VeillantVeillantBack to home

Subprocessors

Last updated: August 25, 2026

Veillant uses the third-party subprocessors below to deliver the Service. Each processes data only as needed for its stated purpose and under its own data-protection commitments. Your authorization for these subprocessors is given in our Data Processing Agreement (Section 5), which also gives you the right to object to a change on data-protection grounds.

How we announce changes

Before a new subprocessor begins processing caller data, we publish it on this page and notify customers who have registered an address for that purpose at least 30 days in advance, as committed in the Data Processing Agreement. To register for these notices, email privacy@veillant.eu with the subject "Subprocessor notices". Every material change to this list is recorded in the change log below, dated.

Infrastructure subprocessors

SubprocessorPurpose of processingLocation(s)Caller dataIn service sinceMore info
VercelWeb application hosting & content deliveryUSA / Global edgeYesJune 2026Link
RailwayReal-time voice WebSocket server hostingUSAYesJune 2026Link
NeonPostgreSQL database hostingEU (Frankfurt)YesJune 2026Link

Platform subprocessors

SubprocessorPurpose of processingLocation(s)Caller dataIn service sinceMore info
OpenAIAI language & real-time voice processing; end-of-call analysis to derive aggregate analytics. Training on our API data is disabled and API request logging is disabled; per OpenAI's published policy, API abuse-monitoring logs are retained for up to 30 days, then deletedUSA for processing; the contracting entity for EEA customers is OpenAI Ireland LtdYesJune 2026Link
TwilioTelephony, inbound phone calls only (the assistant never places calls or sends messages). Call audio is not retained; call metadata including the caller's number is retained by Twilio for up to 120 daysEU (Ireland, ie1) for call processing; metadata partly in the USAYesJune 2026Link
ResendEmail delivery of escalation notices to the business; the email may carry the caller's phone number, name and a short AI-written summary. Resend keeps the content of a sent email and its delivery metadata for a maximum of 30 days after sending, then deletes them automaticallyUSA (stored in the United States regardless of the sending region)YesJune 2026Link
GoogleAuthentication (Sign in with Google)USANo — account data onlyJune 2026Link

Payment subprocessors

SubprocessorPurpose of processingLocation(s)Caller dataIn service sinceMore info
StripeSubscription billing & payment processingUSA / EUNo — account data onlyJuly 2026Link

Change log

  • August 25, 2026: OpenAI's row corrected and completed, after reading the data processing agreement we executed with them on August 20, 2026 and their published API documentation. The contracting entity for a European customer is OpenAI Ireland Ltd while processing happens in the United States, so "USA" alone told half the story, the same half the Twilio row used to hide. The row also now states what OpenAI's published policy says about retention: API abuse-monitoring logs are kept for up to 30 days and then deleted. This page already stated Twilio's and Resend's retention; staying silent on OpenAI's was the inconsistency. Also stated: training on our API data and API request logging are both disabled for our organization. Nothing changed in what we do: this is us describing a provider accurately after reading their own paper.
  • August 21, 2026: Twilio's purpose corrected from "inbound/outbound phone calls" to inbound only: the assistant never places calls or sends messages, an automated check in our build enforces it, and the old wording described Twilio's product rather than our use of it. Nothing changed in what we do.
  • August 21, 2026: Resend's row now states how long they keep what we send them. They confirmed to us in writing on August 21, 2026 that the content of a sent email and its delivery metadata are both kept for a maximum of 30 days after sending and are then deleted automatically, that this period is fixed on their standard plans, and that the data is stored in the United States regardless of which region an email is sent from. Nothing changed in what we do or who we use: this is us describing a provider accurately after asking them directly.
  • August 20, 2026: The contact address for subprocessor notices and registrations changed from hello@veillant.eu to privacy@veillant.eu, a dedicated data-protection mailbox. The list itself is unchanged.
  • August 18, 2026: Twilio's row corrected with what they confirmed to us in writing on August 15, 2026. Calls are processed in their Irish region and the contracting entity for a Danish company is Twilio Ireland Limited, so "USA" was wrong; but their own transfer assessment still places metadata in the United States, so "EU" would be wrong too, and the row now says both. It also states for the first time that Twilio retains call metadata, including the caller's phone number, for up to 120 days. Call audio is not retained, which they confirmed in the same answer. Nothing changed in what we do: this is us describing a provider accurately after asking them directly.
  • August 6, 2026: Neon's location corrected to EU (Frankfurt): that is where our database actually runs, measured on the provider's API. "USA / EU" described the provider's footprint, not our data. And a "Caller data" column now shows which providers touch callers' data and which only process your account data (Google, Stripe), a distinction the DPA already made in Annex I.
  • August 1, 2026: Resend added to this list. Correction, not a new engagement: it has delivered escalation emails since the feature existed, and this list should have said so from the start.
  • July 9, 2026: Initial publication.

Contact

For any question about this list, contact us at privacy@veillant.eu. For more on how we handle data, see our Privacy Policy.

Legal

Terms of ServicePrivacy PolicyData Processing AgreementCookies PolicyAI PolicySubprocessorsHow your call is handled

Legal

Terms of ServicePrivacy PolicyData Processing AgreementCookies PolicyAI PolicySubprocessorsHow your call is handled