Skip to main content

Privacy

Subprocessor register

Last reviewed: August 1, 2026

This register includes Mylla-appointed subprocessors, conditional feature providers, and recipients selected directly by a business. Conditional providers process data only when the related feature is enabled. Contractual checks still in progress are stated openly below.

A business-directed recipient receives data only after a business or account user connects that service. The business holds or controls that provider relationship and must verify its DPA, transfer terms, configuration, and downstream recipients.

Amazon Web Services (AWS)
Subprocessor

EC2, ECS, S3, SSM, CloudWatch

Purpose: Voice infrastructure, compute, encrypted object storage, backups, and operational monitoring.

Data: Call audio, recordings, transcripts, service metadata, and limited operational logs.

Processing locations: European Union and United States, depending on environment and workload.

DPA status: AWS DPA is incorporated into the AWS Service Terms.

Transfer mechanism: EU SCC Modules 2 and 3 apply to restricted transfers; EEA processing is used where configured.

Review provider terms
Google (Gemini)
Subprocessor

Gemini API

Purpose: Realtime voice-model processing for Mylla’s default pipeline, optional text reasoning in a split pipeline, and extraction, OCR, and digestion of uploaded or imported knowledge-base material.

Data: Live call audio for realtime sessions; prompt or transcript context and model responses for configured text-model sessions; knowledge-base document bytes, source URLs, and extracted text.

Processing locations: Global, including the United States.

DPA status: Google publishes a Cloud Data Processing Addendum; Gemini API account coverage remains under operator verification.

Transfer mechanism: Google publishes SCC protections for covered services; Gemini API product mapping remains under operator verification.

Review provider terms
Google (Firebase Cloud Messaging)
Conditional subprocessor

Firebase Cloud Messaging

Purpose: Deliver privacy-safe Companion App notifications to Android devices.

Data: Device push token, delivery metadata, privacy-safe notification copy, and opaque request, business, and delivery-deduplication identifiers. The payload contains no caller details.

Processing locations: Global, including the United States.

DPA status: Google publishes a Cloud Data Processing Addendum; Firebase account coverage remains under operator verification.

Transfer mechanism: Google publishes SCC protections for covered services; Firebase product mapping remains under operator verification.

Review provider terms
OpenAI
Subprocessor

API services

Purpose: Optional realtime or split-pipeline speech recognition, text reasoning, and speech synthesis; post-call diarization and structured processing; selected assistant features; and knowledge-base search embeddings.

Data: Live audio when OpenAI realtime or speech recognition is selected; transcript or prompt text for reasoning and synthesis; call recordings and structured outputs for post-call processing; extracted knowledge-base text chunks and embedding metadata.

Processing locations: European Union and United States, depending on the contracting entity and service.

DPA status: OpenAI publishes an API DPA; organization-level acceptance and retention settings remain under operator verification.

Transfer mechanism: EU SCC Module 2 applies when Mylla is controller and Module 3 when Mylla is processor, where required.

Review provider terms
Deepgram
Conditional subprocessor

Speech-to-text API

Purpose: Transcribe live caller audio when an administrator selects Deepgram for a split voice pipeline.

Data: Live call audio, language or recognition hints, timing metadata, and generated transcript text.

Processing locations: United States, or a dedicated European Union endpoint when explicitly configured and available for the account.

DPA status: Deepgram states that it enters DPAs with customers; Mylla’s account-level DPA and endpoint configuration remain under operator verification.

Transfer mechanism: DPA and SCC coverage for Mylla’s account remains under operator verification.

Review provider terms
Cartesia
Conditional subprocessor

Text-to-speech API

Purpose: Generate agent speech when an administrator selects Cartesia for a split voice pipeline.

Data: Transcript-derived response text, voice and synthesis settings, and generated audio.

Processing locations: United States and provider support locations.

DPA status: Cartesia’s terms reference an incorporated DPA where applicable; Mylla’s account-level coverage remains under operator verification.

Transfer mechanism: Published transfer safeguards and Mylla’s account-level mechanism remain under operator verification.

Review provider terms
ElevenLabs
Conditional subprocessor

Text-to-speech API

Purpose: Generate agent speech when an administrator selects ElevenLabs for a split voice pipeline.

Data: Transcript-derived response text, voice and synthesis settings, and generated audio.

Processing locations: Global, including the United States and European Union.

DPA status: ElevenLabs publishes a DPA; organization-level acceptance and service settings remain under operator verification.

Transfer mechanism: The ElevenLabs DPA includes EU SCC Modules 2 and 3 and a UK addendum; account-level coverage remains under operator verification.

Review provider terms
Supabase
Subprocessor

Database, authentication, and storage

Purpose: Business accounts, authentication, application data, and stored call artifacts.

Data: Account, caller, request, customer, transcript, configuration, and audit data; uploaded knowledge-base documents, source metadata, and extracted knowledge text.

Processing locations: European Union and other support locations identified by Supabase.

DPA status: Supabase publishes a DPA; account and plan acceptance remain under operator verification.

