Sub-processors
Version 1.0 · Effective August 19, 2026 · Archived
Retrieved from https://www.operatorbase.app/subprocessors/2026-08-19 · Archived version 1.0, effective August 19, 2026
DIGITAL WARRIORS LLC ("Operator Base") uses the third-party providers listed below to deliver the Service. This page names each one, what it does, what categories of data it can access, and where it processes that data.
This is an archived version of this page. It is not the current list. It is version 1.0, effective August 19, 2026, kept at this permanent address so that a customer who contracted against it can retrieve the exact text they agreed to. The text below is frozen and is not updated. For the providers we use today, see the current Sub-processor page, which also carries the version history and the changelog.
Version 1.0 is the list incorporated as Annex III by version 1.1 of our Data Processing Addendum. Where this archived version and the current page differ, the version that applies to you is the one in force under your contract, and the changelog on the current page records what changed between them.
Two tables, and why the difference matters
The tables below separate providers by who engages them, because the two groups carry different obligations:
- Sub-processors we engage. We choose these providers, hold the credentials, and pay for them. They process customer data on our instructions. Changes to this list follow the notice process described further down.
- Integrations you connect. These are reached only when you supply credentials to your own account with that vendor. You choose the vendor and hold the contract with them. We transmit data to them on your instruction, and we do not control their processing. If you connect none of them, none of them receive your data.
Three categories of data
Within each table, the Data it can access column opens by naming which of the three categories below a provider can reach. Some providers reach more than one, and those rows name both rather than round up to the broadest:
- End-contact personal data. Personal data about the leads, prospects, and customers your AI agents talk to and your outreach campaigns email.
- Member and visitor data. Data about you and your team as users of Operator Base, and about people who visit our website. Your name, email address, and profile photo, what you post in the community, your direct messages and the files and voice notes attached to them, live call video, and website analytics events.
- Account and operational data. Billing details, sign-in records, service metrics, error diagnostics, and alerts, with no message content and no contact records in them.
Where a provider receives no personal data at all, the row says no personal data and explains what it does receive instead. Listing a provider as a processor of personal data when it is not would be its own inaccuracy, so we do not pad the column.
Sub-processors we engage
| Sub-processor | What it does | Data it can access | Processing location |
|---|---|---|---|
| Infrastructure and hosting | |||
| Amazon Web Services | Hosting for the AI agent platform (ECS Fargate), container images, application logs, operational alerting, and secret storage. | End-contact personal data. All agent platform data passes through the application layer. Stored application logs are redacted before they are written. | United States (us-east-1) |
| Supabase (agent platform database) | The AI agent platform's Postgres database and file storage for uploaded files, voice recordings, widget assets, and data exports. | End-contact personal data. Contact records, conversation history, agent memory, voice recordings, and agent platform account data. | United States (us-east-1) |
| Supabase (operator app and sign-in) | A second, separate Supabase project. It is the operator app's whole backend, and it also holds the sign-in accounts used both for the operator app and for the agent platform dashboard. It stores community posts and comments, direct messages and their attachments, live call recordings, course progress, push notification tokens, and the outreach tool's campaigns, prospect records, and inboxes. | End-contact personal data and member data. Member names, email addresses, and hashed passwords, everything a member posts or uploads, and the prospect records and email threads the outreach tool works with. | United States (us-west-2) |
| Upstash | Redis, in two separate databases. The first carries the agent platform's background job queues, live session state, rate limiting, and streaming updates to the dashboard and chat widget. The second is used by our website for rate limiting and webhook de-duplication only. | End-contact personal data in the agent platform database, because queued job payloads and session state contain message content while a job is in flight. Account and operational data only in the website database: rate-limit counters and processed-webhook markers. | United States (us-east-1) for the agent platform database. Region not confirmed for the website database. |
| Vercel | Hosts the operator app, the agent platform dashboard, and our website, including our website's server-side form and checkout endpoints and the edge middleware that renders link previews for custom onboarding domains. Its API also provisions the custom domains members attach to those sites, and it provides DNS for our own domains. | Member and visitor data. The name, email address, and phone number submitted through a form on our website pass through a Vercel function. The operator app and the dashboard call our own APIs directly, so no end-contact data is processed by Vercel. | Static files and edge middleware are served from Vercel's global network. Server-side function region not confirmed. |
| LiveKit | Carries the real-time audio and video of community live calls and hangouts in the operator app, and runs the server-side recording of a call when one is started. The recording is handed to our own storage afterwards. | Member data. Live call audio and video, the display name or email address shown against a participant, and the recording produced from the call. | Region not confirmed |
