Keldio
FeaturesPricingContactGet Started
Legal

Subprocessor List

The current list of Keldio Subprocessors, Tenant-Configured Providers, and external agent or AI provider categories relevant to Keldio data flows.

Keldio Subprocessor List

Last updated: 17 August 2026 Effective date: 6 May 2026 Document version: 1.0

This Subprocessor List supports the Keldio Data Processing Agreement. It identifies the main third-party providers involved in operating Keldio and distinguishes between:

  1. Keldio Subprocessors — providers Keldio uses on Keldio's account to provide the Services.
  2. Tenant-Configured Providers — providers a Tenant connects using the Tenant's own account, credentials, domain, or provider relationship.
  3. External Agent / AI Providers — systems a Tenant or Tenant-authorised operator connects to Keldio using API keys, MCP keys, browser access, or other authorised access.

This distinction matters. Keldio does not currently provide its own built-in large language model or AI agent runtime as part of the platform by default. Keldio enables Tenants to connect external agents and AI systems to the platform. Those external systems are not Keldio Subprocessors merely because a Tenant connects them.

1. Keldio Subprocessors

These providers process data on Keldio's account as part of the Keldio platform infrastructure.

ProviderPurposeLocation / transfer noteData involved
Vercel Inc.Hosting, edge compute, routing, custom-domain infrastructureGlobal edge / US provider; SCCs or equivalent transfer mechanism where requiredRequest data, page content, logs, technical data, Customer Content served through hosted pages
Supabase Inc.PostgreSQL database, object storage, authentication-adjacent infrastructure, backups, row-level security supportEU primary configuration where available; SCCs for non-EEA fallback/supportCustomer Data, Customer Personal Data, Workspace data, files, operational records
Clerk Inc.Authentication for Admin Users and Members, owner/admin provisioning, invitations, session management, and magic-link/sign-in flowsUS provider; SCCs / DPF where applicableUser identity, email, name, session/authentication data, roles, owner/admin/support/member metadata, tenant-membership metadata, team invitation metadata, account-switching metadata, Member login data
Svix Inc.Webhook infrastructure used for selected inbound/provider webhook handling, including Clerk webhook verification where applicableUS provider; SCCs / DPF where applicableWebhook metadata, identifiers, event payloads where routed through Svix
Cloudflare, Inc.DNS, security, caching, edge/network services, and Cloudflare Stream where Keldio uses a Keldio-controlled accountGlobal; SCCs / DPF where applicableRequest metadata, IP addresses, security logs, video/content metadata where applicable
Amazon Web Services, Inc. / Amazon SESManaged outbound email delivery, inbound email handling, email event ingestion, suppression and reputation infrastructure, object storage and queueing related to email flows where Keldio uses Keldio-controlled AWS/SES accountsEU/US/global infrastructure depending on AWS service configuration; SCCs or equivalent transfer mechanism where requiredSender and recipient email addresses, message metadata, message content where routed through SES/inbound storage, attachment metadata/content where applicable, delivery/open/click/bounce/complaint events, suppression and reputation metadata

Conditional / feature-specific Keldio Subprocessors. Some providers become Keldio Subprocessors only when Keldio uses a Keldio-controlled provider account for the relevant feature. If the feature is not enabled for a Workspace, or if the Tenant uses its own provider account, the provider may not process that Workspace's Customer Personal Data as a Keldio Subprocessor for that flow.

ProviderPurposeLocation / transfer noteData involved
Twilio Inc.SMS, WhatsApp, carrier messaging, delivery-status events, inbound-message handling, and related messaging infrastructure where Keldio uses a Keldio-controlled Twilio account or platform-managed messaging serviceUS/global telecommunications infrastructure; SCCs/DPF or equivalent transfer mechanism where requiredSender and recipient phone numbers, message body/content, media URLs where used, consent/opt-out/help signals, provider status/error metadata, carrier delivery metadata

2. Tenant-Configured Providers

These providers are connected by the Tenant using the Tenant's own account, credentials, domain, or provider relationship. They process data under the Tenant's contract with that provider. They are generally not Keldio Subprocessors for that Tenant-configured flow.

Security and incident responsibility follows control of the provider relationship. Where Keldio uses its own provider account to deliver the service, that provider may be a Keldio Subprocessor as listed here. Where a Tenant connects its own provider account, OAuth grant, mailbox, payment account, phone number, social profile, webhook endpoint, AI/agent tool, or other external service, that provider is normally Tenant-configured and the Tenant is responsible for its authority, terms, security settings, provider incidents, and related End-User notices.

