DRAFT — pending legal review

This page is a starting draft written from standard B2B SaaS templates plus Adoomi-specific facts. It has NOT been reviewed by a qualified lawyer or a paid legal-template service. Do not rely on it for compliance until the draft banner is removed. Karim is in the process of engaging counsel (or a service like Termly / iubenda) to sign these off.

Sub-processors

Third parties Adoomi relies on to deliver the service

Last updated: 29 September 2026

Adoomi engages the sub-processors listed below to deliver the service. Each is bound by a data processing agreement (DPA) or equivalent terms. We publish this list publicly so customers acting as data controllers can satisfy GDPR Art 28(2) transparency obligations.

We’ll update this page whenever a sub-processor is added or removed. For notification of changes, follow our changelog or email privacy@adoomi.ai.

Current sub-processors

Sub-processorPurposeData categoriesLocationPrivacy link
SupabasePrimary database, authentication, vector indexesAccount data, bot configurations, knowledge sources, chat transcriptsEU (Ireland)Privacy ↗
CloudflareEdge workers (chat + ingest + cron), widget hosting, DNS, CDNIP addresses, request metadata, transient chat payloads in flightGlobal edge network; a request may be handled nearest the visitorPrivacy ↗
VercelDashboard + marketing site hosting; scheduled email and webhook jobsIP addresses, request metadata, web vitals; account and workspace data (including chat transcripts, lead details, uploaded knowledge files and data exports) processed in transit by server functions, not storedUS (Washington, D.C.) for app runtime; global edge for static assetsPrivacy ↗
AnthropicDefault LLM provider (Claude) for bot responsesEnd-user chat messages + your knowledge content sent at inference time (no training on customer data per Anthropic API terms)US company; a request may be processed in the US or in any other region where Anthropic runs its modelsPrivacy ↗
OpenAIEmbeddings for every assistant — each visitor message and your knowledge content are converted to vectors for search; optional LLM provider (GPT) when selected by youChat messages + content sent at inference / embedding time (no training)US (via OpenAI API; no regional processing constraint)Privacy ↗
PerplexityOptional LLM provider (Sonar Pro, search-grounded) — only when a workspace selects a Perplexity modelChat messages and retrieved knowledge context for workspaces that choose this modelUnited States; selectable per workspace, never a defaultPrivacy ↗
FirecrawlCrawling your public website to build initial knowledge basePublic URLs you submit + scraped page content (public web pages only)USPrivacy ↗
StripePayment processing, subscription billingBilling email, card token, subscription metadataIreland (Stripe Payments Europe, Limited, our contracting entity); data is also transferred to Stripe, LLC in the US and to Stripe affiliates elsewherePrivacy ↗
ResendTransactional + notification email deliveryRecipient email + display name + email body (transactional only)EU + US (Resend uses AWS regions)Privacy ↗
SentryError tracking + performance monitoringError stack traces, request metadata, breadcrumbs. No conversation content or PII in logs per policy.EU (Frankfurt)Privacy ↗
Better StackStructured log aggregationApplication logs (no message bodies, no PII per logging convention)EUPrivacy ↗
MailSlurpEnd-to-end smoke testing — receives test emails in CI / dev onlyTest inbox addresses only. No customer data. Used only by Adoomi engineering smoke tests.US (test-only inbox)Privacy ↗

International transfers

Where a sub-processor processes data outside the EU/UK (OpenAI, Firecrawl, Perplexity, Resend, Vercel and Stripe in the US, and Anthropic in the US or any other region where it runs its models), transfers rely on Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework. Customer-content transfers to LLM providers are limited to the message + knowledge context sent at inference time. Anthropic, OpenAI and Perplexity do not retain API content for model training per their API terms.

How we notify of changes

We aim to add sub-processors to this page at least 14 days before they begin processing customer data, where commercially reasonable. Email privacy@adoomi.ai with subject “subscribe sub-processor updates” to receive these notifications by email instead of monitoring this page.

Auditing

Customers acting as data controllers may audit our sub-processor arrangements as contemplated by GDPR Art 28(3)(h). Email privacy@adoomi.ai to coordinate.