Skip to content

Subprocessors

Last updated 23 August 2026 · Change notifications: subprocessors@xeso.ai
Current registry · evidence status shown belowThis registry includes providers used by the current service and optional providers that remain configuration-gated. Listing an optional provider does not mean it is enabled. Contract, DPA, service-tier, transfer, and regional statements remain evidence-gated unless the provider entry says otherwise.

What is a subprocessor?

A subprocessor is any third-party service that processes personal data on our behalf. Under the GDPR (Article 28), CCPA, and the Australian Privacy Act, we disclose the identity of those parties so you can evaluate them as part of your data governance review. Each provider that receives personal data must operate under the applicable contractual and processing protections. Optional providers remain disabled until their required approvals are complete.

Current and optional subprocessors

The table below is the public registry as of 23 August 2026. Each entry explains its current or optional role and the evidence status users may rely on. We will provide advance notice before a material new provider begins processing customer personal data where the applicable agreement requires it. Subscribe by emailing subprocessors@xeso.ai.

Google Cloud Platform

Current registry · verify detailsPurpose: Application hosting, storage, loggingData category: All customer data at rest + in transitLocation: United States (us-central1)DPA: Current Google terms apply; XESO account and DPA evidence review remains openCertifications: See the provider trust centre; this is not an XESO certificationCurrent production infrastructure. Network claims remain evidence-gated.

Cloud SQL for PostgreSQL

Current registry · verify detailsPurpose: Primary application databaseData category: Notes, folders, auth metadata, PIILocation: United States (inherits GCP region)DPA: Covered by the applicable Google Cloud terms; account evidence review remains openCertifications: See the Google Cloud trust centre; this is not an XESO certificationCurrent production database. Backup and network claims remain evidence-gated.

Google Gemini (Generative Language API)

Current registry · verify detailsPurpose: LLM inference for chat, summaries, classificationData category: Prompt text + completions. We do not send identifiers by default.Location: Google-managed; processing location is not represented as region-fixedDPA: Current API terms reviewed; production account binding awaits attestationCertifications: Service tier and active-billing status must be deployment-attestedXESO does not use customer content for model training or evaluation. Provider handling follows the active API project's terms; no zero-retention claim is made.Provider data-use terms: Gemini API paid-services data-use terms

Google Workspace APIs

Current registry · verify detailsPurpose: User-directed Drive, Gmail, and Calendar connectionsData category: Selected files, email content, calendar events, account identity, and OAuth metadataLocation: Google-managed; no XESO region-fixed representationDPA: User-authorized connector under the applicable Google account and API termsCertifications: See the Google trust centre; this is not an XESO certificationOAuth scopes are limited by connector and access occurs only after the user connects it.On disconnect: Disconnect deletes XESO's OAuth credential. Notes already imported remain until the user deletes them; Calendar must be reconnected for future access.

Microsoft Graph

Current registry · verify detailsPurpose: Optional user-directed Microsoft calendar connectionData category: Calendar events, account identity, and OAuth metadataLocation: Per the user's Microsoft account and tenantDPA: User-authorized connector under the applicable Microsoft account termsCertifications: See the Microsoft trust centre; this is not an XESO certificationOn disconnect: Disconnect deletes XESO's OAuth credential. Previously stored calendar records follow the account deletion and export lifecycle.

Tavily

Current registry · verify detailsPurpose: Web search for user-requested research answersData category: Search query and returned public-web resultsLocation: Provider-managedDPA: Current production integration; contract and transfer evidence remain under reviewCertifications: See the Tavily provider terms; this is not an XESO certificationServing revision check on 2026-09-04 found TAVILY_API_KEY bound by secret reference. Tavily's current terms permit use of customer input to improve its services, so XESO does not present Tavily as carrying a no-training guarantee.Provider data-use terms: Tavily platform data-use terms

Cloudflare Turnstile

Current registry · verify detailsPurpose: Automated-abuse protection on authenticationData category: Browser, network, challenge, and verification metadataLocation: Cloudflare-managedDPA: Current login protection; contractual evidence remains under reviewCertifications: See the Cloudflare trust centre; this is not an XESO certificationThe server credential is being migrated from plaintext runtime configuration to Secret Manager.

FingerprintJS

Current registry · verify detailsPurpose: Configuration-dependent fraud and abuse signalsData category: Browser and device signal metadataLocation: Provider-managedDPA: Optional; do not enable without current contract and privacy evidenceCertifications: See the provider trust centre; this is not an XESO certification

Upstash / QStash

Current registry · verify detailsPurpose: Configuration-dependent queue deliveryData category: Task route, signed delivery metadata, and bounded job payloadLocation: Provider-managedDPA: Optional; no serving QSTASH_TOKEN was present on 2026-09-04Certifications: See the provider trust centre; this is not an XESO certification

Zoho CRM

Current registry · verify detailsPurpose: Optional user-directed CRM import and synchronizationData category: Selected CRM contacts, deals, fields, attachments, and OAuth metadataLocation: Per the user's selected Zoho data centreDPA: The customer/controller must have a lawful basis to import CRM personal data; XESO acts only on the user's authorized requestCertifications: See the Zoho trust centre; this is not an XESO certificationServing revision check on 2026-09-04 found the connector credentials bound by secret reference.On disconnect: Disconnect removes the connection and OAuth credential. Notes already imported remain in the Library until the user deletes them.