Tenant-selected embeds, scripts, widgets, media players, pixels, analytics tools, form processors, redirect destinations, and other third-party services placed by a Tenant on a Keldio-hosted public page are Tenant-Configured Providers or Tenant-selected recipients for that flow. They are not Keldio Subprocessors merely because the page is hosted on Keldio infrastructure, unless Keldio separately engages that provider on Keldio's own account to provide the Services.

Vimeo embeds, Cloudflare Stream BYO mode, Tenant-supplied video providers, Tenant-connected AI/content tools, and other external systems used by a Tenant for course, community, media, or member portal content are Tenant-Configured Providers or independent providers for the Tenant unless Keldio separately lists them as Keldio Subprocessors for a Keldio-operated service. Supabase object storage remains a Keldio Subprocessor when Keldio stores Customer Content on Keldio-controlled infrastructure.

ProviderPurposeTenant relationshipData involved
Mailgun Technologies, Inc.Email delivery, sending domains, suppression lists, engagement eventsTenant supplies Mailgun key/domain or sending configuration where applicableRecipient email, sender, subject, message body, delivery events, suppression identifiers
Tenant-selected DNS registrars, DNS hosts, mailbox providers, domain hosts, email providers, and webhook endpointsDomain ownership, DNS, mailbox hosting, email routing, and Tenant-selected communications endpointsTenant owns, selects, or contracts with the providerDNS records, sender-domain records, mailbox data, webhook payloads, recipient and message data depending on Tenant configuration

| Twilio Inc. | SMS and WhatsApp messaging where the Tenant connects or authorises its own Twilio account, phone number, Messaging Service, WhatsApp sender, template, or carrier messaging configuration | Tenant controls the Twilio relationship, sender authority, provider terms, carrier obligations, and message compliance | Sender/recipient phone numbers, message content, templates, opt-in/opt-out records, delivery events, status/error metadata, and carrier/provider responses | | Microsoft Corporation / Microsoft 365 / Outlook / Microsoft Graph | Tenant mailbox sync, message retrieval, sending, status, and related mailbox/calendar-provider operations where configured | Tenant controls the Microsoft account, OAuth grant, mailbox, domain, permissions, provider terms, and retention settings | Mailbox identifiers, email addresses, message headers, message content, attachments where fetched or sent, folder/cursor metadata, OAuth/token status, sync status, provider errors, and related logs | | Tenant-selected IMAP/SMTP mailbox hosts and mailbox providers | Tenant mailbox sync, inbound message retrieval, SMTP sending, sent-folder append, and mailbox status testing | Tenant controls the mailbox/provider account, host, credentials, folder configuration, retention, and provider terms | Mailbox identifiers, email addresses, message headers, message content, attachments where fetched or sent, folder/cursor metadata, sync status, provider errors, and related logs | | Mollie B.V. | Payment processing | Tenant has or connects Mollie account where applicable | Buyer identity, payment metadata, order references, transaction status; card/bank details remain with Mollie | | Stripe, Inc. / Stripe Connect | Payment method setup, payment processing, subscriptions, checkout where used | Tenant connects Stripe or Keldio checkout uses Stripe as described in checkout flow | Buyer identity, customer IDs, setup intent/payment intent IDs, subscription/payment metadata; card details remain with Stripe | | Cloudflare Stream in BYO mode | Tenant video hosting and delivery | Tenant connects Tenant-controlled Cloudflare account | Video files, video metadata, viewer/request metadata | | Bundle.social | Hosted social-account connection, social media profile/page/channel connector, social post scheduling, media handoff, publish-status updates, and related social integration operations where enabled | Tenant connects or authorises social accounts/profiles/pages/channels through Bundle.social; downstream social networks remain Tenant-selected destinations or independent providers for the Tenant's publishing instructions | Social account identifiers, profile/page/channel metadata, display names/usernames, post captions, uploaded media or media URLs, scheduling metadata, provider status/error details, platform responses, external post IDs/URLs |

