Legal

Sub-processors

Last updated: 2026-09-30

KnoxCall uses the following sub-processors to deliver its service. We notify customers at least 30 days before adding or removing a sub-processor via:

  • Email to account owners
  • This page
  • A privacy-change notification in the admin UI

To object to a sub-processor addition, email [email protected] within 14 days of notification.

Current Sub-processors

Sub-processor Purpose Data categories Region(s) DPA status Certifications
DigitalOcean Compute, Postgres, Redis, object storage (Spaces) All customer data US (New York): application servers and primary database. Static-IP egress servers: the region selected for each, one of US, UK, EU (Germany, Netherlands), Australia or Singapore Signed ISO 27001:2013, SOC 2 Type II, CSA STAR Level 2
Cloudflare CDN, WAF, DDoS, DNS, mTLS termination All customer traffic transiting the edge Global edge Signed ISO 27001:2022, SOC 2 Type II, PCI DSS, FedRAMP Moderate
Stripe Payment processing, billing Billing identifiers, payment instruments US, EU Signed (built into TOS) PCI DSS Level 1, SOC 1 + 2 Type II, ISO 27001
AWS (S3 Object Lock) Immutable audit-log archive Audit log records US Signed ISO 27001, SOC 1/2/3 Type II, PCI DSS, FedRAMP High
Resend Transactional email Recipient email + message contents US, EU In progress (template signed; awaiting countersign) SOC 2 Type II (in progress)
Klaviyo Marketing email (optional, customer-opt-in) Recipient email US In progress SOC 2 Type II, ISO 27001
Twilio SMS for MFA fallback Recipient phone, MFA codes US, AU In progress SOC 2 Type II, ISO 27001, HIPAA-eligible
Anthropic Claude API (AI features when enabled by tenant) Prompt contents (after PII redaction) US Signed — Zero-Retention Mode SOC 2 Type II, ISO 27001
MaxMind GeoIP2 dataset (IP-to-region) Inbound IP addresses US Licensing terms — no customer data transferred n/a
Grafana Cloud Operator metrics (proxied request counts and latency) Aggregate counters and latency histograms, dimensioned by tenant_id, route name, environment and HTTP status class. No request or response content, and no identifiers of individuals EU Not yet executed SOC 2 Type II, ISO 27001
Sentry Application error tracking (admin UI + backend) Error events (stack traces, an opaque error ID, tenant_id + user UUID tags) and warn/error application log lines. No names, no email addresses, no request bodies, no cookies or IP addresses; request path only, never the query string. Every line passes through our secret-redaction grammar before it leaves the process. Retained 90 days (error events) and 30 days (log lines) EU (Frankfurt) Not yet executed SOC 2 Type II, ISO 27001

Notes

  • "DPA status: Signed" means a written Data Processing Addendum is in force.
  • "DPA status: In progress" means we are using the sub-processor under their standard Terms of Service while the DPA is in countersign.
  • All cross-border transfers from the EEA/UK rely on Standard Contractual Clauses; we make these available on request.

How to Subscribe to Changes

  • Email subscribers: tick the privacy-update box at sign-up or in Settings → Privacy.
  • In-app: every admin sees a notification badge when a new sub-processor entry is added.

Historical Changes

Date Change Effective
2026-06-01 First publication of sub-processor list 2026-06-01
2026-09-02 Added Sentry (application error tracking, EU region) 2026-09-02
2026-09-02 Added Grafana Cloud (operator metrics, EU region) 2026-09-02
2026-09-30 Corrected DigitalOcean's regions: named the New York hosting region and the regions static-IP egress servers can run in (the UK and Singapore were missing) 2026-09-30

Contact

Privacy: [email protected]

Mail: KnoxCall Limited, Auckland, New Zealand