# Klientify subprocessor register

Version: 1.1
Last updated: August 20, 2026

This register identifies providers that may process personal data for Klientify. A provider only receives the categories required for the enabled feature. Optional providers do not receive data when their feature is not enabled.

| Provider | Purpose | Data categories | Processing / transfer note | Status |
| --- | --- | --- | --- | --- |
| Convex | Application backend and database | Account, user, customer, booking, communication, operational, transaction, and security data | Vendor terms include international-transfer safeguards; production region and account evidence are maintained internally | Active |
| Vercel | Web hosting and deployment | Request metadata, build/deployment data, and files routed through enabled services | Primary processing may occur in the United States under the vendor DPA | Active |
| Stripe | SaaS billing, merchant checkout, and payment processing | Billing contacts, transaction data, merchant account data, and customer payment metadata | Stripe may also act as an independent controller for parts of payment processing; entity and transfers depend on account region | Active |
| PostHog | Consent-gated product analytics | Technical and usage events; Direct private URLs are excluded | EU host configured; current implementation uses in-memory browser persistence | Active when analytics consent is granted |
| UseSend | Transactional email | Recipient email, message content, and delivery metadata | Production use must not continue without contractual processing terms or a suitable replacement | Active; DPA evidence outstanding |
| Resend | Voice-related or other transactional email | Recipient email, message content, call summary or transcript where configured, and delivery metadata | Used only for the enabled delivery route under the vendor DPA and transfer safeguards | Optional |
| Retell AI | Klientify Voice calls and voice-AI processing | Phone numbers, voice, call content and metadata, transcripts, summaries, analysis, and recordings where enabled | US provider; processing and transfers are governed by the Retell DPA and applicable transfer safeguards | Active for Klientify Voice |
| SMSAPI | SMS delivery | Phone number, message content, sender, and delivery metadata | Direct subprocessor only when Klientify supplies the account; a customer-controlled account is the customer's integration | Active when a Klientify-supplied SMS account is enabled |
| Twilio | Telephony or messaging | Phone number, message/call content and metadata | Direct subprocessor only when Klientify supplies the account; if used only within Retell it remains in Retell's provider chain, and a customer-controlled account is the customer's integration | Optional |
| Fly.io | Hosting the Klientify-operated AI assistant service | Assistant requests and responses, selected application context, identifiers, and technical metadata | The production Machine is in Stockholm; Fly.io is a US provider and uses international subprocessors under its DPA and transfer safeguards | Active when the AI assistant is enabled |
| OpenAI | AI text/image generation and assistant inference/embeddings | Prompts, supplied context, generated output, and technical metadata | Only for enabled AI features; customers must not submit restricted sensitive data | Optional |
| Google | Calendar and Meet integration | Connected-user identity, OAuth scopes/tokens, booking and calendar-event details | Only after a user connects Google; OAuth tokens are encrypted at rest in Klientify | Optional |

The Klientify AI assistant service itself is a Klientify-operated internal component, not a separate subprocessor. Fly.io and OpenAI are the external providers used by that component.

## Changes and objections

Klientify gives customers at least 15 days' advance notice before an intended addition or replacement of a subprocessor, unless an urgent security or legal circumstance makes advance notice impracticable. During that period, a customer may object on reasonable data-protection grounds by emailing contact@klientify.me. The process and remedies are set out in the Klientify DPA.

## Contact

Questions, objections, and requests for supporting transfer or DPA information: contact@klientify.me.
