Skip to content

SUB-PROCESSORS

Sub-processors

Vendors visible in the Amevia codebase that may process personal data when the matching feature is turned on.

Last updated: 19 August 2026

1Current sub-processors (from product code)

Vendors that may process customer or visitor data when the feature is enabled
VendorRoleTypical dataNotes
Infrastructure host (VPS) + PostgreSQLApplication and database hostingService data including conversations and accountsCountry of the server is not published until verified
StripePaid billingBilling email, customer and subscription identifiers — card data stays with StripeUsed when paid checkout is configured
GoogleOptional account sign-in (OAuth)Email, name, subject identifier after the user clicks Continue with GoogleNot used unless the user chooses Google sign-in
Transactional email (SMTP and/or Resend)Account and notification emailRecipient address and message contentWhich path is live depends on environment configuration
DeepSeek and/or local OllamaGenerate agent repliesVisitor question and retrieved knowledge snippets needed for a replyDeepSeek involves a transfer whose legal tool is not yet published
DiscordOptional human handoffConversation excerpts posted to a customer-connected channelOnly if the customer enables Discord
Customer OpenCart/WHMCS MySQL (optional)Read-only store enrichment in MonitorStore profile/order fields the customer authorisesProcessed in the customer’s database; Amevia uses a read-only connection the customer configures

Vendor

Infrastructure host (VPS) + PostgreSQL

Role

Application and database hosting

Typical data

Service data including conversations and accounts

Notes

Country of the server is not published until verified

Vendor

Stripe

Role

Paid billing

Typical data

Billing email, customer and subscription identifiers — card data stays with Stripe

Notes

Used when paid checkout is configured

Vendor

Google

Role

Optional account sign-in (OAuth)

Typical data

Email, name, subject identifier after the user clicks Continue with Google

Notes

Not used unless the user chooses Google sign-in

Vendor

Transactional email (SMTP and/or Resend)

Role

Account and notification email

Typical data

Recipient address and message content

Notes

Which path is live depends on environment configuration

Vendor

DeepSeek and/or local Ollama

Role

Generate agent replies

Typical data

Visitor question and retrieved knowledge snippets needed for a reply

Notes

DeepSeek involves a transfer whose legal tool is not yet published

Vendor

Discord

Role

Optional human handoff

Typical data

Conversation excerpts posted to a customer-connected channel

Notes

Only if the customer enables Discord

Vendor

Customer OpenCart/WHMCS MySQL (optional)

Role

Read-only store enrichment in Monitor

Typical data

Store profile/order fields the customer authorises

Notes

Processed in the customer’s database; Amevia uses a read-only connection the customer configures

2Updates

This page is the public sub-processor list referenced by the DPA. It does not include secret hostnames or credentials.

Sub-processors — Amevia