Privacy
Subprocessor register
Last reviewed: August 1, 2026
This register includes Mylla-appointed subprocessors, conditional feature providers, and recipients selected directly by a business. Conditional providers process data only when the related feature is enabled. Contractual checks still in progress are stated openly below.
A business-directed recipient receives data only after a business or account user connects that service. The business holds or controls that provider relationship and must verify its DPA, transfer terms, configuration, and downstream recipients.
EC2, ECS, S3, SSM, CloudWatch
Purpose: Voice infrastructure, compute, encrypted object storage, backups, and operational monitoring.
Data: Call audio, recordings, transcripts, service metadata, and limited operational logs.
Processing locations: European Union and United States, depending on environment and workload.
DPA status: AWS DPA is incorporated into the AWS Service Terms.
Transfer mechanism: EU SCC Modules 2 and 3 apply to restricted transfers; EEA processing is used where configured.
Review provider termsGemini API
Purpose: Realtime voice-model processing for Mylla’s default pipeline, optional text reasoning in a split pipeline, and extraction, OCR, and digestion of uploaded or imported knowledge-base material.
Data: Live call audio for realtime sessions; prompt or transcript context and model responses for configured text-model sessions; knowledge-base document bytes, source URLs, and extracted text.
Processing locations: Global, including the United States.
DPA status: Google publishes a Cloud Data Processing Addendum; Gemini API account coverage remains under operator verification.
Transfer mechanism: Google publishes SCC protections for covered services; Gemini API product mapping remains under operator verification.
Review provider termsFirebase Cloud Messaging
Purpose: Deliver privacy-safe Companion App notifications to Android devices.
Data: Device push token, delivery metadata, privacy-safe notification copy, and opaque request, business, and delivery-deduplication identifiers. The payload contains no caller details.
Processing locations: Global, including the United States.
DPA status: Google publishes a Cloud Data Processing Addendum; Firebase account coverage remains under operator verification.
Transfer mechanism: Google publishes SCC protections for covered services; Firebase product mapping remains under operator verification.
Review provider termsAPI services
Purpose: Optional realtime or split-pipeline speech recognition, text reasoning, and speech synthesis; post-call diarization and structured processing; selected assistant features; and knowledge-base search embeddings.
Data: Live audio when OpenAI realtime or speech recognition is selected; transcript or prompt text for reasoning and synthesis; call recordings and structured outputs for post-call processing; extracted knowledge-base text chunks and embedding metadata.
Processing locations: European Union and United States, depending on the contracting entity and service.
DPA status: OpenAI publishes an API DPA; organization-level acceptance and retention settings remain under operator verification.
Transfer mechanism: EU SCC Module 2 applies when Mylla is controller and Module 3 when Mylla is processor, where required.
Review provider termsSpeech-to-text API
Purpose: Transcribe live caller audio when an administrator selects Deepgram for a split voice pipeline.
Data: Live call audio, language or recognition hints, timing metadata, and generated transcript text.
Processing locations: United States, or a dedicated European Union endpoint when explicitly configured and available for the account.
DPA status: Deepgram states that it enters DPAs with customers; Mylla’s account-level DPA and endpoint configuration remain under operator verification.
Transfer mechanism: DPA and SCC coverage for Mylla’s account remains under operator verification.
Review provider termsText-to-speech API
Purpose: Generate agent speech when an administrator selects Cartesia for a split voice pipeline.
Data: Transcript-derived response text, voice and synthesis settings, and generated audio.
Processing locations: United States and provider support locations.
DPA status: Cartesia’s terms reference an incorporated DPA where applicable; Mylla’s account-level coverage remains under operator verification.
Transfer mechanism: Published transfer safeguards and Mylla’s account-level mechanism remain under operator verification.
Review provider termsText-to-speech API
Purpose: Generate agent speech when an administrator selects ElevenLabs for a split voice pipeline.
Data: Transcript-derived response text, voice and synthesis settings, and generated audio.
Processing locations: Global, including the United States and European Union.
DPA status: ElevenLabs publishes a DPA; organization-level acceptance and service settings remain under operator verification.
Transfer mechanism: The ElevenLabs DPA includes EU SCC Modules 2 and 3 and a UK addendum; account-level coverage remains under operator verification.
Review provider termsDatabase, authentication, and storage
Purpose: Business accounts, authentication, application data, and stored call artifacts.
Data: Account, caller, request, customer, transcript, configuration, and audit data; uploaded knowledge-base documents, source metadata, and extracted knowledge text.
Processing locations: European Union and other support locations identified by Supabase.
DPA status: Supabase publishes a DPA; account and plan acceptance remain under operator verification.
