Legal
Sub-processors
The complete list of suppliers that can reach personal data held in Dialspire, what each one does for us, and exactly what it sees.
Last updated 21 August 2026
Draft, pending professional review. This document describes how Dialspire actually works today, but it has not been reviewed by a solicitor and some details are still to be filled in. Please don’t rely on it as a final statement of our obligations.
What this page is
Article 28(2) of the UK GDPR says a processor may not bring in another processor without its customer’s authorisation. Our data processing agreement gives us general authorisation to use the suppliers on this page, and this page is where we keep that list honest and current.
Each of these suppliers is bound by a contract imposing the same data protection obligations we owe you, and we remain liable to you for what they do.
Where a supplier is listed as processing outside the UK, the location is as published by that supplier. Confirm it against their current data processing agreement before relying on this table for your own record of processing.
Always in use
These four are involved in running the service for every customer, all of the time.
| Supplier | What it does for us | Personal data it can reach | Where |
|---|---|---|---|
| Vercel | Runs and serves the application | All data in transit through the app; operational request logs including IP addresses | United States, edge delivery worldwide ([VERCEL DEPLOYMENT REGION]) |
| Neon | Managed PostgreSQL — the database everything is stored in | All stored data: accounts, sessions, leads, calls, notes, emails, transcripts, summaries | [NEON DATABASE REGION] |
| Stripe | Subscription payments | Billing contact details and payment card details, entered by you directly on Stripe’s own page; plan and subscription status | United States and the European Economic Area |
| [TRANSACTIONAL EMAIL PROVIDER] | Sends system email — password resets and similar | The recipient’s email address and the contents of that message | [PROVIDER LOCATION] |
Only if the feature is switched on
These only receive data when the relevant feature is actually in use. If your workspace never turns call recording on, no audio ever leaves for transcription, and no transcript is ever summarised.
| Supplier | What it does for us | Personal data it can reach | Where |
|---|---|---|---|
| Twilio | Places calls where the workspace uses our platform calling, and stores the master recording | The number dialled, the rep’s number, call metadata, and the call audio | United States |
| Telnyx | Carries calls made through the in-app softphone | The number dialled, the rep’s number, call metadata, and the call audio | United States |
| Groq | Transcribes call recordings — our default transcription provider | Call audio, and therefore whatever was said on the call | United States |
| Deepgram | Transcribes call recordings where speaker labelling is needed; used only if Groq is not configured | Call audio, and therefore whatever was said on the call | United States |
| Anthropic | Turns a call transcript into a short summary and a suggested disposition | The call transcript, and a description of what your business sells if your admin has entered one | United States |
| Amazon Web Services (Simple Email Service) | Sends outbound email from a verified address without holding your mailbox password | Sender and recipient addresses, subject, message body, and delivery, bounce and complaint events | [AWS REGION] |
| Sentry | Error monitoring — reports a crash so we can fix it | Technical detail about the failure. Phone numbers, email addresses and free text are redacted before an error leaves our servers, and session recording is not enabled at all | [SENTRY REGION — EU OR US] |
Error monitoring is off unless a reporting endpoint is configured, and the redaction runs before anything is sent rather than after it arrives — a crash report is a copy of whatever was in memory when something broke, and in this product that memory holds leads’ names and mobile numbers.
Call audio is fetched by Dialspire using your carrier’s own credentials and forwarded to the transcription provider as bytes. We never hand a third party a carrier media URL, because in practice such a URL is a bearer credential that anyone holding it could replay.
On our public website
These three see data only from visitors to our public marketing website — never anything inside a workspace. They cannot reach a lead, a call, a note, an email or any other data held in the product. All three are inert unless we switch them on, and all three are also named on our cookies page.
| Supplier | What it does for us | Personal data it can reach | Where |
|---|---|---|---|
| Cloudflare | Bot protection on our public enquiry form (Turnstile). Inert unless we configure it. | The IP address and browser signals of a visitor who submits the enquiry form — nothing from any workspace | United States, edge delivery worldwide |
| Vercel (Web Analytics) | Visitor counts for the marketing site, loaded only after a visitor chooses “Accept all”. Never runs inside the signed-in app. | Page path (with any checkout, reset or invite key removed), referrer, country, browser and device type, and the IP and user agent from which Vercel derives a visitor hash it discards after 24 hours — no cookie, no cross-site identifier, and nothing from any workspace | United States |
| Plausible Analytics | Privacy-friendly analytics for the marketing site, loaded only after a visitor chooses “Accept all”. Inert unless we configure it. | Page path, referrer, and the IP and user agent from which Plausible derives a daily rotating visitor hash — no cookie, no cross-site identifier, and nothing from any workspace | Germany (EU) |
Suppliers you connect yourself
Some suppliers only ever enter the picture because you connected your own account with them. In those cases your contract is with that supplier directly, alongside ours.
Your own calling carrier
A workspace can route its calls through its own Vonage, Telnyx, Plivo, Bandwidth, SignalWire or Twilio account instead of ours. When it does, calls are placed on your account, under your carrier contract, and the recording is held by them.
Your own mailbox
Connecting Gmail, Outlook, Yahoo, iCloud, Zoho Mail, GMX, Fastmail or any other SMTP mailbox means email is sent through that provider on your credentials.
Your own calendar and booking page
A salesperson can connect their own Google or Outlook calendar, read-only, or give us a private iCal link, so that meetings leads book appear on their Dialspire calendar. We read their events to find meetings with your leads and store only those. The booking page they send leads to (Calendly, Zoom Scheduler, Cal.com or similar) is their own account: we redirect the lead there and may fill in the lead’s name and email on the form, but we send that service nothing ourselves.
Your own CRM
Connecting HubSpot, Salesforce, Pipedrive, Close or Zoho CRM sends lead and activity data out to your own CRM account, at your instruction. What happens to it there is governed by your agreement with that CRM.
- We store the credentials for these connections encrypted with AES-256-GCM, and we use them only to do the thing you connected them for.
- Disconnecting stops the flow going forward; it does not reach into the other service and delete what has already been sent there.
Transfers outside the UK
Several suppliers above process personal data in the United States, which the UK has not declared adequate. For each one we rely on the transfer mechanism recorded in that supplier’s data processing agreement: either the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the supplier holds a current certification under it.
[RECORD THE MECHANISM RELIED ON FOR EACH SUPPLIER] — and keep a transfer risk assessment alongside it, which the Addendum requires.
Ask us at [PRIVACY CONTACT EMAIL] for a copy of the safeguards in place for any supplier on this page.
How we tell you about changes
Before a new sub-processor starts handling your data we will update this page and email workspace admins at least 30 days beforehand, so there is time to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may end your subscription for the affected service without penalty — the same terms are set out in the DPA.
Replacing a supplier with one doing the same job is still a change, and gets the same notice.