Sub-processors
Version: v1.1 β 2026-08-18
Effective date: 2026-08-18
Some vendors below are optional or "when configured" integrations
rather than active on every deployment; those rows are marked
(optional / when configured). We list them for transparency even
where they are not engaged by default.
Vestibo ("Vestibo") uses a small set of
sub-processors to provide the Service. This page is the
authoritative list. Customers can subscribe to change notifications by
emailing privacy@vestibo.com; we will give at least thirty (30)
days' notice before adding or replacing a sub-processor, as set out
in Β§ 6 of the DPA.
This list is reviewed and republished at least quarterly.
1. Infrastructure
| Vendor | Purpose | Data processed | Region | DPA / BAA / DPF |
|---|
| Amazon Web Services, Inc. (AWS) | Compute, application load balancer (edge / TLS termination), Route 53 (DNS), managed database (RDS Postgres), managed cache (ElastiCache Redis), KMS, CloudWatch, and Amazon SES (transactional email). Object storage (S3) is not currently in use; no Customer Data is stored in S3 today. | Account data and conversation data (transcripts, records) in the managed database; email content via SES. | us-east-1 | AWS DPA + SCCs, BAA (HIPAA tier), DPF certified. |
| Sentry (Functional Software, Inc.) (optional / when configured β not engaged on current production deployments) | Application error monitoring. | Stack traces, request IDs, optionally tenant IDs (no Customer-Content) β once enabled; no data flows today. | US (data-residency add-on available for EU). | Sentry DPA + SCCs. |
2. Large Language Model (LLM) providers
| Vendor | Purpose | Data processed | Region | DPA / BAA / training opt-out |
|---|
| DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) | Text generation β Vestibo's default model provider, via DeepSeek's hosted API (OpenAI-compatible endpoint at api.deepseek.com). | Prompt + completion content. Prompts can include conversation content from any channel (call-transcript turns, SMS/WhatsApp/chat messages), the business's configured instructions and settings, and knowledge-base text retrieved as context by the agent's search tool. | People's Republic of China. DeepSeek's published privacy policy states it collects, processes and stores data on servers in the PRC, and its platform terms are governed by PRC law. We cannot verify any other processing location and do not claim one. | No DPA or BAA is in place with DeepSeek. DeepSeek's privacy policy states inputs may be used to train and improve its models and describes a training opt-out; Vestibo has not signed a data-processing agreement with DeepSeek and has not verified or exercised that opt-out for its account. Accordingly, no PHI is permitted through this provider, and the Clinic/HIPAA tier is not offered while the default model provider operates without a BAA. |
| Anthropic, PBC (optional / when configured) | Text generation (Claude-class) β no longer the default provider. Engaged only where a tenant selects Anthropic in their Model Router (with the tenant's own API key) or a deployment explicitly configures an Anthropic-format primary or fallback, directly or via AWS Bedrock. Not engaged on the default production path. | Prompt + completion content (which may include conversation excerpts) β only for tenants/deployments that enable it. | US. | Anthropic DPA (incorporated in its commercial terms); no training on customer content by default under those terms. |
| OpenAI, LLC (optional / when configured) | Text generation, where a tenant enables it. Also embeddings for semantic knowledge search β but only where a deployment explicitly opts in to the hosted embeddings path; by default semantic search either runs on our own self-hosted embeddings server or stays inert (keyword-only), and no knowledge content is sent to OpenAI. | Prompt + completion content (which may include conversation excerpts); knowledge-base text where hosted embeddings are opted in. | US. | OpenAI's DPA is incorporated in its API terms, and a BAA is available via OpenAI's Enterprise plan; Vestibo has not executed a BAA with OpenAI, so this row describes availability, not an executed agreement. Zero-data-retention is available for eligible endpoints. OpenAI states API data is not used for training by default. |
| (Optional, configurable per tenant) Other LLM providers as the customer enables them in their Model Router. | per-vendor. | per-vendor. | per-vendor. | per-vendor β Vestibo ships only providers with a training opt-out. |
3. Voice (STT + TTS)
On the default telephony path, speech recognition is provided by
Twilio (see Β§ 4 β the active voice sub-processor by default). When
the self-hosted voice runtime is enabled, speech-to-text and
text-to-speech run on Vestibo's own infrastructure with no third-party
voice sub-processor. The vendors below are optional and engaged
only where a deployment explicitly configures them.