| Meta Platforms, Inc. / Facebook / Instagram / Threads | Social profile/page connection and Tenant social publishing where configured | Tenant controls or authorises the relevant social account, profile, page, business account, permissions, and platform relationship | Social account/page identifiers, captions, media, scheduling and publication metadata, comments/status/error information, external post URLs | | TikTok Pte. Ltd. / TikTok social tools | Social profile connection and Tenant social publishing where configured | Tenant controls or authorises the relevant TikTok account and platform relationship | Social account identifiers, captions, videos/media, scheduling and publication metadata, status/error information, external post URLs | | LinkedIn / Microsoft group entities social tools | LinkedIn profile or organisation page connection and Tenant social publishing where configured | Tenant controls or authorises the relevant LinkedIn profile/page/company account and platform relationship | Account/page identifiers, captions, media, scheduling and publication metadata, status/error information, external post URLs | | X Corp. / Twitter social tools | X/Twitter account connection and Tenant social publishing where configured | Tenant controls or authorises the relevant X/Twitter account and platform relationship | Account identifiers, captions, media, scheduling and publication metadata, status/error information, external post URLs | | Google LLC / YouTube | YouTube channel connection and Tenant video/social publishing where configured | Tenant controls or authorises the relevant YouTube/Google account, channel, permissions, and platform relationship | Channel/account identifiers, video media or URLs, titles/descriptions, scheduling and publication metadata, status/error information, external video URLs | | Meta Platforms, Inc. | Meta Conversions API, pixels, ad attribution, business tools | Tenant controls Meta Business / ad account configuration | Hashed identifiers, IP, user agent, click IDs, conversion events, attribution metadata | | TikTok Pte. Ltd. / TikTok group entities | TikTok Events API, ad attribution, business tools | Tenant controls TikTok Business configuration | Hashed identifiers, IP, user agent, click IDs, conversion events, attribution metadata | | Google LLC | Google Ads, conversion measurement, analytics or tag-related integrations where configured | Tenant controls Google account configuration | Click IDs, conversion events, hashed identifiers where configured, analytics/ad metadata |

| LinkedIn / Microsoft group entities | LinkedIn Insight Tag, advertising attribution, campaign measurement, and related business tools where configured | Tenant controls the LinkedIn/Microsoft advertising account or pixel configuration | Partner ID, page/event metadata, IP/user-agent or browser metadata, attribution and conversion metadata where configured | | X Corp. / Twitter advertising tools | X/Twitter Pixel, advertising attribution, campaign measurement, and related business tools where configured | Tenant controls the X/Twitter advertising account or pixel configuration | Pixel ID, page/event metadata, browser/request metadata, attribution and conversion metadata where configured |

| Google LLC / Google Calendar / Google Meet | Calendar availability checks, busy-block sync, event creation/cancellation, conferencing links, and meeting metadata where a Tenant connects its own Google account or selects Google calendar features | Tenant controls the Google account, OAuth grant, selected calendars, provider settings, conferencing settings, and Google relationship | Calendar identifiers, busy/free intervals, appointment time, booker/host names or email addresses where included in events, meeting-link metadata, provider event IDs, provider errors | | Vimeo, Inc. | Legacy video embeds where used | Tenant or Keldio legacy content relationship depending on configuration | Embedded video delivery metadata, viewer/request metadata | | Webhook endpoints selected by Tenant | Delivery of Keldio event payloads to Tenant systems | Tenant owns or selects endpoint | Event payloads, contact/order/member data included in the configured event |

3. External Agent / AI Providers

Keldio's platform exposes APIs and MCP tools that allow a Tenant to connect external agents, scripts, automation systems, or AI systems. Keldio does not, by default, provide a built-in LLM that processes Tenant data inside the platform.

Where a Tenant, Admin User, agency, implementation partner, or Tenant-authorised operator connects an external AI system or agent runtime, that provider processes data under the Tenant's or operator's relationship with that provider. Examples may include:

Provider / system typeExample purposeStatus
OpenAIExternal agent reasoning, drafting, analysis, workflow execution when connected by a Tenant/operatorExternal Agent / AI Provider unless separately engaged by Keldio
AnthropicExternal agent reasoning, drafting, analysis, workflow execution when connected by a Tenant/operatorExternal Agent / AI Provider unless separately engaged by Keldio
Google Gemini / Google AI servicesExternal agent reasoning, analysis, or media understanding when connected by a Tenant/operatorExternal Agent / AI Provider unless separately engaged by Keldio
OpenClaw or other agent runtimesAgent orchestration, MCP/API execution, operational automationExternal Agent / AI Provider or Tenant/operator tool unless separately engaged by Keldio
Self-hosted models or scriptsTenant-operated automation or AI workflowsTenant-controlled system

If Keldio later engages an AI provider on Keldio's own account to process Customer Personal Data as part of the Keldio Services, Keldio will list that provider as a Keldio Subprocessor or otherwise update this list and the applicable legal terms.

