DRAFT — pending legal review

This page is a starting draft written from standard B2B SaaS templates plus Adoomi-specific facts. It has NOT been reviewed by a qualified lawyer or a paid legal-template service. Do not rely on it for compliance until the draft banner is removed. Karim is in the process of engaging counsel (or a service like Termly / iubenda) to sign these off.

Sub-processors

Third parties Adoomi relies on to deliver the service

Last updated: 11 June 2026

Adoomi engages the sub-processors listed below to deliver the service. Each is bound by a data processing agreement (DPA) or equivalent terms. We publish this list publicly so customers acting as data controllers can satisfy GDPR Art 28(2) transparency obligations.

We’ll update this page whenever a sub-processor is added or removed. For notification of changes, follow our changelog or email privacy@adoomi.ai.

Current sub-processors

Sub-processorPurposeData categoriesLocationPrivacy link
SupabasePrimary database, authentication, vector indexesAccount data, bot configurations, knowledge sources, chat transcriptsEU (Frankfurt + Ireland)Privacy ↗
CloudflareEdge workers (chat + ingest + cron), widget hosting, DNS, CDNIP addresses, request metadata, transient chat payloads in flightGlobal edge; data processing pinned to EUPrivacy ↗
VercelDashboard + marketing site hostingIP addresses, request metadata, web vitalsEU (Frankfurt) for app runtime; global edge for static assetsPrivacy ↗
AnthropicDefault LLM provider (Claude) for bot responsesEnd-user chat messages + your knowledge content sent at inference time (no training on customer data per Anthropic API terms)US (via Anthropic API). EU residency option in progress.Privacy ↗
OpenAIOptional LLM provider (GPT) when configured by you; embeddingsChat messages + content sent at inference / embedding time (no training)EU (Ireland) for inference; global for some auxiliary servicesPrivacy ↗
DeepSeekOptional LLM provider (DeepSeek V4 Flash) — only when a workspace selects a DeepSeek modelChat messages and retrieved knowledge context for workspaces that choose this modelPRC (Hangzhou); selectable per workspace, never a defaultPrivacy ↗
PerplexityOptional LLM provider (Sonar Pro, search-grounded) — only when a workspace selects a Perplexity modelChat messages and retrieved knowledge context for workspaces that choose this modelUnited States; selectable per workspace, never a defaultPrivacy ↗
FirecrawlCrawling your public website to build initial knowledge basePublic URLs you submit + scraped page content (public web pages only)USPrivacy ↗
StripePayment processing, subscription billingBilling email, card token, subscription metadataEU (Ireland)Privacy ↗
ResendTransactional + notification email deliveryRecipient email + display name + email body (transactional only)EU + US (Resend uses AWS regions)Privacy ↗
SentryError tracking + performance monitoringError stack traces, request metadata, breadcrumbs. No conversation content or PII in logs per policy.EU (Frankfurt)Privacy ↗
Better StackStructured log aggregationApplication logs (no message bodies, no PII per logging convention)EUPrivacy ↗
MailSlurpEnd-to-end smoke testing — receives test emails in CI / dev onlyTest inbox addresses only. No customer data. Used only by Adoomi engineering smoke tests.US (test-only inbox)Privacy ↗

International transfers

Where a sub-processor processes data outside the EU/UK (Anthropic, OpenAI auxiliary services, Firecrawl and Perplexity in the US), transfers rely on Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework. Customer-content transfers to LLM providers are limited to the message + knowledge context sent at inference time. Anthropic, OpenAI and Perplexity do not retain API content for model training per their API terms.

DeepSeek (PRC) is different in kind and is treated accordingly: it is never a default, never used for embeddings or background processing, and only receives content for workspaces whose owner explicitly selects a DeepSeek model in the dashboard. Transfers occur under DeepSeek’s API data terms. Workspaces with strict EU-only or no-PRC-transfer requirements should simply not select DeepSeek models — every other part of the service is unaffected by this option existing.

How we notify of changes

We aim to add sub-processors to this page at least 14 days before they begin processing customer data, where commercially reasonable. Email privacy@adoomi.ai with subject “subscribe sub-processor updates” to receive these notifications by email instead of monitoring this page.

Auditing

Customers acting as data controllers may audit our sub-processor arrangements as contemplated by GDPR Art 28(3)(h). Email privacy@adoomi.ai to coordinate.