Sub-processors

Effective 30 July 2026

Nelkins Technologies uses the third parties below to operate Broker OS. Each processes data only for the stated service purpose and under applicable contractual and security controls. Provider access is limited to permissions the user or administrator has authorised.

Sub-processorPurposeData handled
VercelApplication hosting and deliveryRequest metadata, application traffic and operational logs
Managed PostgreSQL database hostPrimary application data storageTenant operational data and encrypted credentials
GoogleGoogle OAuth, Gmail sending and authorised read-only mailbox accessConnected identity, OAuth grants, messages sent by the user, authorised message metadata and bounded previews
MicrosoftMicrosoft identity, Graph email sending and delegated mailbox synchronisationConnected identity, OAuth grants, messages sent by the user, authorised message metadata and bounded previews
StripeSubscription billingBilling contact, customer and subscription identifiers; card details remain with Stripe
SentryError monitoringError events and diagnostic metadata configured to minimise personal data
WhatsApp Business or configured messaging providerOutbound messaging the user triggersRecipient, message content and delivery metadata
Configured email delivery providerTransactional and operational emailRecipient address, message content and delivery metadata
Approved AI inference provider(s)User-facing drafting and Nelkins Intelligence featuresTenant-scoped prompt context required for the requested result; not authorised for shared-model training

We will give notice of material changes to this list. Questions or DPA requests can be sent to privacy@nelkins-os.xyz.