Sub-processors
Every third party that may process personal data on Adoptiv's behalf, what each one receives, and whether it is on by default or only when someone switches it on.
Adoptiv Inc · Updated 2026-08-03
01How to read this page
A sub-processor is a company we use to run Adoptiv that may handle personal data belonging to our customers. Every one of them is under a written contract that limits it to processing on our instructions, holds it to security obligations no less protective than our own, and is covered by the transfer clauses in /legal/dpa. We remain responsible to our customers for what they do.
The last column is the one to read carefully. Many of these are not on unless somebody turns them on.
| Value | What it means |
|---|---|
| Default | Part of running the platform. Every customer's data may reach it |
| Customer choice | Reached only when a customer switches on a feature, connects an account, or selects that provider |
| Operator choice | Reached only when Adoptiv binds that provider to a job. Customers cannot add their own provider keys |
One important scoping point about the AI section. That table lists every provider the platform is built to support, not a list of companies all receiving your data at once. Each AI job is bound to a single provider at a time, so the providers actually in use are a small subset. A customer can ask which providers are bound for its account and we will tell it.
This page covers sub-processors. It does not cover the services a customer chooses to connect for itself, such as another CRM or a video conferencing account. Those are the customer's own controllers and its own contracts, and we only move data at its instruction.
02Infrastructure
These run the platform. There is no version of Adoptiv that does not use them.
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Hetzner Online GmbH, Germany | Cloud servers and S3-compatible object storage. This is our primary infrastructure, in Nuremberg and Falkenstein | Everything the platform stores: databases, call recordings, voicemail audio, CRM files and attachments | Default |
| Amazon Web Services | S3 object storage, supported as an alternative to Hetzner for customers who need it | The same categories as above, where a workspace is configured to use it | Customer choice |
| Cloudflare, Inc. | DNS, and it sits in front of our web traffic | DNS records, and the connection metadata of any request to us, including IP address | Default |
03Mailbox and calendar
Reached only when a user connects their own mailbox or calendar. If nobody connects one, none of these receive anything.
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Google LLC, Gmail API | Reads and sends mail for a connected Gmail account | Requests for messages, threads, labels and attachments, and the messages a user sends from Adoptiv. See /legal/google-user-data | Customer choice |
| Google LLC, Cloud Pub/Sub | Delivers the notification that tells us a connected Gmail mailbox has changed | A change marker for the mailbox. It does not carry message content | Customer choice |
| Google LLC, Calendar API | Reads a connected calendar and writes meetings booked from Adoptiv | Events, times, attendees and meeting links | Customer choice |
| Microsoft Corporation, Microsoft Graph | Reads and sends mail, reads and writes calendar, reads contacts, for a connected Microsoft account | Message headers, bodies and attachments, calendar events, contact entries, and change notification subscriptions | Customer choice |
| The customer's own IMAP host | Syncs a mailbox the customer nominates by hostname | Whatever that mailbox contains. The customer chooses the host and we connect to it | Customer choice |
04AI and speech
This is the most sensitive category, because these providers can receive the content of calls and email rather than just metadata.
AI analysis is opt-in for each workspace and every switch starts off. Nothing here receives anything until an administrator turns a feature on. Providers are engaged under terms that prohibit them from training any model on the data.
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Microsoft Azure AI Speech | Speech to text, and text to speech for voice prompts | Call and voicemail audio, and the text to be spoken | Operator choice, after a workspace opts in |
| AssemblyAI, Inc. | Speech to text | Call and voicemail audio | Operator choice, after a workspace opts in |
| Speechmatics Ltd | Speech to text | Call and voicemail audio | Operator choice, after a workspace opts in |
| Amazon Transcribe | Speech to text | Call and voicemail audio | Operator choice, after a workspace opts in |
| Amazon Polly | Text to speech for voice prompts and agents | The text to be spoken | Operator choice |
| ElevenLabs Inc. | Text to speech, and speech to text | The text to be spoken, and call audio where its transcription is used | Operator choice |
| OpenAI, L.L.C. | Language model work, and Whisper transcription | Call transcripts, email thread bodies, CRM notes and comments, drafted email text, and call audio where Whisper is used | Operator choice, after a workspace opts in |
| Microsoft Azure OpenAI Service | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Anthropic PBC | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Google LLC, Gemini API | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Cohere Inc. | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Mistral AI SAS | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Groq, Inc. | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Together Computer, Inc. | Language model work | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
| Amazon Bedrock | Language model work and embeddings | Call transcripts, email bodies and CRM field values | Operator choice, after a workspace opts in |
Where analysis produces suggested corrections to a contact record, such as a corrected job title or postal address heard on a call, those suggested values pass through the language model as part of the same request. They are held as suggestions for a person to accept or reject, not applied automatically.
