Overview
Dilmach may engage subprocessors to process Customer Personal Data on Dilmach's behalf. Dilmach remains responsible for the processor obligations applicable to its relationship with the customer and will impose appropriate data protection obligations on subprocessors.
Subprocessor Architecture
These providers process data as necessary to deliver the corresponding part of the Services. They do not become controllers of Customer Content simply because they provide infrastructure or services to Dilmach. Stripe determines the purposes and means of certain processing under its own privacy framework for aspects of payment processing that fall outside Dilmach's instructions; see Current Subprocessors below for role-specific detail.
Current Subprocessors
This list reflects providers that our engineering team has confirmed are actually integrated into the production application, not merely available as an integration option. Integrations that exist in our infrastructure account but are not wired into any production feature (for example, unused AI or monitoring integrations) are not listed here.
| Provider | Purpose | Data categories | Role |
|---|---|---|---|
| Vercel | Application hosting, deployment infrastructure, and file storage (Vercel Blob) for uploaded files | All categories processed through the Services, including uploaded files | Processor / infrastructure provider |
| Neon | Primary database — stores account, CRM, billing-reference and application data | All categories processed through the Services | Processor / infrastructure provider |
| Stripe | Payment processing for Pro and Premium subscriptions | Billing contact details, subscription and transaction metadata. Full card data is handled by Stripe directly and not received by Dilmach. | Processor for billing data processed on Dilmach's instructions; independent controller for aspects of payment processing governed by Stripe's own privacy framework |
| Resend | Transactional email delivery (account verification, notifications) | Recipient email address, name where provided, email content | Processor |
| xAI | AI model provider for the in-app AI assistant and AI-generated video features | User prompts and relevant workspace context supplied to the assistant | Processor |
| OpenAI | AI model provider used to generate embeddings for knowledge-base search | Workspace content indexed for semantic search | Processor |
| Browserbase | Managed browser infrastructure for optional user-initiated web-fetch/crawl features | URLs and page content requested by the user; no CRM or account data is sent | Processor |
| Google (Google Analytics) | Website and product usage analytics | Visitor/usage data such as IP-derived location, device, browser and page interactions | Independent controller for its own analytics processing |
Exact processing regions and the specific international-transfer mechanism used for each provider are as described in that provider's own current security and privacy documentation, linked below.
Vercel
Application hosting, deployment infrastructure and file storage (Vercel Blob)
Provider-level assurance
Neon
Primary database infrastructure (all application and Customer Content data)
Provider-level assurance
Stripe
Payment processing for Pro and Premium subscriptions
Provider-level assurance
Resend
Transactional email delivery (account, verification and notification emails)
Provider-level assurance
xAI
AI model provider for the in-app AI assistant and AI-generated video features
Provider-level assurance
OpenAI
AI model provider used to generate embeddings for workspace knowledge-base search
Provider-level assurance
Browserbase
Managed browser infrastructure used by optional web-fetch/crawl features initiated by users
Provider-level assurance
Google (Google Analytics)
Website and product usage analytics
Provider-level assurance
Processing Location and Transfers
See our Privacy Policy for our general approach to international transfers.