Legal

Sub-processors

The complete list of suppliers that can reach personal data held in Dialspire, what each one does for us, and exactly what it sees.

Last updated 21 August 2026

Draft, pending professional review. This document describes how Dialspire actually works today, but it has not been reviewed by a solicitor and some details are still to be filled in. Please don’t rely on it as a final statement of our obligations.

What this page is

Article 28(2) of the UK GDPR says a processor may not bring in another processor without its customer’s authorisation. Our data processing agreement gives us general authorisation to use the suppliers on this page, and this page is where we keep that list honest and current.

Each of these suppliers is bound by a contract imposing the same data protection obligations we owe you, and we remain liable to you for what they do.

Where a supplier is listed as processing outside the UK, the location is as published by that supplier. Confirm it against their current data processing agreement before relying on this table for your own record of processing.

Always in use

These four are involved in running the service for every customer, all of the time.

Core sub-processors
SupplierWhat it does for usPersonal data it can reachWhere
VercelRuns and serves the applicationAll data in transit through the app; operational request logs including IP addressesUnited States, edge delivery worldwide ([VERCEL DEPLOYMENT REGION])
NeonManaged PostgreSQL — the database everything is stored inAll stored data: accounts, sessions, leads, calls, notes, emails, transcripts, summaries[NEON DATABASE REGION]
StripeSubscription paymentsBilling contact details and payment card details, entered by you directly on Stripe’s own page; plan and subscription statusUnited States and the European Economic Area
[TRANSACTIONAL EMAIL PROVIDER]Sends system email — password resets and similarThe recipient’s email address and the contents of that message[PROVIDER LOCATION]

Only if the feature is switched on

These only receive data when the relevant feature is actually in use. If your workspace never turns call recording on, no audio ever leaves for transcription, and no transcript is ever summarised.

Feature-dependent sub-processors
SupplierWhat it does for usPersonal data it can reachWhere
TwilioPlaces calls where the workspace uses our platform calling, and stores the master recordingThe number dialled, the rep’s number, call metadata, and the call audioUnited States
TelnyxCarries calls made through the in-app softphoneThe number dialled, the rep’s number, call metadata, and the call audioUnited States
GroqTranscribes call recordings — our default transcription providerCall audio, and therefore whatever was said on the callUnited States
DeepgramTranscribes call recordings where speaker labelling is needed; used only if Groq is not configuredCall audio, and therefore whatever was said on the callUnited States
AnthropicTurns a call transcript into a short summary and a suggested dispositionThe call transcript, and a description of what your business sells if your admin has entered oneUnited States
Amazon Web Services (Simple Email Service)Sends outbound email from a verified address without holding your mailbox passwordSender and recipient addresses, subject, message body, and delivery, bounce and complaint events[AWS REGION]
SentryError monitoring — reports a crash so we can fix itTechnical detail about the failure. Phone numbers, email addresses and free text are redacted before an error leaves our servers, and session recording is not enabled at all[SENTRY REGION — EU OR US]

Error monitoring is off unless a reporting endpoint is configured, and the redaction runs before anything is sent rather than after it arrives — a crash report is a copy of whatever was in memory when something broke, and in this product that memory holds leads’ names and mobile numbers.

Call audio is fetched by Dialspire using your carrier’s own credentials and forwarded to the transcription provider as bytes. We never hand a third party a carrier media URL, because in practice such a URL is a bearer credential that anyone holding it could replay.

On our public website

These three see data only from visitors to our public marketing website — never anything inside a workspace. They cannot reach a lead, a call, a note, an email or any other data held in the product. All three are inert unless we switch them on, and all three are also named on our cookies page.

Marketing-website sub-processors
SupplierWhat it does for usPersonal data it can reachWhere
CloudflareBot protection on our public enquiry form (Turnstile). Inert unless we configure it.The IP address and browser signals of a visitor who submits the enquiry form — nothing from any workspaceUnited States, edge delivery worldwide
Vercel (Web Analytics)Visitor counts for the marketing site, loaded only after a visitor chooses “Accept all”. Never runs inside the signed-in app.Page path (with any checkout, reset or invite key removed), referrer, country, browser and device type, and the IP and user agent from which Vercel derives a visitor hash it discards after 24 hours — no cookie, no cross-site identifier, and nothing from any workspaceUnited States
Plausible AnalyticsPrivacy-friendly analytics for the marketing site, loaded only after a visitor chooses “Accept all”. Inert unless we configure it.Page path, referrer, and the IP and user agent from which Plausible derives a daily rotating visitor hash — no cookie, no cross-site identifier, and nothing from any workspaceGermany (EU)

Suppliers you connect yourself

Some suppliers only ever enter the picture because you connected your own account with them. In those cases your contract is with that supplier directly, alongside ours.

Your own calling carrier

A workspace can route its calls through its own Vonage, Telnyx, Plivo, Bandwidth, SignalWire or Twilio account instead of ours. When it does, calls are placed on your account, under your carrier contract, and the recording is held by them.

Your own mailbox

Connecting Gmail, Outlook, Yahoo, iCloud, Zoho Mail, GMX, Fastmail or any other SMTP mailbox means email is sent through that provider on your credentials.

Your own calendar and booking page

A salesperson can connect their own Google or Outlook calendar, read-only, or give us a private iCal link, so that meetings leads book appear on their Dialspire calendar. We read their events to find meetings with your leads and store only those. The booking page they send leads to (Calendly, Zoom Scheduler, Cal.com or similar) is their own account: we redirect the lead there and may fill in the lead’s name and email on the form, but we send that service nothing ourselves.

Your own CRM

Connecting HubSpot, Salesforce, Pipedrive, Close or Zoho CRM sends lead and activity data out to your own CRM account, at your instruction. What happens to it there is governed by your agreement with that CRM.

  • We store the credentials for these connections encrypted with AES-256-GCM, and we use them only to do the thing you connected them for.
  • Disconnecting stops the flow going forward; it does not reach into the other service and delete what has already been sent there.

Transfers outside the UK

Several suppliers above process personal data in the United States, which the UK has not declared adequate. For each one we rely on the transfer mechanism recorded in that supplier’s data processing agreement: either the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the supplier holds a current certification under it.

[RECORD THE MECHANISM RELIED ON FOR EACH SUPPLIER] — and keep a transfer risk assessment alongside it, which the Addendum requires.

Ask us at [PRIVACY CONTACT EMAIL] for a copy of the safeguards in place for any supplier on this page.

How we tell you about changes

Before a new sub-processor starts handling your data we will update this page and email workspace admins at least 30 days beforehand, so there is time to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may end your subscription for the affected service without penalty — the same terms are set out in the DPA.

Replacing a supplier with one doing the same job is still a change, and gets the same notice.