05Email delivery
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Resend, Inc. | Sends the platform's own mail: sign-in and verification, invitations, password resets, billing notices and digests | The recipient address, subject and body of that message, and identifiers for the workspace and user it concerns | Default |
| Amazon Simple Email Service | Sends a customer's own outbound mail, when the customer selects it | The full message: sender, recipients, subject, body and attachments | Customer choice |
| Twilio SendGrid | Sends a customer's own outbound mail, when the customer selects it | The full message: sender, recipients, subject, body and attachments | Customer choice |
| Mailgun Technologies, Inc. | Sends a customer's own outbound mail, when the customer selects it. A European endpoint is available | The full message: sender, recipients, subject, body and attachments | Customer choice |
| The customer's own SMTP host | Sends a customer's own outbound mail through a server it nominates | The full message. The customer chooses the host | Customer choice |
Resend is the only one of these that is always on, because the platform has to be able to email you about your own account. A customer's own campaign and CRM mail never silently falls back to it: if the customer's chosen sender is unavailable, the send fails rather than going out from an Adoptiv address.
06Telephony numbers
Adoptiv runs its own voice infrastructure. Call media and recordings stay on our own servers and storage. The companies below sell and provision phone numbers.
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Twilio Inc. | Searches for and buys phone numbers | A country and area code when searching, and one number in E.164 format when buying, plus the address to route that number to | Customer choice |
| Telnyx LLC | Searches for and buys phone numbers | The same: search criteria, one E.164 number, and a routing identifier | Customer choice |
| Plivo Inc. | Searches for and buys phone numbers | The same: search criteria, one E.164 number, and a routing identifier | Customer choice |
| Sinch AB | Searches for and buys phone numbers | The same: search criteria, one E.164 number, and a routing identifier | Customer choice |
None of these receives call audio, recordings, transcripts or call detail records from Adoptiv. They do not receive contact lists or CRM data. To be straight about one thing that is inherent rather than something our software sends: whoever is the carrier of record for a number carries the calls to and from it, so that provider's network sees the call the way any telephone carrier does.
Messaging runs on the same carrier that supplies the number. A text sent from Adoptiv goes out over that carrier, and the recipient number, the message body and the sending number reach it in order to be delivered. Nothing else about the record travels with it.
07Payments
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Stripe, Inc. | Takes payment and manages subscriptions. This is our only payment processor | Customer name, email address, billing address, and an identifier for the workspace. Card details are entered directly with Stripe, which is a PCI-DSS Level 1 service provider, and Adoptiv servers never see or store a card number | Default |
There is no second payment processor. If you find another one named in an older Adoptiv document, that document is out of date and this page is correct.
08Compliance screening and business data
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| The Blacklist Alliance | Screens phone numbers against do-not-call and known litigator lists before a call is placed | Phone numbers only | Operator choice |
| Google Maps Platform | Verifies and standardises a postal address, and renders a static map of it | A postal address | Operator choice |
| Clearbit | Looks up company information from a domain name | A company domain name | Operator choice |
| Apollo.io | Looks up company information from a domain name | A company domain name | Operator choice |
| ZoomInfo | Looks up company information from a domain name | A company domain name | Operator choice |
| Lusha | Looks up company information from a domain name | A company domain name | Operator choice |
| Cognism | Looks up company information from a domain name | A company domain name | Operator choice |
The five company lookup providers do the same job and only one is used at a time. They receive a company domain, not a person's contact details.
09Meetings
Reached only when a user connects that account to create meeting links from Adoptiv.