| Cloudflare | Stream and R2 hold and deliver video: our course and help videos, and the video files members attach to direct messages and community posts. Workers serve the static client onboarding sites members generate. Turnstile screens our website's forms for automated abuse. | Member and visitor data. Video a member uploads can show or name a person. Turnstile receives the visitor's IP address and browser signals. | Global content delivery network |
| AI and content processing | |||
| Anthropic | Large language model used for intent classification, conversation summarization, agent memory extraction, in-product help, agent and tool authoring, generating the client onboarding sites members build, and, on our own account, the outreach tool's campaign email generation and per-prospect personalization. | End-contact personal data. Message content and conversation context are sent as prompts. For outreach personalization that includes the prospect's name, business category, city, and website. | United States |
| Google (Gemini API) | Text embeddings for knowledge base indexing and knowledge base search, part of in-product help, and the operator app's AI co-pilot and lesson features. | End-contact personal data and member data. Knowledge base content, search queries derived from what an end contact asked, and the questions a member asks the co-pilot. | United States |
| OpenAI | Screens community posts, comments, and direct messages for prohibited content before they are published, runs the prompt testing bench, and generates text embeddings for the operator app's knowledge features. | Member data. The text of a community post, comment, or direct message, and the prompts a member tests. | United States |
| Vultr (Serverless Inference) | Runs the content safety classifier that screens agent inputs and outputs, where a customer has enabled the safety guard on an agent. | End-contact personal data. Message text is sent for classification when the guard is enabled. | United States |
| Deepgram | Speech to text. Transcribes voice notes sent in direct messages, and our course and help videos, so they can be read and searched. | Member data. The audio of a voice note a member records, and the transcript produced from it. | United States |
| Replicate | Generates the images used in the client onboarding sites a member builds. | No personal data. We send a text prompt describing the business the site is for. | United States |
| Jina AI | Reads public web pages: the pages a customer adds as a knowledge base source, the prospect and client websites the demo builder and onboarding flow read, and the web search behind agent research. | Account and operational data. The web addresses we are asked to read or search for, and the public page content returned. No end-contact data. | United States |
| Context7 | Looks up third-party developer documentation while a member is authoring a custom agent tool, so the tool builder can reference a library's real API. | No personal data. The library name and topic a member types into the tool builder. | Region not confirmed |
| Internet Archive | Fallback page reader. When a prospect's website cannot be reached directly, the demo builder reads the most recent archived snapshot of it instead. | No personal data. The hostname of the public website being read. | United States |
| Google Public DNS | Resolves DNS records over HTTPS when the outreach tool verifies that a sending domain is correctly configured and that a prospect's domain exists. | No personal data. A hostname and a DNS record type. | United States |
| Messaging, email, and notifications | |||
| Mailgun | Sends and receives email for AI agents, both on our shared sending domain and on any custom sending domain a customer verifies. All agent email is sent through our Mailgun account. | End-contact personal data. Recipient email addresses, subject lines, and message bodies. | United States (US API endpoint) |
| SendGrid | Sends the outreach tool's campaign email from the sending domains a member verifies, receives the replies to it, and reports delivery events back to us. | End-contact personal data. Prospect email addresses, subject lines, message bodies, and the content of their replies. | United States |
| Resend | Transactional and lifecycle email to members: team invitations, account and authentication email, and the notification emails that mirror in-app activity. | Member data, and end-contact personal data in one case. Member name and email address, notification emails that can quote the first 100 characters of a direct message or community post, and outreach notifications that name the prospect email address a reply came from. | United States |
| Meta Platforms (WhatsApp Business) | The WhatsApp Business Cloud API and Meta messaging channels. Customers connect their own WhatsApp Business account through our Meta application. | End-contact personal data. Phone numbers, profile names, and message content. | United States |
| Apple (Push Notification service) | Delivers push notifications to the operator app on iOS. The device registers a token with Apple, and we send the notification through Apple to that token. | Member data. The device push token and the notification itself, which can name the member who sent a message and quote the first 100 characters of it. | Region not confirmed. Operated by Apple. |
| Google (Firebase Cloud Messaging) | Delivers push notifications to the operator app on Android, in the same way Apple's service does on iOS. | Member data. The device push token and the notification itself, which can name the member who sent a message and quote the first 100 characters of it. | Region not confirmed. Operated by Google. |
| Contact data and verification | |||
| FullEnrich | Finds a work email address and phone number for a prospect a member has selected in the prospecting tool. | End-contact personal data. The prospect's name, company, and website go out, and an email address and phone number come back. | Region not confirmed |
| Exa | Searches the public web for companies and people matching the prospecting criteria a member sets. | End-contact personal data. The search criteria go out, and the matching records come back. | United States |
