Sub-processors
Last updated: 2026-07-18
Voxly engages the third parties listed below to operate the platform and deliver our service. We sign data processing agreements with each and require them to provide the same level of data protection that we provide to you under our own DPA.
Customer-opt-in connectors (Jira, Slack, Zapier, and others added to the Connectors marketplace) are sub-processors only for workspaces that explicitly install them. If your workspace has not connected a given provider, no data flows to it.
We give 30 days' advance notice of any new sub-processor before they begin processing customer data. Change notices are emailed automatically to each customer's billing contact. How change notices work.
Running a security review? Our DPA template (PDF) includes this list as a schedule, alongside SCC elections and our technical and organisational measures. The live list on this page is authoritative.
Infrastructure
| Vendor | Purpose | Location | Tier | Added | Links |
|---|---|---|---|---|---|
Vercel Inc. Vercel | Application hosting, edge network, CDN, and serverless function execution. | United States (multi-region) | C0-C3 | 2026-03-17 | DPA · Privacy |
Supabase Inc. Supabase | Managed PostgreSQL database, authentication, storage, and Vault for encrypted secrets. | United States (AWS, multi-region) | C0-C4 | 2026-03-17 | DPA · Privacy |
Observability
Communications
Payments
AI services
| Vendor | Purpose | Location | Tier | Added | Links |
|---|---|---|---|---|---|
Anthropic, PBC Anthropic | LLM-powered feedback summarisation and categorisation (Claude API). Voxly does not allow Anthropic to retain prompts for training (zero-retention enrolment). | United States (AWS) | C2 | 2026-04-15 | DPA · Privacy |
OpenAI, L.L.C. OpenAI | Embedding generation for semantic feedback search. API access only; prompts not retained for training under our zero-retention agreement. | United States | C2 | 2026-04-15 | DPA · Privacy |
Customer-opt-in connectors
| Vendor | Purpose | Location | Tier | Added | Links |
|---|---|---|---|---|---|
Atlassian Pty Ltd / Atlassian, Inc. Atlassian (Jira) · opt-in only | Customer-opt-in connector. When a workspace admin connects Jira, Voxly relays feedback content the admin chooses to push, plus OAuth tokens stored in Voxly Vault, to Atlassian. Voxly never accesses the customer's Jira data outside the explicit push action. | United States (AWS), Europe | C2 | 2026-04-29 | DPA · Privacy |
Slack Technologies, LLC Slack · opt-in only | Customer-opt-in connector. When a workspace admin connects Slack, Voxly posts notifications to the channels the admin selects. OAuth tokens stored in Voxly Vault. | United States (AWS) | C2 | 2026-04-29 | DPA · Privacy |
Zapier, Inc. Zapier · opt-in only | Customer-opt-in connector. When a workspace admin enables Zapier, Voxly delivers trigger payloads (feedback events) to Zaps the admin configures. Authentication is via a Voxly-issued API key. | United States (AWS) | C2 | 2026-04-29 | DPA · Privacy |
Linear Orbit, Inc. Linear · opt-in only | Customer-opt-in connector. When a workspace admin connects Linear, Voxly creates Linear issues from feedback the admin chooses to promote. OAuth tokens stored in Voxly Vault; Voxly never reads Linear data outside the connected organization. | United States (GCP) | C2 | 2026-07-15 | DPA · Privacy |
GitHub, Inc. GitHub · opt-in only | Customer-opt-in connector. When a workspace admin connects GitHub, Voxly creates GitHub issues from feedback the admin chooses to promote. OAuth tokens stored in Voxly Vault; access is limited to repositories the authorizing account can reach. | United States (multi-region) | C2 | 2026-07-15 | DPA · Privacy |
Zendesk, Inc. Zendesk · opt-in only | Customer-opt-in connector. When a workspace admin connects Zendesk (subdomain + agent API token, stored in Voxly Vault), tagged support tickets can be converted into Voxly feedback. Voxly only reads tickets surfaced by the admin-configured trigger. | United States (AWS), EU pods available | C2 | 2026-07-15 | DPA · Privacy |
Intercom, Inc. Intercom · opt-in only | Customer-opt-in connector. When a workspace admin connects Intercom, qualified support conversations can be converted into Voxly feedback. OAuth tokens stored in Voxly Vault; app permissions are configured read-only for conversations. | United States (AWS), EU/AU hosting available | C2 | 2026-07-15 | DPA · Privacy |
HubSpot, Inc. HubSpot · opt-in only | Customer-opt-in connector. When a workspace admin connects HubSpot, Voxly logs feedback activity on matching HubSpot contacts (contacts read/write scopes only). OAuth tokens stored in Voxly Vault. | United States (AWS), EU data residency available | C2 | 2026-07-15 | DPA · Privacy |
Discord Inc. Discord · opt-in only | Customer-opt-in connector. When a workspace admin attaches a Discord webhook to an AlertConfig rule, Voxly POSTs notification payloads to the channel the webhook addresses. The webhook URL itself (which is the credential) is stored in Voxly Vault; Discord never receives Voxly credentials. No PortalUser PII is sent unless the workspace admin includes it in the alert template. For the webhook-outbound model, the workspace admin's acceptance of the Discord Developer Terms of Service is the operative agreement governing data handling. | United States (GCP, multi-region) | C2 | 2026-07-18 | DPA · Privacy |
Total current sub-processors: 16.