| Vendor | Purpose | Data processed | Region | DPA / BAA |
|---|
| Deepgram, Inc. (optional / when configured) | Speech-to-text. | Voice audio, transcript. | US (residency options available). | Deepgram DPA, BAA (HIPAA tier). |
| ElevenLabs, Inc. (optional / when configured) | Text-to-speech. | Generated audio + synthesis text. | US. | ElevenLabs DPA; not used on the HIPAA path (no PHI). |
| OpenAI, LLC (optional / when configured) | Optional TTS and optional Realtime API for low-latency voice. | Voice audio + transcript. | US. | See Β§ 2. |
4. Telephony and messaging
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Twilio Inc. | Voice trunking, SMS + WhatsApp in/out, phone-number provisioning. | Caller ID, phone numbers, call/SMS/WhatsApp content. | US (data-residency options available). | Twilio DPA + SCCs. |
5. Email
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Amazon SES (via AWS) | Transactional email (account, magic link, billing, agent-sent email). | Email addresses, message content. | Same as AWS row. | AWS DPA. |
| (Optional) Customer-supplied SMTP provider | Outbound email when the customer connects their own provider. | Email addresses, message content. | per-vendor. | Customer-owned. |
6. Integrations you connect (calendaring, CRM, messaging)
These are engaged only when a tenant chooses to connect them.
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Google LLC | Google sign-in, Google Calendar booking, and (optional) Gmail triage. | Profile email, calendar events, email content where Gmail is connected, OAuth tokens (encrypted at rest). | US / EU. | Google Cloud DPA. |
| Acuity Scheduling, Inc. (optional / when connected) | Acuity OAuth for booking appointments. | Booking records, OAuth tokens. | US. | Acuity DPA. |
| HubSpot, Inc. / Salesforce, Inc. (optional / when connected) | CRM sync where a tenant connects one. | Contact records, OAuth tokens (encrypted at rest). | US / EU. | per-vendor DPA. |
| Telegram FZ-LLC (optional / when configured) | Optional messaging channel. | Message content, chat/user IDs. | Global. | per-vendor terms. |
7. Documents and signatures
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| DocuSign / HelloSign (planned / when enabled) | E-signature for the Clinic/HIPAA BAA and DPA. Not yet engaged β no signer data flows today. | Signer name, email, IP (once enabled). | US / EU. | per-vendor DPA. |
8. Payments
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| Stripe, Inc. | Subscription billing for your Vestibo plan, and β where enabled β Stripe Connect (Express) so a business can collect payments from its own customers via Stripe-hosted links. Stripe Connect is built but off by default, enabled per tenant via a feature flag. | Cardholder data (tokenised β Vestibo never sees raw card numbers), billing address, last-4. | US / EU. | Stripe DPA, PCI DSS Level 1. |
9. Customer support
| Vendor | Purpose | Data processed | Region | DPA |
|---|
| None today | Support runs over email (support@vestibo.com) through our own email infrastructure; we do not use a third-party ticketing vendor. If we adopt one we will list it here and give the notice required by Β§ 6 of the DPA. | β | β | β |
10. Sub-processors no longer in use
| Vendor | Purpose | End date |
|---|
| (none) | | |
Change history
- 2026-08-18 β v1.1 β Β§ 2 corrected: Vestibo's default model provider is
DeepSeek (hosted DeepSeek API), not Anthropic. Production has run on
DeepSeek since late July 2026, so the v1.0 entry below ("Anthropic as default
LLM") was inaccurate; it is retained, annotated, for the record. The new
DeepSeek row states plainly that, per DeepSeek's published policy, processing
occurs in the People's Republic of China, and that no DPA, BAA, or verified
training opt-out is currently in place with DeepSeek β accordingly the
Clinic/HIPAA tier is not offered on the current stack. Anthropic is retained
as an optional, tenant-/deployment-configured provider.
- 2026-07-23 β v1.0 β first published version; rebranded to Vestibo and refreshed to match the current stack (Anthropic as default LLM (inaccurate β production's default provider was DeepSeek; corrected in v1.1), Stripe Connect built but off by default, no S3 in use yet, added CRM/messaging integrations, and the opt-in-only hosted-embeddings path for semantic knowledge search).
- 2026-05-16 β v0.1 β initial internal draft.
How to subscribe to changes: email privacy@vestibo.com.