4. Provider role notes

Some providers can appear in more than one role depending on configuration. For example:

  • Cloudflare may be a Keldio Subprocessor when Keldio uses a Keldio-controlled Cloudflare account, but a Tenant-Configured Provider when the Tenant connects its own Cloudflare account.
  • Cloudflare Stream is a Keldio Subprocessor only when Keldio's own Cloudflare account is used for video hosting or delivery. In BYO mode it is Tenant-configured. Vimeo legacy embeds are external video embeds or Tenant/Keldio legacy content references as applicable and should not be treated as Keldio-managed course delivery guarantees.
  • Stripe may process Keldio subscription checkout data for Keldio's own paid plans and may also process Tenant-to-End-User payment data where a Tenant uses Stripe Connect.
  • Stripe Connect may involve Keldio using a platform-level Stripe key to create onboarding links or route API calls to a Tenant's connected Stripe account. For Tenant-to-End-User transactions, the connected account and related provider relationship remain Tenant-controlled unless Keldio expressly states otherwise for a specific Keldio-operated service.
  • Mollie and Stripe may process Keldio's own plan checkout, billing, subscription, refund, and accounting records as providers for Keldio's customer relationship with the Tenant. For Tenant-to-End-User transactions, they are generally Tenant-Configured Providers or independent payment-service providers for the Tenant's transaction, depending on the connected account and checkout configuration.
  • Mailgun may process Keldio operational email or Tenant email depending on configuration, sending domain, and account ownership.
  • Mailgun may be a Tenant-Configured Provider when a Tenant supplies its own Mailgun account, domain, or credentials. If Keldio uses Mailgun from a Keldio-controlled account for Keldio-managed platform email or fallback delivery, Mailgun should be listed as a Keldio Subprocessor for that specific managed flow.
  • AI providers are not automatically Keldio Subprocessors merely because an external agent connected by a Tenant can access the Tenant's Workspace.

Client-side pixels, tags, scripts, analytics tools, and advertising destinations selected or configured by a Tenant are Tenant-Configured Providers or Tenant-selected recipients. Keldio hosting the page, serving the tracker, or transmitting an event on the Tenant's instructions does not make those providers Keldio Subprocessors unless Keldio separately engages them on Keldio's own account for a Keldio-operated service and lists them as Keldio Subprocessors.

Google Calendar, Google Meet, Microsoft calendar tools, conferencing tools, mailbox providers, and similar scheduling providers are Tenant-Configured Providers when connected by the Tenant or a Tenant-authorised user. They are not Keldio Subprocessors for that flow unless Keldio separately uses a Keldio-controlled account to provide a managed scheduling service and lists that provider as a Keldio Subprocessor.

  • Bundle.social may be used as a connector between Keldio and Tenant-selected social networks for social profile connection and publishing. Unless Keldio later offers a Keldio-controlled first-party managed social service and lists Bundle.social or the relevant social network as a Keldio Subprocessor for that service, Bundle.social and the downstream social platforms are treated as Tenant-Configured Providers or Tenant-selected recipients for the Tenant's social publishing instructions.
  • Twilio, Microsoft, mailbox providers, Cloudflare Stream, Mailgun, Stripe, and similar providers may appear in different legal roles depending on whether Keldio or the Tenant controls the relevant account and provider relationship. Keldio classifies each provider by flow, not by brand name alone.
  • External agents, API clients, MCP clients, implementation partners, contractors, and customer-controlled automation clients are not Keldio Subprocessors merely because they receive Tenant-issued credentials or act through a Workspace. The Tenant is responsible for deciding whether those parties are its processors, subprocessors, authorised users, independent providers, or other recipients under the Tenant's own legal arrangements.

Cooperation with a provider, platform, payment network, email network, social network, hosting provider, law-enforcement authority, regulator, or abuse desk during an abuse, security, payment-risk, provider-risk, or AUP investigation does not by itself change that provider's legal role. A Tenant-configured provider, external agent, AI system, webhook recipient, or social platform remains Tenant-configured or external for the relevant flow unless Keldio separately engages it on Keldio's own account as a Keldio Subprocessor and lists it here.

5. Subprocessor changes

Keldio may add, replace, or remove Subprocessors in accordance with the Data Processing Agreement. Keldio will maintain this list and provide notice of material Subprocessor changes where required.

Tenants may object to a new or replacement Keldio Subprocessor on reasonable data-protection grounds as described in the DPA.

6. Contact

Questions about Keldio Subprocessors can be sent to:

  • legal@keldio.com
  • support@keldio.com
Keldio

The agent-first platform for building and scaling your online business.

Product
FunnelsEmailCRMBillingLMS
Resources
ContactPricing
Legal
Legal TermsAcceptable Use PolicySubprocessor ListPrivacy PolicyPlatform TermsData Processing AgreementWebsite Terms
© 2026 Keldio. All rights reserved.