Transfer mechanism: EU SCC Module 2 or Module 3, according to Mylla’s role.

Review provider terms
Vercel
Subprocessor

Web hosting, functions, Analytics, and Speed Insights

Purpose: Serve the web application, execute API routes, and measure aggregate reliability and performance.

Data: Request data, account and application payloads handled by functions, IP-derived metadata, and performance events.

Processing locations: Global infrastructure, including the European Union and United States.

DPA status: Vercel publishes a DPA for covered Pro and Enterprise services; current plan coverage remains under operator verification.

Transfer mechanism: EU SCCs and the UK transfer addendum for covered restricted transfers.

Review provider terms
Twilio
Subprocessor

Voice, phone numbers, SIP, and SMS

Purpose: Telephony routing, phone-number management, call signaling, and configured SMS delivery.

Data: Caller and recipient phone numbers, call and message metadata, routing data, and content required for the selected service.

Processing locations: Global, including the United States.

DPA status: Twilio’s DPA forms part of the customer agreement.

Transfer mechanism: Twilio Binding Corporate Rules for covered services and EU SCCs for other restricted transfers.

Review provider terms
Twilio SendGrid
Subprocessor

Transactional email

Purpose: Send invitations, request notifications, and service emails.

Data: Recipient email address, message content, delivery metadata, and template variables.

Processing locations: Global, including the United States.

DPA status: Covered by the Twilio DPA and its SendGrid-specific terms.

Transfer mechanism: EU SCCs apply to SendGrid restricted transfers where required.

Review provider terms
Stripe
Processor and independent controller

Payments, subscriptions, tax, and billing

Purpose: Process payments, manage subscriptions, prevent fraud, and meet financial obligations.

Data: Business contact, billing, tax, transaction, and payment-method data. Full card details do not pass through Mylla servers.

Processing locations: Global, including the European Union and United States.

DPA status: Stripe’s DPA forms part of its Services Agreement.

Transfer mechanism: Data Privacy Framework where applicable, backed by EU SCCs and the UK addendum.

Review provider terms
Sentry (Functional Software)
Subprocessor

Error monitoring and diagnostics

Purpose: Detect crashes, delivery failures, performance problems, and security-relevant errors.

Data: Error traces, route and release metadata, device or browser details, opaque identifiers, and limited network metadata.

Processing locations: United States and provider support locations.

DPA status: Sentry makes a DPA available in the organization account; execution status remains under operator verification.

Transfer mechanism: Published provider transfer terms apply; Mylla’s account-level mechanism remains under operator verification.

Review provider terms
Linear (Linear Orbit, Inc.)
Subprocessor

Issue tracking and incident triage

Purpose: Track product work and receive operational diagnostic context when a signed production Sentry alert creates or updates an incident issue.

Data: Error title, route, Sentry and project identifiers or links, environment and release metadata, stack-frame details and source context, and any business or customer identifiers present in that diagnostic context after limited secret redaction.

Processing locations: Primary processing in the United States; authorized subprocessors may also operate in the European Union or globally.

DPA status: Linear publishes a DPA incorporated through its agreement; Mylla’s account-level acceptance remains under operator verification.

Transfer mechanism: EU SCC Modules 2 and 3 and the UK Addendum apply to covered restricted transfers; account-level coverage remains under operator verification.

Review provider terms
Expo (650 Industries)
Conditional subprocessor

Expo Push Service and EAS

Purpose: Deliver Companion App notifications and support mobile build and release operations.

Data: Push tokens, installation identifiers, platform and app-version metadata, privacy-safe notification copy, and opaque request, business, and delivery-deduplication identifiers. The payload contains no caller details.

Processing locations: United States and provider support locations.

DPA status: Expo’s service terms include processor obligations; standalone account documentation remains under operator verification.

Transfer mechanism: EU SCCs and Data Privacy Framework commitments described in Expo’s published terms.

Review provider terms
Apple
Conditional subprocessor

Apple Push Notification service

Purpose: Deliver privacy-safe Companion App notifications to Apple devices.

Data: Device push token, delivery metadata, privacy-safe notification copy, and opaque request, business, and delivery-deduplication identifiers. The payload contains no caller details.

Processing locations: Global Apple infrastructure.

DPA status: Governed by Apple developer and platform terms; no separate Mylla DPA is recorded.

Transfer mechanism: Provider terms and applicable statutory transfer safeguards; contractual review remains pending.

Browser-selected Web Push services
Conditional subprocessor

Web Push delivery (for example, Google, Mozilla, or Apple endpoints)

Purpose: Deliver browser notifications after a user enables Web Push for Mylla.

Data: Push subscription endpoint, encrypted notification payload, and delivery metadata.

Processing locations: Global infrastructure selected by the user’s browser and push-service operator.

DPA status: The user’s browser selects the push-service operator; provider mapping and Mylla account-level contractual coverage remain under operator verification.

Transfer mechanism: Provider terms and applicable statutory safeguards; endpoint-specific transfer review remains pending.

