Trust
Sub-processors
Version 2026-09-27 · Effective September 27, 2026
These are the companies that process personal information for us while we run Sona. Each one receives only what its job needs. This list is part of our Data Processing Addendum.
| Provider | What it does | What reaches it | When |
|---|---|---|---|
| Twilio | Telephony: the phone numbers, inbound call routing, call transfer, the live speech pipeline (ConversationRelay) and, when a business turns recording on, the call recording. | Call audio, the caller's phone number and call metadata. Recordings are copied to our storage and then deleted at Twilio. | Always |
| Amazon Web Services: Amazon S3 | Stores call recordings: when a business turns recording on, Twilio uploads each finished recording to our storage bucket on Amazon S3, where it is kept and played back from. | The call recording, kept for the business's recording retention period and then deleted. | When a business turns recording on and the platform stores recordings through Twilio's external storage. |
| Deepgram (through Twilio) | Speech recognition: turns the caller's speech into text during the call. | Call audio, in real time. | When a business's receptionist uses a Deepgram speech model (the default). |
| Google (through Twilio) | Speech recognition and synthesized voices. | Call audio (recognition) or the receptionist's reply text (voice). | When a business selects a Google speech model or voice. |
| Amazon Web Services: Amazon Polly (through Twilio) | Synthesized voices. | The receptionist's reply text. | When a business selects an Amazon Polly voice. |
| ElevenLabs (through Twilio) | Synthesized voices. | The receptionist's reply text. | When a business selects an ElevenLabs voice. |
| Anthropic | The language model that decides what the receptionist says and which action it takes. | The text of the live conversation and the business's receptionist instructions. | When a business's receptionist uses a Claude model (the default). |
| OpenAI | Embeddings for the knowledge base (turning a business's pages, documents and FAQs, and a caller's question to them, into search vectors), and the language model when a business selects an OpenAI model. | Knowledge-base text and the words of a caller's question to it, sent without any phone number or call identifier. Conversation text only if an OpenAI model is selected. | When a business uses the knowledge base, or selects an OpenAI model. |
| Supabase | Database, file storage and sign-in for the dashboard. | All service data at rest: accounts, configuration, call records, transcripts, recordings, messages, appointments and knowledge-base content. | Always |
| Vercel | Hosts this website, the customer dashboard and our billing endpoints. | Web requests (including IP address and browser details), request logs, and the dashboard pages a signed-in user views. | Always |
| Voice service hosting provider (to be named before publication) | Runs the voice service: call routing, the live conversation, the receptionist's tools and the post-call workers. | Everything a call produces passes through it: conversation text, tool actions, messages, appointments and, when recording is on, the recording on its way to storage. | Always |
| Stripe | Subscription billing, invoices, card payments and wallet credit. Card details are entered in Stripe's own fields and never reach our servers. | The billing contact, card details and the usage we invoice. | When a business subscribes to a paid plan or adds wallet credit. |
| Microsoft (Microsoft 365) | Email: sends the email alerts a business asks for (a post-call summary after each call an agent answers, for agents that have it switched on, and alerts for messages taken and for appointments booked, moved or cancelled) and the account emails (sign-up confirmation and password reset), receives the email sent to our contact addresses, and carries the messages visitors send through the contact form on our home page to that mailbox. | The recipient's email address and the email's content. For an alert: the last four digits of the caller's number, the call's length and outcome, the caller's name, callback number, reason and appointment time, and a note when the receptionist told the caller to hang up and dial 911. Never a transcript or a recording. For an account email: the confirmation or reset link. For a contact-form message: the name, email address and message the visitor wrote. | Alerts when a business has email alerts switched on; account emails whenever someone signs up or resets a password; a contact-form message whenever a visitor sends one. |
About the speech providers
Speech recognition and synthesized voices run inside Twilio's ConversationRelay service, which passes audio or text to the provider selected for each business's receptionist. Only the providers a business's configuration selects receive its calls.
Changes to this list
Before a new sub-processor starts processing personal information for our customers, we update this page and email each workspace's editors at least 30 days in advance, as the Data Processing Addendum describes. Questions or objections: legal@bizefy.dev.
Not on this list
The marketing site opens Calendly's booking page in a window when you choose to book a call with us; if you use it, you deal with Calendly directly and no customer or caller data is sent to it. The business you called, and the people it invites to its dashboard, are not sub-processors: the information is theirs.