Inflowence LogoInflowenceEvery call answered. Reviews on autopilot.Every call answered. Reviews on autopilot. Built for local businesses.
  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Acceptable Use
  • Messaging & SMS
  • SMS Terms
  • Voice & AI Disclosure
  • Data Processing
  • Subprocessors
  • Datenschutz
  • Impressum

Subprocessors List

Effective Date: June 2, 2026

This page lists all third-party subprocessors (service providers) that Inflowence uses to provide our services. We maintain this list for transparency and to comply with data protection obligations under CCPA and other applicable US privacy regulations.

Purpose of This List

As described in our Privacy Policy and Data Processing Addendum, Inflowence uses carefully selected third-party service providers to deliver our platform. These subprocessors may process customer data on our behalf.

Key Points:

  • All subprocessors are bound by contractual obligations to protect data
  • We conduct due diligence on security and privacy practices
  • Subprocessors are only granted access to data necessary for their services
  • We monitor subprocessor compliance with data protection requirements

Updates to This List

We may add, remove, or change subprocessors as we improve our services:

  • Material changes will be announced 30 days in advance
  • Non-material changes will be reflected here immediately
  • Subscribe for updates: Email subprocessor-updates@inflowence.ai with "Subscribe" in subject

Subprocessor List

The subprocessors below reflect the services Inflowence integrates directly. The "Data Location" column indicates where each provider primarily processes data.

Core Infrastructure

| Entity Name | Service Provided | Data Location | Purpose | |-------------|-----------------|---------------|---------| | Vercel Inc. | Application hosting, serverless functions, workflow runtime | USA / global edge | Hosts the web application and API/workflow endpoints; all request traffic transits Vercel | | Supabase Inc. | PostgreSQL database & file storage | USA | Stores application records (including demo/prospect data) and uploaded website screenshots | | Upstash Inc. | Serverless Redis + QStash message queue | USA / Global | Rate limiting and idempotency keys (Redis); durable job/queue delivery that may carry contact data (QStash) |

CRM & Communications

| Entity Name | Service Provided | Data Location | Purpose | |-------------|-----------------|---------------|---------| | HighLevel Inc. (GoHighLevel) | CRM, Voice AI, messaging relay | USA | Primary CRM: business/contact/opportunity records, AI voice agent + knowledge base, and SMS/email/social messaging | | Resend (Plus Five Five, Inc.) | Internal notification email | USA | Delivers internal operational/notification email to Inflowence's own team; notification content may include limited personal data (e.g., the email address tied to an account event). Not used for customer-facing or marketing email. | | AgentMail, Inc. | Programmatic email inboxes | USA | Provisions tenant-facing inbox addresses during account/trial setup |

AI & Data Enrichment

| Entity Name | Service Provided | Data Location | Purpose | |-------------|-----------------|---------------|---------| | OpenAI, L.L.C. | Embeddings & text generation | USA | Generates embeddings and drafts content from company knowledge-base material (retrieval-augmented generation) | | Firecrawl (SideGuide Technologies, Inc., f/k/a Mendable AI) | Website capture | USA | Captures a screenshot of a prospect's public website during demo creation | | Google LLC (Places API) | Business-listing lookup | USA / Global | Business search / autocomplete to identify a company's public listing details | | DataForSEO LLC | Google Business Profile data | USA | Retrieves public business-profile facts (name, phone, address, rating) for enrichment (admin/internal) |

Analytics (consent-gated)

| Entity Name | Service Provided | Data Location | Purpose | |-------------|-----------------|---------------|---------| | PostHog, Inc. | Product & web analytics | EU | Usage/event analytics, EU-hosted, loaded subject to consent | | Google LLC (Analytics / GA4) | Web analytics | USA / Global | Aggregate website-traffic analytics, loaded subject to consent | | Microsoft Corporation (Clarity) | Session-replay analytics | USA / Global | Heatmaps / session replay of site interactions, loaded subject to consent | | Meta Platforms, Inc. (Pixel) | Advertising / conversion pixel | USA / Global | Conversion measurement for advertising, loaded subject to consent |