Granola and Readwise

Current registry · verify detailsPurpose: Optional user-directed import from connected knowledge servicesData category: Selected meeting notes, highlights, source links, and connector credentialsLocation: Provider-managedDPA: User-authorized source access; provider contract and transfer evidence remain under reviewCertifications: See each provider's terms; this is not an XESO certificationOn disconnect: Disconnect removes the connector credential. Content already imported remains until the user deletes it.

YouTube, X/Twitter mirrors, and Wikimedia

Current registry · verify detailsPurpose: User-requested retrieval of public source materialData category: Submitted public URL, network metadata, and returned public contentLocation: Provider-managedDPA: External content sources, not represented as contracted XESO subprocessorsCertifications: No XESO certification claimRequests may reach YouTube, X/Twitter syndication or mirror services, and Wikipedia/Wikimedia only when a user asks XESO to import or retrieve that source.

Groq

Current registry · verify detailsPurpose: Optional audio transcription fallback when GROQ_API_KEY is configuredData category: Audio chunks and transcripts for user-requested media importsLocation: United StatesDPA: Pending - do not enable in production without DPACertifications: Vendor review required before production enablementCode path is gated by GROQ_API_KEY; leave unset unless legal approval is complete.Provider data-use terms: Groq customer-data and model-training terms

OpenAI

Current registry · verify detailsPurpose: Optional BYOK LLM inference when a user supplies their own OpenAI keyData category: User query + retrieved snippets for BYOK requestsLocation: Per OpenAI API regionDPA: User-elected provider termsCertifications: User-selected provider; account terms varyThe serving revision had no platform OPENAI_API_KEY on 2026-09-04. OpenAI is used only when a user configures their own provider key; platform TTS/transcription therefore remains unavailable.On disconnect: Removing the BYOK credential stops new requests. Existing XESO notes and answers remain until the user deletes them.Provider data-use terms: OpenAI API data-use and training terms

Anthropic

Current registry · verify detailsPurpose: Optional BYOK LLM inference when a user supplies their own Anthropic keyData category: User query + retrieved snippets for BYOK requestsLocation: Per Anthropic API regionDPA: User-elected provider termsCertifications: User-selected provider; account terms varyOnly used when a user configures their own provider key.On disconnect: Removing the BYOK credential stops new requests. Existing XESO notes and answers remain until the user deletes them.

Stripe

Current registry · verify detailsPurpose: Billing, subscription management, invoicingData category: Payment metadata (PANs never stored by XESO), billing emailLocation: United StatesDPA: Current Stripe terms apply; signed-evidence claim is not yet approvedCertifications: See the Stripe trust centre; this is not an XESO certification

Resend

Current registry · verify detailsPurpose: Transactional email delivery (magic links, digests)Data category: Email address, email subject, bodyLocation: United StatesDPA: Current Resend terms apply; signed-evidence claim is not yet approvedCertifications: See the Resend trust centre; this is not an XESO certificationFull note bodies are never emailed.

PostHog

Current registry · verify detailsPurpose: Product analytics (self-host fallback to PostHog Cloud)Data category: Pseudonymous user ID, event names, event properties (PII-stripped)Location: United StatesDPA: Conditional provider; do not enable without current contract and DPA evidenceCertifications: See the provider trust centre; this is not an XESO certificationIP addresses are anonymised at ingest; users may opt out in settings.

Sentry

Current registry · verify detailsPurpose: Error monitoring and performance tracesData category: Stack traces, request metadata, scrubbed user contextLocation: United StatesDPA: Conditional provider; do not enable without current contract and DPA evidenceCertifications: See the provider trust centre; this is not an XESO certificationPII scrubbing filters applied before ingest; optional — only enabled when SENTRY_DSN is set.

GitHub

Current registry · verify detailsPurpose: Source code, CI, SBOM publicationData category: Source code, commit metadata, built artifactsLocation: United StatesDPA: Development and CI provider; contract evidence remains internally reviewedCertifications: See the GitHub trust centre; this is not an XESO certification

International transfers

Some providers may process data outside the user's country. The applicable transfer mechanism depends on the provider, account, and current contract and may include Standard Contractual Clauses or another lawful mechanism. XESO does not present a transfer or regional-residency claim as complete until the supporting account and contract evidence has been reviewed.

Change notification

Material new subprocessors are added here and announced to subscribed customers before they begin processing customer personal data where the applicable agreement requires notice. Customers can raise an objection by emailing subprocessors@xeso.ai within the period stated in that notice.

Contact

Amalgam Holdings Pty Ltd Email: subprocessors@xeso.ai Postal: available on request.