Subprocessors
- Effective from
- Last updated
- Version
- 1.0
We rely on outside providers to run the service. When one of them processes our customers’ personal data, it is a subprocessor, and this is the full list.
Each one is under contract with us, accesses only what its function needs, and is bound by confidentiality and security obligations equivalent to our own.
How we announce changes
Before adding a new subprocessor or replacing an existing one, we publish it here and give active organizations at least 30 days’ notice.
If your organization has a reasonable, data-protection-grounded objection, raise it within that period by writing to info@meruma.app. We will look for a reasonable alternative and, if there is none, your organization may drop the affected service without penalty.
Infrastructure
These providers are involved regardless of how your organization is set up.
| Provider | What for | What data it processes | Country |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage, queues, user identity and transactional email | All service data | United States (us-east-1) |
| Cloudflare | Protection against automated submissions on public forms | IP address and browser signals of whoever fills in a form | United States and global network |
Channels and optional features
These providers are involved only if your organization turns on the corresponding channel or feature.
| Provider | What for | What data it processes | Country |
|---|---|---|---|
| Meta Platforms | WhatsApp, Instagram and Messenger channels | Messages, attachments, identifiers and profile names of that channel’s contacts | United States and Ireland |
| Telnyx | Calling, SMS and call recording | Phone numbers, metadata and audio of calls and messages | United States |
| Gmail email channel, calendar sync and sign-in | Emails, calendar events and connected-account data | United States | |
| Microsoft | Outlook email channel and calendar sync | Emails, calendar events and connected-account data | United States |
| OpenAI | AI bots, using your organization’s key | The conversation messages and the knowledge documents you upload | United States |
About OpenAI: the data sent is not used to train models, theirs or ours.
Services your organization chooses
Your organization can also connect services of its own or of third parties that we neither choose nor control:
- Its own mail server (SMTP or IMAP), if it prefers to send and receive through it rather than through the channels above.
- Services embedded in the websites it publishes with the site builder: analytics, maps or video, for example. If your organization adds them, those services receive data about site visitors, and it is the organization that must disclose it and obtain any required consent.
Components we run ourselves
Some features rely on open source software that runs inside our own infrastructure, with no third party receiving data: document-to-PDF conversion for e-signature, and the PostgreSQL database. They are not subprocessors, but we mention them so the picture is complete.
International transfers
Every provider on this list processes data in the United States. For transfers from the European Union, the United Kingdom or Switzerland we rely on the Standard Contractual Clauses approved by the European Commission (Implementing Decision 2021/914), together with the technical measures described on the security page.
Questions
Write to info@meruma.app if you need the contractual detail of any of these providers for your own compliance review.