Transfer mechanism: EU SCC Module 2 or Module 3, according to Mylla’s role.
Review provider termsWeb hosting, functions, Analytics, and Speed Insights
Purpose: Serve the web application, execute API routes, and measure aggregate reliability and performance.
Data: Request data, account and application payloads handled by functions, IP-derived metadata, and performance events.
Processing locations: Global infrastructure, including the European Union and United States.
DPA status: Vercel publishes a DPA for covered Pro and Enterprise services; current plan coverage remains under operator verification.
Transfer mechanism: EU SCCs and the UK transfer addendum for covered restricted transfers.
Review provider termsVoice, phone numbers, SIP, and SMS
Purpose: Telephony routing, phone-number management, call signaling, and configured SMS delivery.
Data: Caller and recipient phone numbers, call and message metadata, routing data, and content required for the selected service.
Processing locations: Global, including the United States.
DPA status: Twilio’s DPA forms part of the customer agreement.
Transfer mechanism: Twilio Binding Corporate Rules for covered services and EU SCCs for other restricted transfers.
Review provider termsTransactional email
Purpose: Send invitations, request notifications, and service emails.
Data: Recipient email address, message content, delivery metadata, and template variables.
Processing locations: Global, including the United States.
DPA status: Covered by the Twilio DPA and its SendGrid-specific terms.
Transfer mechanism: EU SCCs apply to SendGrid restricted transfers where required.
Review provider termsPayments, subscriptions, tax, and billing
Purpose: Process payments, manage subscriptions, prevent fraud, and meet financial obligations.
Data: Business contact, billing, tax, transaction, and payment-method data. Full card details do not pass through Mylla servers.
Processing locations: Global, including the European Union and United States.
DPA status: Stripe’s DPA forms part of its Services Agreement.
Transfer mechanism: Data Privacy Framework where applicable, backed by EU SCCs and the UK addendum.
Review provider termsError monitoring and diagnostics
Purpose: Detect crashes, delivery failures, performance problems, and security-relevant errors.
Data: Error traces, route and release metadata, device or browser details, opaque identifiers, and limited network metadata.
Processing locations: United States and provider support locations.
DPA status: Sentry makes a DPA available in the organization account; execution status remains under operator verification.
Transfer mechanism: Published provider transfer terms apply; Mylla’s account-level mechanism remains under operator verification.
Review provider termsIssue tracking and incident triage
Purpose: Track product work and receive operational diagnostic context when a signed production Sentry alert creates or updates an incident issue.
Data: Error title, route, Sentry and project identifiers or links, environment and release metadata, stack-frame details and source context, and any business or customer identifiers present in that diagnostic context after limited secret redaction.
Processing locations: Primary processing in the United States; authorized subprocessors may also operate in the European Union or globally.
DPA status: Linear publishes a DPA incorporated through its agreement; Mylla’s account-level acceptance remains under operator verification.
Transfer mechanism: EU SCC Modules 2 and 3 and the UK Addendum apply to covered restricted transfers; account-level coverage remains under operator verification.
Review provider termsExpo Push Service and EAS
Purpose: Deliver Companion App notifications and support mobile build and release operations.
Data: Push tokens, installation identifiers, platform and app-version metadata, privacy-safe notification copy, and opaque request, business, and delivery-deduplication identifiers. The payload contains no caller details.
Processing locations: United States and provider support locations.
DPA status: Expo’s service terms include processor obligations; standalone account documentation remains under operator verification.
Transfer mechanism: EU SCCs and Data Privacy Framework commitments described in Expo’s published terms.
Review provider termsApple Push Notification service
Purpose: Deliver privacy-safe Companion App notifications to Apple devices.
Data: Device push token, delivery metadata, privacy-safe notification copy, and opaque request, business, and delivery-deduplication identifiers. The payload contains no caller details.
Processing locations: Global Apple infrastructure.
DPA status: Governed by Apple developer and platform terms; no separate Mylla DPA is recorded.
Transfer mechanism: Provider terms and applicable statutory transfer safeguards; contractual review remains pending.
Web Push delivery (for example, Google, Mozilla, or Apple endpoints)
Purpose: Deliver browser notifications after a user enables Web Push for Mylla.
Data: Push subscription endpoint, encrypted notification payload, and delivery metadata.
Processing locations: Global infrastructure selected by the user’s browser and push-service operator.
DPA status: The user’s browser selects the push-service operator; provider mapping and Mylla account-level contractual coverage remain under operator verification.
Transfer mechanism: Provider terms and applicable statutory safeguards; endpoint-specific transfer review remains pending.
