Sub-processors
PelagosAgent runs the platform on behalf of each business client. The client is the organisation its customers are dealing with; we are the client's data intermediary. Everyone in the table below sits underneath us, and we tell clients before adding or replacing a provider.
(content) marks a party that can see the actual words a customer typed.
The register
| Sub-processor | What it does for us | What it receives | Where it runs |
|---|---|---|---|
| DigitalOcean | Hosts the agent inbox, the automation engine and their database | Everything operational: conversations, contacts, bookings, escalation logs (content) | Singapore |
| Cloudflare | DNS, content delivery, firewall and access control in front of those servers; the servers accept traffic only from Cloudflare | Request metadata; message content in transit (content) | Global edge network |
| Supabase | The product database: bookings, contacts, tenant configuration, templates, escalation records | Contact names and phone numbers, booking details, escalation records containing message excerpts (content) | Singapore (AWS ap-southeast-1) |
| Meta Platforms (WhatsApp Cloud API) | Carries the messages themselves; this is WhatsApp | Phone numbers, profile names, full message content (content) | Meta's global infrastructure |
| Google (Gemini API) | Retrieves the relevant part of the client's knowledge base and generates replies | The customer's message plus the retrieved knowledge-base context (content) | United States |
| OpenAI (API) | Language model used in the reply pipeline | The customer's message, sent for inference (content) | United States |
| OpenRouter | Routes part of the reply pipeline to a language-model provider | The customer's message, sent for inference (content) | United States |
| Google (Firebase Cloud Messaging) | Delivers push notifications to the staff app on Android | Device push tokens; notification payloads (sender name and a preview of the message) | Google global |
| Apple (Push Notification service) | Delivers push notifications to the staff app on iOS, once the iOS app is released | Device push tokens; notification payloads | Apple global |
Present in the app but not receiving data
Sentry (crash reporting). The staff apps contain the Sentry library, but released builds are not configured with a reporting endpoint, so nothing is sent. If that changes, Sentry will move into the table above before the release ships, and the app privacy policy describes the on-device scrubbing that will apply.
Not used
No analytics SDK, advertising SDK, session-replay tool or CRM is in the path. If one is ever added, it belongs in the table above before it ships.
Transfers outside Singapore
Two categories of data leave Singapore:
- Message content, to the United States, for AI inference. Every customer message the assistant answers is sent to the AI providers above. This is the core of how the product works; it cannot be switched off without switching off the assistant.
- Push notification payloads, to Google's and Apple's push services, so staff phones can be alerted.
Singapore's Personal Data Protection Act (section 26) allows a transfer out of Singapore only where the recipient is bound to a comparable standard of protection. The safeguard relied on is contractual: each provider's data-processing terms, accepted when the account was created. Prompts and responses sent to the AI providers are handled under those providers' API terms, which do not permit use of API content for model training by default.
Keeping this list true
- A new third party goes in this table before it starts receiving data.
- Clients are told before a sub-processor is added or changed, so they can raise an objection; the mechanism and notice period are in the Data Processing Addendum.
- The register is re-checked whenever the automation changes which model or service it calls.
Contact
Questions about this list: [email protected].