Vestibo
All legal documents

Legal

Sub-processors

Sub-processors

Version: v1.0 β€” 2026-07-23 Effective date: 2026-07-23

Some vendors below are optional or "when configured" integrations rather than active on every deployment; those rows are marked (optional / when configured). We list them for transparency even where they are not engaged by default.

Vestibo ("Vestibo") uses a small set of sub-processors to provide the Service. This page is the authoritative list. Customers can subscribe to change notifications by emailing privacy@vestibo.com; we will give at least thirty (30) days' notice before adding or replacing a sub-processor, as set out in Β§ 6 of the DPA.

This list is reviewed and republished at least quarterly.

1. Infrastructure

VendorPurposeData processedRegionDPA / BAA / DPF
Amazon Web Services, Inc. (AWS)Compute, application load balancer (edge / TLS termination), Route 53 (DNS), managed database (RDS Postgres), managed cache (ElastiCache Redis), KMS, CloudWatch, and Amazon SES (transactional email). Object storage (S3) is not currently in use; no Customer Data is stored in S3 today.Account data and conversation data (transcripts, records) in the managed database; email content via SES.us-east-1AWS DPA + SCCs, BAA (HIPAA tier), DPF certified.
Sentry (Functional Software, Inc.)Application error monitoring.Stack traces, request IDs, optionally tenant IDs (no Customer-Content).US (data-residency add-on available for EU).Sentry DPA + SCCs.

2. Large Language Model (LLM) providers

VendorPurposeData processedRegionDPA / BAA / training opt-out
Anthropic, PBCText generation (Claude-class) β€” Vestibo's default model provider, used directly and, on some deployments, via AWS Bedrock.Prompt + completion content (which may include conversation excerpts).US.Anthropic DPA, training-on-customer-data disabled.
OpenAI, LLC (optional / when configured)Text generation, where a tenant enables it. Also embeddings for semantic knowledge search β€” but only where a deployment explicitly opts in to the hosted embeddings path; by default semantic search either runs on our own self-hosted embeddings server or stays inert (keyword-only), and no knowledge content is sent to OpenAI.Prompt + completion content (which may include conversation excerpts); knowledge-base text where hosted embeddings are opted in.US.OpenAI DPA, BAA (HIPAA tier; via OpenAI's Enterprise plan), zero-data-retention available for eligible endpoints β€” training-on-customer-data is disabled.
(Optional, configurable per tenant) Other LLM providers as the customer enables them in their Model Router.per-vendor.per-vendor.per-vendor.per-vendor β€” Vestibo ships only providers with a training opt-out.

3. Voice (STT + TTS)

On the default telephony path, speech recognition is provided by Twilio (see Β§ 4 β€” the active voice sub-processor by default). When the self-hosted voice runtime is enabled, speech-to-text and text-to-speech run on Vestibo's own infrastructure with no third-party voice sub-processor. The vendors below are optional and engaged only where a deployment explicitly configures them.

VendorPurposeData processedRegionDPA / BAA
Deepgram, Inc. (optional / when configured)Speech-to-text.Voice audio, transcript.US (residency options available).Deepgram DPA, BAA (HIPAA tier).
ElevenLabs, Inc. (optional / when configured)Text-to-speech.Generated audio + synthesis text.US.ElevenLabs DPA; not used on the HIPAA path (no PHI).
OpenAI, LLC (optional / when configured)Optional TTS and optional Realtime API for low-latency voice.Voice audio + transcript.US.See Β§ 2.

4. Telephony and messaging

VendorPurposeData processedRegionDPA
Twilio Inc.Voice trunking, SMS + WhatsApp in/out, phone-number provisioning.Caller ID, phone numbers, call/SMS/WhatsApp content.US (data-residency options available).Twilio DPA + SCCs.

5. Email

VendorPurposeData processedRegionDPA
Amazon SES (via AWS)Transactional email (account, magic link, billing, agent-sent email).Email addresses, message content.Same as AWS row.AWS DPA.
(Optional) Customer-supplied SMTP providerOutbound email when the customer connects their own provider.Email addresses, message content.per-vendor.Customer-owned.

6. Integrations you connect (calendaring, CRM, messaging)

These are engaged only when a tenant chooses to connect them.

VendorPurposeData processedRegionDPA
Google LLCGoogle sign-in, Google Calendar booking, and (optional) Gmail triage.Profile email, calendar events, email content where Gmail is connected, OAuth tokens (encrypted at rest).US / EU.Google Cloud DPA.
Acuity Scheduling, Inc. (optional / when connected)Acuity OAuth for booking appointments.Booking records, OAuth tokens.US.Acuity DPA.
HubSpot, Inc. / Salesforce, Inc. (optional / when connected)CRM sync where a tenant connects one.Contact records, OAuth tokens (encrypted at rest).US / EU.per-vendor DPA.
Telegram FZ-LLC (optional / when configured)Optional messaging channel.Message content, chat/user IDs.Global.per-vendor terms.

7. Documents and signatures

VendorPurposeData processedRegionDPA
DocuSign / HelloSign (planned / when enabled)E-signature for the Clinic/HIPAA BAA and DPA. Not yet engaged β€” no signer data flows today.Signer name, email, IP (once enabled).US / EU.per-vendor DPA.

8. Payments

VendorPurposeData processedRegionDPA
Stripe, Inc.Subscription billing for your Vestibo plan, and β€” where enabled β€” Stripe Connect (Express) so a business can collect payments from its own customers via Stripe-hosted links. Stripe Connect is built but off by default, enabled per tenant via a feature flag.Cardholder data (tokenised β€” Vestibo never sees raw card numbers), billing address, last-4.US / EU.Stripe DPA, PCI DSS Level 1.

9. Customer support

VendorPurposeData processedRegionDPA
None todaySupport runs over email (support@vestibo.com) through our own email infrastructure; we do not use a third-party ticketing vendor. If we adopt one we will list it here and give the notice required by Β§ 6 of the DPA.β€”β€”β€”

10. Sub-processors no longer in use

VendorPurposeEnd date
(none)

Change history

  • 2026-07-23 β€” v1.0 β€” first published version; rebranded to Vestibo and refreshed to match the current stack (Anthropic as default LLM, Stripe Connect built but off by default, no S3 in use yet, added CRM/messaging integrations, and the opt-in-only hosted-embeddings path for semantic knowledge search).
  • 2026-05-16 β€” v0.1 β€” initial internal draft.

How to subscribe to changes: email privacy@vestibo.com.

Questions? Email legal@vestibo.com.