| DeBounce | Checks whether a prospect email address is deliverable, and whether its domain is a disposable-mail domain, before a campaign sends to it. | End-contact personal data. Email addresses only. | Region not confirmed |
| NeverBounce | Checks that an email address typed into a form on our website is deliverable before we accept the submission. | Visitor data. The email address typed into the form, only. | United States |
| Analytics, error reporting, and alerting | |||
| Sentry | Application error monitoring and crash reporting. | Account and operational data. Error events are redacted before they are sent. See the note on redaction limits below. | United States |
| Microsoft (Clarity) | Session recordings and interaction heatmaps for the operator app when it is used in a web browser, so we can see where the interface is failing people. It is not active in the iOS or Android app. | Member data. A recording of the screen as the member uses the app, their Operator Base user identifier, and their account role. Because it records the screen, anything on screen at the time is in the recording. | Region not confirmed |
| PostHog | Product analytics for our website: page views and funnel events, used to see which pages lead to a sign-up. | Visitor data. A visitor identifier, page URLs, and events. A person profile is created only for a visitor we have identified. | United States |
| Meta Platforms (advertising pixel) | Measures which advertising leads to a sign-up or purchase on our website. This is a separate role from the WhatsApp Business row above. | Visitor data. Page views and purchase events, with the identifiers the pixel sets in the visitor's browser. | United States |
| ClickMagick | Click tracking and conversion attribution for our advertising, on our website only. | Visitor data. Click and conversion events. | United States |
| FirstPromoter | Affiliate attribution: records which affiliate referred a purchase on our website, so the referral can be paid. | Visitor data. A referral identifier and the purchase event attached to it. | Region not confirmed |
| Slack | Delivers infrastructure alerts to the Operator Base engineering team. | Account and operational data. Service names, alarm names, and internal identifiers. No end-contact data. | United States |
| Telegram | Delivers automated production health alerts to the Operator Base engineering team. | Account and operational data. Message counts and service state. No message content and no contact data. | Region not confirmed |
| Billing, delivery, and operations | |||
| Stripe | Subscription billing and payment processing for your Operator Base account, including checkout on our website. | Account and billing data only. Billing name, email address, and payment details. No end-contact data. | United States |
| GoHighLevel (our own account) | Our own customer relationship management account. It receives the opt-in forms submitted on our website and records purchase status against a customer record. This is separate from the GoHighLevel account a customer connects, listed in the second table. | Member and visitor data. Name, email address, phone number, and purchase status. Separately, the testimonial photos and videos we host in that GoHighLevel account are loaded directly by your browser from Google Cloud Storage, which sees the device's IP address the way any external image would. No end-contact data. | United States |
| Capgo | Delivers over-the-air JavaScript updates to installed iOS and Android copies of the operator app, so a fix reaches the app without an app store release. | No personal data. A generated device identifier, the app and operating system version, and which update channel the device is on. No account data and no content. | Region not confirmed |
| GitHub | Hosted build runners compress the recording of a community live call after the call ends, then hand the compressed file back to our storage. | Member data. The video and audio of a recorded community call, for the length of the compression job. | Region not confirmed. GitHub-hosted runners. |
| Microlink | Takes a screenshot of a prospect's public website so the demo builder can show that site inside a phone mockup. It is a fallback path, used when a demo does not yet have its own screenshot endpoint. | No personal data. We send the public web address of the business the demo is for. The screenshot is loaded by the member's browser, so Microlink sees that device's IP address the way any external image request would. | Region not confirmed |
| Giphy | GIF search in direct messages and community posts. The search runs through our server so that our key is not exposed. | No personal data from us. We send only the search term. Separately, the GIF file itself is loaded by your device from Giphy's own network, which sees the device's IP address the same way any external image would. | United States |
On processing locations. Operator Base has not configured a European or other non-US region for any service, and the systems that store your data run in the United States. Two things are worth reading precisely. First, where a specific zone is shown, such as us-east-1 or us-west-2, we have verified it against the account that runs the service. Where a country is shown without a zone, that is the provider's own stated primary processing country for the endpoint we call, not a region we selected and can hold them to. Where the row says the region is not confirmed, we have not established it and would rather say so. Second, delivery is not the same as storage: Vercel and Cloudflare serve files and run edge code from whichever location is nearest the device making the request, which can be outside the United States, while the systems that hold the data stay where the table says.
On error monitoring. Application logs and error reports are redacted before they leave our services. That redaction removes email addresses and phone numbers by pattern matching. It does not detect names, addresses, or free text inside a third-party error message, so a residual identifier can reach our logging and error monitoring providers. We state this plainly rather than claim that no personal data reaches them. See the Security page for detail.
