What this page is
MairyAI uses the third-party providers below to deliver the Service. Each one is a subprocessor under our Data Processing Addendum ("DPA"). Each is bound by a written contract requiring protections at least as strong as our DPA, including the prohibition on using customer content to train AI models and on selling or sharing personal information. MairyAI remains fully responsible to our customers for each subprocessor's performance.
We give customers at least 30 days' notice before adding or replacing a subprocessor that will process customer personal information. To receive those notices, email support@mairyai.com. Customers may object on reasonable data-protection grounds, as described in Section 6 of the DPA.
Current subprocessors
Core call handling
These providers are in the live call path. A call cannot be answered without them.
| Provider | Role in the Service | Data it receives | Processing location |
|---|---|---|---|
| Twilio Inc. | Telephony and messaging infrastructure. Carries the inbound telephone call, provides the telephone number, and streams call audio to and from the Service. Messaging is not offered under the launch plan and no message is sent or received on your behalf. | Caller telephone number, number called, call time and duration, call audio during the call, call status metadata. | United States, with global carrier interconnection |
| OpenAI, L.L.C. | AI language processing — understands what the caller says and generates the assistant's replies, summaries, and qualification results. | The text of what the caller says and the conversation context needed to respond. | United States configured where offered |
| ElevenLabs Inc. | Speech synthesis — converts the assistant's replies into spoken audio. | The text the assistant is about to say. Not caller audio. | United States configured where offered |
| RunPod, Inc. | GPU compute — hosts the speech and voice models used to process and produce call audio. | Call audio and text in transit during processing. | United States regions |
Model training is off, and that is a commitment we make to you.
- OpenAI — used on API terms. Under the OpenAI API data-usage policy, content submitted through the API is not used to train OpenAI models by default. API content may be retained for a limited period for abuse and misuse monitoring.
- ElevenLabs — used on paid API terms with the no-training configuration available at our tier, so text submitted for synthesis is not used to train ElevenLabs models.
- RunPod — provides raw GPU compute for models we run. It is infrastructure, not a model provider, and has no model-training interest in the content.
These are the terms we rely on to make the commitment in the Privacy Policy. If a provider changed them, we would move providers or tell customers before anything changed — we would not weaken the commitment quietly. Confirm each provider's current policy version and abuse-retention window before this page is published, and re-confirm at each subprocessor review.
Platform infrastructure
| Provider | Role in the Service | Data it receives | Processing location |
|---|---|---|---|
| Render Services, Inc. | Application hosting — runs the MairyAI web application, API, and background workers, and hosts the managed database. | All customer and call data stored by the Service, encrypted at rest. | United States |
| Cloudflare, Inc. | Network routing, DNS, TLS termination, DDoS protection, and object storage for stored call recordings, transcripts, and generated exports. | Web request metadata and IP addresses; encrypted stored call content where recording or transcripts are enabled. | United States, with global edge routing |
Account, billing, and operations
| Provider | Role in the Service | Data it receives | Processing location |
|---|---|---|---|
| Okta, Inc. (Auth0) | Authentication — signs users in to the dashboard and manages sessions and multi-factor authentication. | Customer user email address, name, authentication events, IP address. No caller data. | United States |
| Stripe, Inc. | Payment processing — hosted checkout, subscriptions, invoices, and the billing portal. | Billing contact name, email, billing address, payment card details (collected by Stripe directly — MairyAI never receives full card numbers), subscription and invoice records. No caller data. | United States |
| Functional Software, Inc. (Sentry) | Error monitoring — captures application errors and performance data so we can find and fix faults. | Technical error data, stack traces, request metadata, and user or workspace identifiers. Configured to scrub personal information and call content. Should receive no caller data. | United States |
| ActiveCampaign, LLC (Postmark) | Transactional email — sends account, billing, security, and notification emails. | Recipient email address and the content of the email sent, which may include call notification summaries where the customer enables them. | United States |
Customer-connected integrations
| Provider | Role in the Service | Data it receives | Processing location |
|---|---|---|---|
| Google LLC | Calendar integration — creates, updates, and reads appointments in a Google Calendar account the customer connects. | Appointment details, including the caller's name, telephone number, and the reason for the appointment as captured on the call. | United States / Google global infrastructure |
Customer-connected integrations are different. Google Calendar is used only when a customer connects their own Google account, and the data written there lands in a system the customer controls. The customer's agreement with Google governs it, and deleting data from MairyAI does not delete appointments already written into the customer's calendar. The customer must delete those separately.
About the "processing location" column
Read this column as where each provider is configured to process, not as a guarantee.
- Storage is United States-based. Our databases, stored recordings and transcripts, and backups sit in United States regions.
- Transit and edge processing are not. Cloudflare operates a global edge network, so encrypted traffic and stored objects may be routed through or cached at locations outside the United States. Twilio interconnects with global carriers.
- Some providers do not offer a region guarantee at our tier. Where a United States region is offered we configure it; where it is not, the provider's own terms govern.
- Support and engineering access may come from outside the United States under a provider's standard terms.
MairyAI does not offer data residency guarantees. A customer with a contractual United States-only processing requirement should raise it before signing up, because we cannot meet it at launch. This matches Section 9 of the Privacy Policy and Section 5.1 of the DPA.
What is not on this list
- Messaging. SMS, MMS and WhatsApp are not offered under the launch plan. Twilio appears above as telephony infrastructure; no messaging channel is enabled and no message is sent on a customer's behalf.
- We do not use advertising networks, data brokers, or marketing analytics providers that receive personal information.
- We do not sell personal information or share it for cross-context behavioral advertising.
- Providers that never receive customer personal information — such as source-control, internal documentation, or developer tooling — are not subprocessors and are not listed.
- Our own affiliates and contractors, who are bound by the same obligations as our employees.
Data flow in one paragraph
A caller dials the customer's number. Twilio carries the call and streams the audio. Speech models on RunPod convert what the caller says to text. OpenAI decides how to respond. ElevenLabs turns that response into speech, which Twilio plays back to the caller. After the call, the structured result — metadata, summary, outcome, booking — is stored by the application on Render, behind Cloudflare. If the customer enabled recording or transcripts, that content is encrypted and stored in Cloudflare object storage. If a booking was made, it is written to the customer's Google Calendar. The customer signs in through Okta/Auth0 to see the result, pays through Stripe, receives notifications through Postmark, and any application errors along the way are reported to Sentry.
Contact
Questions about this list: support@mairyai.com Subprocessor objections: support@mairyai.com, per Section 6 of the DPA.