquest does not enable provider model-improvement use for Customer Content where the contracted API/DPA control permits opt-out.
  • Last reviewed by Valiquest: 2026-08-14.

10. ElevenLabs (route-dependent)

  • Provider: ElevenLabs group entity applicable to the account agreement.
  • Service area: Direct text-to-speech for supported voices and languages.
  • Categories of Personal Data processed: Text sent for speech generation, generated audio, voice/language selection, and request metadata. Customer voice cloning is not part of the standard self-service feature.
  • Processing region(s): ElevenLabs' service infrastructure; optional data-residency or zero-retention controls require the corresponding account configuration. International support, moderation, and subprocessors may process outside a selected storage region as described in ElevenLabs' DPA.
  • Transfer mechanism: ElevenLabs' DPA incorporates SCCs and other lawful transfer mechanisms for covered transfers.
  • Last reviewed by Valiquest: 2026-08-14.

11. OpenRouter (route-dependent)

  • Provider: OpenRouter, Inc.
  • Service area: Routes selected pipeline prompts to the configured downstream model provider.
  • Categories of Personal Data processed: Customer Content included in prompts and model outputs, model/provider selection, and request metadata.
  • Processing region(s): United States and the selected downstream model provider's service footprint.
  • Transfer mechanism: OpenRouter's DPA for covered API processing, applicable SCCs, and the selected downstream provider's data-processing terms.
  • Operational note: OpenRouter states that it does not train on API Inputs or Outputs. Downstream model retention/training rules still depend on the selected provider, so Virtual Customer restricts selectable production routes to reviewed providers.
  • Last reviewed by Valiquest: 2026-08-14.

12. Resend (or SendGrid as fallback)

  • Provider (primary): Resend, Inc. (US) — currently configured for transactional email.
  • Provider (fallback): Twilio Inc., d/b/a SendGrid (US) — kept on file in case of provider failure.
  • Service area: Transactional email delivery (invitations, password resets, trial reminders, billing notifications).
  • Categories of Personal Data processed: Recipient email address, recipient name (if included), email body (which may include account references, organisation name, billing details, in some cases links containing tokens).
  • Processing region(s): US.
  • Transfer mechanism: EU SCCs 2021/914 (Module Three) via the provider's DPA.
  • Certifications cited by provider: SOC 2 Type II (Resend); SOC 2 Type II + ISO 27001 (SendGrid).
  • Last reviewed by Valiquest: 2026-08-14.

Subprocessors not yet engaged

The following are commonly asked about but Valiquest does not currently engage them:

  • Mixpanel / Amplitude / PostHog / Hotjar / Segment — no product analytics today.
  • Google Analytics / Google Tag Manager / Facebook Pixel — no marketing analytics today.
  • Intercom / Zendesk / Crisp — no live chat today.
  • Mux / Agora — not used; real-time media is transported through LiveKit Cloud.
  • AWS / Azure — not used as primary infrastructure; only in transit via specific LLM providers above.

If we engage any of these in the future, we will give 30 days' notice via the RSS feed at /legal/subprocessors.rss and via email to subscribers.


Audit log of changes

DateChangeEffective dateNotice given (days)
2026-08-14Added the current voice and routing providers LiveKit Cloud, Deepgram, ElevenLabs, and OpenRouter; removed environment-verification placeholders and distinguished route-dependent processing.2026-08-14 (pre-production legal correction)Pre-production update
2026-06-04Confirmed Stripe/Link as the active merchant-of-record billing provider for Stripe Managed Payments purchases; inactive legacy billing-provider wording removed from the active Subprocessor List.Public Stripe checkout launch (pre-launch update)Pre-launch update
2026-04-22Initial publication (v1).2026-05-1930

When we add, replace, or remove a Subprocessor:

  1. We update this document and re-publish via the public HTML page and RSS feed.
  2. We send a notice to all info@valiquest.com subscribers and to the billing contact for each customer.
  3. Customers may object on legitimate data-protection grounds within the notice window (see DPA §7.1(d)).

Subscribe to changes

  • RSS: add https://app.virtualcustomer.io/legal/subprocessors.rss to your RSS reader.
  • Email: send "Subscribe Subprocessors" to info@valiquest.com. We will also include the billing contact for every paid customer automatically.
© 2026 Valiquest AB · Org.nr 559577-0347 · Strandvägen 61, 191 35 Sollentuna, Sweden
Terms Privacy Cookies DPA Subprocessors AI Use AUP Security Refunds Cookie preferences