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Zoom Video Communications, Inc. | Creates a meeting and returns a join link | The meeting subject, time and the invited attendees | Customer choice |
| Google Meet | Creates a meeting and returns a join link, through Google Calendar | The meeting subject, time and the invited attendees | Customer choice |
| Microsoft Teams | Creates a meeting and returns a join link, through Microsoft Graph | The meeting subject, time and the invited attendees | Customer choice |
| Cisco Webex | Creates a meeting and returns a join link | The meeting subject, time and the invited attendees | Customer choice |
10Product telemetry and support
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Functional Software, Inc. trading as Sentry | Error and performance monitoring, so we find faults before you report them | Error reports, stack traces and performance traces. These are tagged with the signed-in user's identifier and email address and the workspace identifier, so we can tell whose fault we are looking at. Session replays are captured with text masked and media blocked | Default |
| PostHog, Inc. | Product analytics on our marketing and sign-in pages | Anonymous page views and interaction events. It is not loaded inside the authenticated product, and visitors in the EEA, the UK and Switzerland are not tracked unless they consent | Default on marketing pages |
| Intercom, Inc. | The support messenger and our support inbox | For a signed-in user: name, email, phone, and the workspace name, plan and country. For a website visitor: nothing identifying. The messenger loads for everyone so that support is always reachable, and it is not gated behind the analytics consent banner | Default |
| Google Analytics 4 | Website traffic measurement. Marketing pages only | Page views and clicks on calls to action. No names, emails or phone numbers are sent. It does not load in the product, and it does not load outside our public website | Marketing pages, subject to consent |
| Google Ads | Measures which adverts lead to a demo request. Marketing pages only | A conversion event. No names, emails or phone numbers are sent | Marketing pages, subject to consent |
Sentry is the one to note if you are assessing us, because it is the only telemetry provider that receives an identifiable email address, and it is on by default. It exists so that when something breaks we can find the account it broke for.
11Website and browser services
These are small, but they are outbound connections and they belong on the list.
| Provider | What it does for us | What it receives | Status |
|---|---|---|---|
| Gravatar, an Automattic service | Shows a profile picture for a contact where one exists | A hashed form of the contact's email address, requested by your browser rather than by our servers. Your browser's IP address reaches Gravatar as part of that request | Default |
| Google reCAPTCHA | Stops automated abuse of our public forms | A challenge token, plus the browser and IP information Google collects to score it | Default on public forms |
| Browser push services | Delivers a push notification to a browser that has asked for them. In practice this is the push endpoint operated by the browser's maker, such as Google, Mozilla or Apple | The push endpoint identifier and the encrypted notification payload | Customer choice, per user |
| Calendly LLC | Books demo calls from our public website. It is not part of the product | The name, email and time chosen by whoever books a demo with our sales team | Marketing pages only |
12What is deliberately not on this list
Naming a company we do not use would be as misleading as leaving out one we do, so here is what we checked and excluded.
- No second payment processor. Billing runs through Stripe alone.
- No IP geolocation service. We look up approximate location from a database file held on our own servers, so visitor IP addresses are not sent to a geolocation vendor.
- No advertising or data broker receives customer content, and we do not sell personal data.
- No AI provider receives anything from a workspace that has not switched AI features on.
Configuration keys for unused services sometimes survive in a codebase after a feature is removed. A leftover key is not a sub-processor. This page lists services that actually receive data.
13Changes, and how to be told about them
We give at least 30 days' notice before we add a new sub-processor or replace an existing one. The notice period runs from the day this page is updated.
- To subscribe, email subprocessors@adoptiv.com with the subject Subscribe and tell us which addresses to notify. We will confirm, and you can unsubscribe the same way.
- Notice goes to every subscribed address and to the account administrator on file.
- If you object on reasonable data protection grounds, write to legal@adoptiv.com within the 30 days and explain the grounds. We will work with you to resolve it.
- If it cannot be resolved, you may terminate the affected part of the service without penalty and receive a pro rata refund for the unused period, as set out at /legal/dpa.
We may occasionally have to replace a sub-processor faster than 30 days, for instance if one fails or a contract is terminated for cause. If that happens we will tell you as soon as we can and explain why, and your right to object still stands.
Questions about anything on this page go to privacy@adoptiv.com, or Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Our phone number is +1 (636) 556 0022.
Adoptiv Inc, 2810 N Church St STE 88783, Wilmington, DE 19802, United States. Questions about this document go to legal@adoptiv.com. Privacy requests go to privacy@adoptiv.com.