PelagosAgent

Sub-processors

Third parties that handle personal data when the PelagosAgent platform runs · Last updated 22 September 2026

PelagosAgent runs the platform on behalf of each business client. The client is the organisation its customers are dealing with; we are the client's data intermediary. Everyone in the table below sits underneath us, and we tell clients before adding or replacing a provider.

(content) marks a party that can see the actual words a customer typed.

The register

Sub-processorWhat it does for usWhat it receivesWhere it runs
DigitalOceanHosts the agent inbox, the automation engine and their databaseEverything operational: conversations, contacts, bookings, escalation logs (content)Singapore
CloudflareDNS, content delivery, firewall and access control in front of those servers; the servers accept traffic only from CloudflareRequest metadata; message content in transit (content)Global edge network
SupabaseThe product database: bookings, contacts, tenant configuration, templates, escalation recordsContact names and phone numbers, booking details, escalation records containing message excerpts (content)Singapore (AWS ap-southeast-1)
Meta Platforms (WhatsApp Cloud API)Carries the messages themselves; this is WhatsAppPhone numbers, profile names, full message content (content)Meta's global infrastructure
Google (Gemini API)Retrieves the relevant part of the client's knowledge base and generates repliesThe customer's message plus the retrieved knowledge-base context (content)United States
OpenAI (API)Language model used in the reply pipelineThe customer's message, sent for inference (content)United States
OpenRouterRoutes part of the reply pipeline to a language-model providerThe customer's message, sent for inference (content)United States
Google (Firebase Cloud Messaging)Delivers push notifications to the staff app on AndroidDevice push tokens; notification payloads (sender name and a preview of the message)Google global
Apple (Push Notification service)Delivers push notifications to the staff app on iOS, once the iOS app is releasedDevice push tokens; notification payloadsApple global

Present in the app but not receiving data

Sentry (crash reporting). The staff apps contain the Sentry library, but released builds are not configured with a reporting endpoint, so nothing is sent. If that changes, Sentry will move into the table above before the release ships, and the app privacy policy describes the on-device scrubbing that will apply.

Not used

No analytics SDK, advertising SDK, session-replay tool or CRM is in the path. If one is ever added, it belongs in the table above before it ships.

Transfers outside Singapore

Two categories of data leave Singapore:

Singapore's Personal Data Protection Act (section 26) allows a transfer out of Singapore only where the recipient is bound to a comparable standard of protection. The safeguard relied on is contractual: each provider's data-processing terms, accepted when the account was created. Prompts and responses sent to the AI providers are handled under those providers' API terms, which do not permit use of API content for model training by default.

Keeping this list true

Contact

Questions about this list: [email protected].