Skip to main content

[ Privacy ]

Sub-processors

Effective
August 6, 2026
Version
2026-08-06

This document provides a complete, exhaustive list of all third-party sub-processors that process personal data on behalf of Syntax Voice. It forms part of the Data Processing Addendum and serves as Annex III of the Standard Contractual Clauses.

01 / Voice and Media Processing

These providers process live audio and text to facilitate real-time conversations.

  • Deepgram. Provides primary speech-to-text for live calls and console transcripts, as well as failover text-to-speech.
  • Cartesia. Provides primary text-to-speech. Receives the assistant’s reply text only; it does not receive inbound caller audio.
  • Google Cloud Speech-to-Text. Acts strictly as a speech-to-text failover.

02 / AI and Language Models

These providers generate assistant replies, summaries, and triage decisions. We do not train models on your data, and we do not sell personal data.

  • OpenAI. Serves as the primary language model. We programmatically redact Social Security numbers and payment card patterns before transmission, and medical terms and phone numbers for HIPAA-restricted workspaces.
  • Anthropic. Serves as the failover language model.
  • Google (Gemini). Serves as an alternative language model, used only if configured by your workspace.

03 / Communications and Telephony

  • Twilio. Powers inbound and outbound calling, SMS and MMS, web chat (Conversations), call recording storage, and A2P 10DLC campaign registration via Trust Hub.
  • Browser push services. Apple, Google, and Mozilla deliver encrypted dashboard notifications. They route the payload without the ability to read it.

04 / Infrastructure and Hosting

  • Amazon Web Services. Hosts the core voice application (EC2), databases (RDS), storage (S3), and key management (KMS).
  • Vercel. Hosts the dashboard, marketing site, and API routes. Vercel does not process or receive call audio.
  • Upstash. Manages Redis rate-limiting for the dashboard. Upstash does not process conversation content.

05 / Business Operations

  • Stripe. Handles subscription billing and checkout. Payment card numbers never reach Syntax Voice servers.
  • Resend. Delivers transactional emails, including call summaries and operational alerts.
  • Sentry. Provides error tracking and sampled session replays for the dashboard and marketing site. Replays do not capture call audio or monitor your end customers, and medical terminology is scrubbed before transmission.

06 / Optional Integrations

Data flows to these providers only if actively enabled by your workspace.

  • Calendars (Google Calendar and Microsoft Graph). Read availability and write appointment details such as attendee names, phone numbers, emails, and notes.
  • Google Places. Looks up public business details during onboarding. Receives no caller data.
  • HubSpot. Connects via OAuth, storing encrypted tokens. No contact records are currently synchronized.
  • Custom endpoints. If you configure outbound webhooks or transfer destinations, you act as the data controller for that onward transfer.

07 / Providers That Receive No Personal Data

  • Cloudflare. Provides DNS and control-plane configuration only. It does not process call audio, transcripts, or message content.
  • Unbuilt integrations. Platforms named in our marketing (ServiceTitan, Housecall Pro, Buildium, ModivCare, Jobber) are not currently integrated and receive zero data.
  • SSO providers. Google and GitHub act as independent controllers if you use them to sign into your dashboard.

08 / Changes and Notifications

We will notify workspace owners via email 30 days before adding or replacing a sub-processor. You have 30 days from the notice date to object to the new sub-processor on reasonable data protection grounds by emailing hello@syntaxvoice.com.