On session recordings.Microsoft Clarity records the screen while the operator app is used in a web browser. If a member has end-contact data on screen at the time, for example an outreach inbox, that appears in the recording. The recording is tied to the member's Operator Base user identifier, never to their email address. It does not run in the iOS or Android app.
Integrations you connect
These vendors receive data only after you connect an account and supply credentials. The credentials you store with us are encrypted. You can disconnect an integration at any time, which stops further transmission to that vendor. Data already delivered to a vendor is held under your agreement with them, and you would raise any deletion request directly with that vendor as well as with us.
| Integration | What it does | Data it can access |
|---|---|---|
| Retell AI | Voice agent telephony: call handling, live transcription, and call recordings, both for the agent platform and for the demo voice agents built in the operator app. The speech vendor for a voice is selected inside your Retell account, from Retell's catalogue of ElevenLabs, OpenAI, Cartesia, MiniMax, and Fish Audio voices. | End-contact personal data. Phone numbers, call audio, transcripts, and post-call analysis. |
| Twilio | SMS and voice phone numbers, using the customer's own Twilio account credentials. | End-contact personal data. Phone numbers and message content. |
| GoHighLevel (LeadConnector) | Two-way CRM synchronization of contacts, conversations, tags, opportunities, and appointments with your own GoHighLevel account. | End-contact personal data. The full contact record and conversation history. |
| Apify | Runs the prospecting scrapes in the operator app against Google Places, LinkedIn, and Meta ad libraries, using your own Apify account token. | Account and operational data goes out, end-contact personal data comes back. We send the search criteria you set, your Apify token, and a callback address containing your Operator Base job identifier. The business and contact records Apify returns are what become your prospect list. |
| Model providers: Anthropic, OpenAI, Groq, Mistral, Cohere, Qwen, OpenRouter, Azure OpenAI, Google Gemini, or a custom endpoint | Language model inference for your agents, and for the outreach tool's AI reply drafting and stale follow-ups in the operator app. These run on a model provider key you supply, so the vendor here is whichever provider you connect. Note the boundary: campaign email generation and per-prospect personalization in the outreach tool run on our own Anthropic account, not yours, and Anthropic is listed as a sub-processor we engage in the first table for that reason. | End-contact personal data. Message content and conversation context are sent as prompts. |
| Calendars: Google Calendar, Microsoft 365, Apple CalDAV, Calendly | Availability lookup and appointment booking. | End-contact personal data. Name, email address, and appointment details. |
| Slack | Delivering human-handoff notifications into a customer's own Slack workspace when an agent escalates a conversation to a person. | End-contact personal data. The conversation content included in the handoff notification. |
| Meta and other advertising or analytics tags you add | The demo and client onboarding sites you generate let you paste in your own tracking tags, such as a Meta pixel or a tag manager container. | End-contact personal data. Whatever the tag you install is configured to collect from the people who visit that site. |
| Stripe Connect | Connecting an agency's own Stripe account so the agency can bill the sub-accounts it manages on the platform. | Account and billing data only. Billing details of the sub-accounts an agency manages. No end-contact data. |
Each of these vendors operates its own infrastructure and sets its own processing locations. Because you hold the account, the applicable region is the one configured in your account with that vendor, not one we select.
Two vendors appear in both tables because they play two unrelated roles. GoHighLevel is our own CRM for Operator Base customer records, and separately the CRM you may connect for your end contacts. Meta Platforms operates the WhatsApp Business channel your agents use, and separately the advertising pixel on our website. The rows state which role is which.
How we tell you when this list changes
Before a new sub-processor begins processing customer data, we will:
- publish a new version of this page with a new version number and effective date, record the change in the version history on the current Sub-processor page, and archive the version being replaced at its own permanent address;
- send written notice to the email address on your Operator Base account at least 30 days beforehand.
You may object to a new sub-processor on reasonable data protection grounds by writing to support@operatorbase.app before that sub-processor begins processing. If we cannot resolve your objection, you may terminate the affected part of the Service. The objection process is set out in section 8 of our Data Processing Addendum.
Replacing a sub-processor with another that performs the same function follows the same process. Removing a sub-processor does not require notice, because it reduces the number of parties that reach your data.
Saving a copy.This page is formatted to print cleanly. Use your browser's print command and choose "Save as PDF" to keep a copy of this archived version for your records. The printed copy carries the version number, the effective date, and the address it was retrieved from.
Questions
If you need this information in a different format for a vendor review, or want to ask about a specific provider, contact us:
DIGITAL WARRIORS LLC
180 NE 29th St, Apt 330
Miami, FL 33137
support@operatorbase.app