Microsoft sign-in and Outlook Calendar
Purpose: Optional account authentication and calendar availability or booking features.
Data: Account profile and email; calendar identifiers, availability, and event details when connected.
Processing locations: Global Microsoft infrastructure.
DPA status: Microsoft publishes data-protection terms; the connecting business or account owner must verify its agreement covers the selected service.
Transfer mechanism: The connecting business is responsible for confirming an applicable transfer mechanism under its Microsoft agreement.
Review provider termsGoogle sign-in and Google Calendar
Purpose: Authenticate an account or check availability and create calendar events when a user connects Google.
Data: Account profile and email; calendar identifiers, availability, and event details when connected.
Processing locations: Global Google infrastructure.
DPA status: Google publishes data-protection terms; the connecting business or account owner must verify its agreement covers the selected service.
Transfer mechanism: The connecting business is responsible for confirming an applicable transfer mechanism under its Google agreement.
Review provider termsCalendly scheduling
Purpose: Read scheduling configuration and availability when a business connects its Calendly account.
Data: Connected-account identity, event types, scheduling links, availability, and booking metadata.
Processing locations: United States and other locations described in Calendly’s provider documentation.
DPA status: Calendly publishes a DPA incorporated into its customer terms; the connecting business must verify its account coverage.
Transfer mechanism: Calendly’s DPA includes EU SCCs and a UK addendum; the connecting business must confirm they apply to its account.
Review provider termsCal.com scheduling
Purpose: Check availability and create bookings when a business connects a Cal.com cloud or self-hosted account.
Data: Event types, availability, attendee name and email, timezone, booking time, and optional booking notes.
Processing locations: The business-selected Cal.com cloud or self-hosted deployment.
DPA status: Cal.com publishes DPA materials through its Trust Center; self-hosted terms depend on the business-selected operator.
Transfer mechanism: The connecting business must confirm the mechanism for its selected Cal.com deployment.
Review provider termsAsana project tasks
Purpose: Create project tasks from call requests when a business connects Asana.
Data: Connected-account identity, workspace and project identifiers, caller or request details, summaries, and task notes.
Processing locations: Global, including the United States.
DPA status: Asana publishes a DPA; the connecting business must verify that its account agreement covers the integration.
Transfer mechanism: Asana publishes Data Privacy Framework and SCC safeguards; the connecting business must confirm the applicable mechanism.
Review provider termsSlack incoming webhooks
Purpose: Send new request notifications to a channel selected by the business.
Data: Caller name or phone number, request summary, request link, channel metadata, and delivery status.
Processing locations: The business-selected Slack workspace and its configured data region.
DPA status: Slack makes a DPA available to customers; the connecting business must verify its workspace agreement.
Transfer mechanism: The connecting business must confirm the transfer mechanism that applies to its Slack workspace.
Review provider termsHubSpot CRM
Purpose: Search, create, or update CRM contacts when a business connects HubSpot.
Data: Connected-account identity, caller name, phone number, email, inquiry summary, language, and selected contact properties.
Processing locations: Locations selected or provided under the business’s HubSpot account.
DPA status: HubSpot publishes a DPA incorporated into its customer terms; the connecting business must verify account coverage.
Transfer mechanism: HubSpot publishes transfer safeguards in its DPA; the connecting business must confirm the applicable mechanism.
Review provider termsWebhooks by Zapier
Purpose: Send configured call and lead events to a Zap selected by the business.
Data: Caller details, inquiry summary, language, call duration, recording URL, status, custom fields, and event metadata.
Processing locations: Global, including the United States.
DPA status: Zapier’s DPA is incorporated into its terms; the connecting business must verify that its account and downstream Zap steps are covered.
Transfer mechanism: Zapier’s DPA includes SCCs; the connecting business must also assess every downstream service used by its Zap.
Review provider termsCustom webhook and MCP connector
Purpose: Send configured events or allow an agent to call external tools chosen and configured by the business.
Data: For webhooks: configured call, caller, request, and recording fields. For MCP: tool inputs and outputs required by the selected external tool.
Processing locations: The endpoint and hosting locations selected by the business.
DPA status: No single provider agreement applies. The business is responsible for its agreement with the endpoint operator.
Transfer mechanism: The business must assess and document any restricted transfer created by its selected endpoint.
Self-hosted LiveKit
Mylla uses LiveKit's open-source software on Mylla-managed AWS infrastructure. Mylla does not use LiveKit Cloud for these calls, so LiveKit is not a separate subprocessor and a LiveKit DPA or cross-border transfer mechanism is not applicable to this deployment.
Questions or objections? Email support@mylla.ai or review the Privacy Policy.