Microsoft
Business-directed recipient

Microsoft sign-in and Outlook Calendar

Purpose: Optional account authentication and calendar availability or booking features.

Data: Account profile and email; calendar identifiers, availability, and event details when connected.

Processing locations: Global Microsoft infrastructure.

DPA status: Microsoft publishes data-protection terms; the connecting business or account owner must verify its agreement covers the selected service.

Transfer mechanism: The connecting business is responsible for confirming an applicable transfer mechanism under its Microsoft agreement.

Review provider terms
Google (connected account services)
Business-directed recipient

Google sign-in and Google Calendar

Purpose: Authenticate an account or check availability and create calendar events when a user connects Google.

Data: Account profile and email; calendar identifiers, availability, and event details when connected.

Processing locations: Global Google infrastructure.

DPA status: Google publishes data-protection terms; the connecting business or account owner must verify its agreement covers the selected service.

Transfer mechanism: The connecting business is responsible for confirming an applicable transfer mechanism under its Google agreement.

Review provider terms
Calendly
Business-directed recipient

Calendly scheduling

Purpose: Read scheduling configuration and availability when a business connects its Calendly account.

Data: Connected-account identity, event types, scheduling links, availability, and booking metadata.

Processing locations: United States and other locations described in Calendly’s provider documentation.

DPA status: Calendly publishes a DPA incorporated into its customer terms; the connecting business must verify its account coverage.

Transfer mechanism: Calendly’s DPA includes EU SCCs and a UK addendum; the connecting business must confirm they apply to its account.

Review provider terms
Cal.com
Business-directed recipient

Cal.com scheduling

Purpose: Check availability and create bookings when a business connects a Cal.com cloud or self-hosted account.

Data: Event types, availability, attendee name and email, timezone, booking time, and optional booking notes.

Processing locations: The business-selected Cal.com cloud or self-hosted deployment.

DPA status: Cal.com publishes DPA materials through its Trust Center; self-hosted terms depend on the business-selected operator.

Transfer mechanism: The connecting business must confirm the mechanism for its selected Cal.com deployment.

Review provider terms
Asana
Business-directed recipient

Asana project tasks

Purpose: Create project tasks from call requests when a business connects Asana.

Data: Connected-account identity, workspace and project identifiers, caller or request details, summaries, and task notes.

Processing locations: Global, including the United States.

DPA status: Asana publishes a DPA; the connecting business must verify that its account agreement covers the integration.

Transfer mechanism: Asana publishes Data Privacy Framework and SCC safeguards; the connecting business must confirm the applicable mechanism.

Review provider terms
Slack (Salesforce)
Business-directed recipient

Slack incoming webhooks

Purpose: Send new request notifications to a channel selected by the business.

Data: Caller name or phone number, request summary, request link, channel metadata, and delivery status.

Processing locations: The business-selected Slack workspace and its configured data region.

DPA status: Slack makes a DPA available to customers; the connecting business must verify its workspace agreement.

Transfer mechanism: The connecting business must confirm the transfer mechanism that applies to its Slack workspace.

Review provider terms
HubSpot
Business-directed recipient

HubSpot CRM

Purpose: Search, create, or update CRM contacts when a business connects HubSpot.

Data: Connected-account identity, caller name, phone number, email, inquiry summary, language, and selected contact properties.

Processing locations: Locations selected or provided under the business’s HubSpot account.

DPA status: HubSpot publishes a DPA incorporated into its customer terms; the connecting business must verify account coverage.

Transfer mechanism: HubSpot publishes transfer safeguards in its DPA; the connecting business must confirm the applicable mechanism.

Review provider terms
Zapier
Business-directed recipient

Webhooks by Zapier

Purpose: Send configured call and lead events to a Zap selected by the business.

Data: Caller details, inquiry summary, language, call duration, recording URL, status, custom fields, and event metadata.

Processing locations: Global, including the United States.

DPA status: Zapier’s DPA is incorporated into its terms; the connecting business must verify that its account and downstream Zap steps are covered.

Transfer mechanism: Zapier’s DPA includes SCCs; the connecting business must also assess every downstream service used by its Zap.

Review provider terms
Business-selected webhook or MCP provider
Business-directed recipient

Custom webhook and MCP connector

Purpose: Send configured events or allow an agent to call external tools chosen and configured by the business.

Data: For webhooks: configured call, caller, request, and recording fields. For MCP: tool inputs and outputs required by the selected external tool.

Processing locations: The endpoint and hosting locations selected by the business.

DPA status: No single provider agreement applies. The business is responsible for its agreement with the endpoint operator.

Transfer mechanism: The business must assess and document any restricted transfer created by its selected endpoint.

Self-hosted LiveKit

Mylla uses LiveKit's open-source software on Mylla-managed AWS infrastructure. Mylla does not use LiveKit Cloud for these calls, so LiveKit is not a separate subprocessor and a LiveKit DPA or cross-border transfer mechanism is not applicable to this deployment.

Questions or objections? Email support@mylla.ai or review the Privacy Policy.