Legal
Subprocessors
Last updated: April 19, 2026
Anvil uses the following third-party service providers (“subprocessors”) to deliver the Service. Each is bound by a data-processing agreement and appropriate transfer safeguards. Enterprise customers receive at least 30 days’ notice of any material change before it takes effect; email 738888@proton.me to subscribe to the change feed.
| Provider | Purpose | Data processed | Location | Safeguard |
|---|---|---|---|---|
| Cloudflare, Inc. ↗ | DNS, CDN, WAF, DDoS protection | IP address, request metadata, headers | Global (edge locations) | EU SCCs · ISO 27001 · SOC 2 Type II |
| Stripe Payments Europe, Ltd. ↗ | Payment processing, subscription billing, invoicing | Name, email, billing address, card metadata (card number NOT shared with Anvil) | Ireland (EU) with US transfer under DPF | EU SCCs · DPF · PCI-DSS Level 1 |
| Resend, Inc. ↗ | Transactional and marketing email delivery | Recipient email, email content, open/click events | United States | EU SCCs · DPF |
| 杭州深度求索人工智能基础技术研究有限公司 (DeepSeek) ↗ | AI inference for chat, agent, reasoning, discovery, lead analysis, reply classification, and composition (deepseek-v4-pro and deepseek-v4-flash) | Only the fields you send to an AI feature (website text, prospect metadata, message bodies). Not used for training under DeepSeek API data usage policy. | China (Hangzhou) | PIPL standard contract · zero-retention mode available on Enterprise |
| OpenAI, LLC ↗ | Embedding generation only (text-embedding-3-small, 1536-dim) for RAG indexing. Scope reduced from prior chat/agent inference; chat and reasoning are now served by DeepSeek. | Text fragments submitted for vector embedding (knowledge-base chunks, prospect snippets). Not used for training under OpenAI API data usage policy. | United States | EU SCCs · zero-retention mode available on Enterprise |
| Google LLC ↗ | Google OAuth (sign-in), Google Calendar sync, optional Places / Maps API | Google account email, name, profile photo, calendar events (only when user connects Calendar) | United States | EU SCCs · DPF · ISO 27001 |
| Meta Platforms Ireland, Ltd. ↗ | WhatsApp Business Cloud API (only when user connects a WhatsApp channel) | Phone numbers, message content, delivery events | Ireland (EU) with US transfer under SCCs | EU SCCs |
| Twilio, Inc. ↗ | Telephony (outbound voice), SMS (optional features) | Phone numbers, call metadata, call recordings (if enabled), SMS content | United States | EU SCCs · DPF · ISO 27001 |
| ElevenLabs, Inc. ↗ | AI text-to-speech for voice outreach (optional) | Script text, voice samples (if cloning) | United States | EU SCCs |
| Sentry, Inc. ↗ | Error monitoring and application performance | Error traces, IP (scrubbed), request path. PII is filtered before transmission. | United States | EU SCCs · DPF |
| GitHub, Inc. ↗ | Source-code hosting (our code; no customer content) | None (source code only) | United States | EU SCCs · ISO 27001 |
| OpenStreetMap Foundation ↗ | Public business directory lookups (Nominatim, Overpass) | Query terms (e.g. "restaurants in Berlin"); no personal data | United Kingdom, Germany | Public-interest API under OSM Foundation DPA |
Change notifications
We maintain a mailing list that receives advance notice of every subprocessor addition, removal, or material change. If you object to a proposed change within 30 days, you may terminate your affected subscription and receive a pro-rated refund. Email 738888@proton.me with the subject “Subprocessor updates” to subscribe.
Sub-sub-processors
The providers listed above may in turn engage their own subprocessors (for example, cloud hosting under them). Each provider publishes its own list; links above lead to their current disclosures.