Billing & Payments

| Entity Name | Service Provided | Data Location | Purpose | |-------------|-----------------|---------------|---------| | Stripe, Inc. | Payment processing & billing | USA / Global | Processes subscription payments, card details, and invoicing for paid plans |

Sub-subprocessors engaged through GoHighLevel

The following are engaged by GoHighLevel (not directly by Inflowence) to deliver messaging on its platform: Twilio Inc. (SMS and voice delivery, phone-number provisioning), Mailgun (Sinch) (email delivery), and the AI-model providers GoHighLevel engages for its Voice AI features (voice transcription and conversation intelligence). Their processing is governed by GoHighLevel's own subprocessor terms.

Data Processing Details

What Data is Shared

Subprocessors may process the following types of data depending on their role:

Customer Account Data:

  • Business name and contact information
  • User account credentials (hashed/encrypted)
  • Billing and payment information (Stripe only)
  • Usage and activity logs

End-User Data (Your Customers):

  • Contact information (names, emails, phone numbers)
  • Communication content (messages, emails, call recordings)
  • Social media profiles and interactions
  • Engagement and behavioral data

Technical Data:

  • IP addresses and device information
  • Browser and operating system data
  • Session information and cookies
  • Performance and error logs

Security Measures

All subprocessors are required to:

  • Implement appropriate technical and organizational security measures
  • Encrypt data in transit and at rest
  • Maintain industry-standard access controls
  • Conduct regular security audits and assessments
  • Notify us of any security incidents promptly
  • Comply with applicable data protection laws

Geographic Considerations

Primary Data Storage

Customer data is primarily stored in:

  • European Union (Supabase, EU region — Ireland) for the application database and uploaded files
  • United States for CRM, telephony, and messaging data (GoHighLevel and its carriers)
  • European Union for product analytics (PostHog, EU region)
  • Content may be served globally through Vercel's edge network

International Transfers

Data may be transferred internationally:

  • Standard Contractual Clauses (SCCs) are in place where required
  • Adequacy decisions are followed where applicable
  • Additional safeguards are implemented for sensitive transfers

Data Residency Options

For customers with specific data residency requirements:

  • Contact sales@inflowence.ai for custom arrangements
  • Enterprise plans may offer regional data storage options
  • Additional fees may apply for dedicated regional hosting

Subprocessor Obligations

Each subprocessor is contractually obligated to:

  1. Process data only as instructed by Inflowence
  2. Maintain confidentiality of all customer data
  3. Implement security measures commensurate with data sensitivity
  4. Assist with data subject requests (access, deletion, etc.)
  5. Notify us of any data breaches or security incidents
  6. Delete or return data upon termination of services
  7. Comply with data protection laws including applicable US state laws (CCPA, CPRA, VCDPA, etc.)
  8. Undergo audits and provide compliance documentation

Your Rights

As a Inflowence customer, you have the right to:

Object to Subprocessors

If you object to our use of a specific subprocessor:

  • Notify us in writing within 30 days of receiving notice of a new subprocessor
  • We will work with you to find an alternative solution
  • If no alternative is feasible, you may terminate your agreement without penalty

Request Information

You may request:

  • Additional information about subprocessor security practices
  • Copies of relevant data processing agreements
  • Evidence of subprocessor compliance certifications
  • Details about data flows and processing activities

Contact: legal@inflowence.ai

Audit Rights

Enterprise customers may have audit rights:

  • Review subprocessor compliance documentation
  • Request third-party audit reports (SOC 2, ISO 27001, etc.)
  • Conduct audits subject to mutual agreement

Changes and Notifications

New Subprocessors

When adding a new subprocessor:

  • 30 days advance notice for material changes
  • Notice via email to your account email address
  • Notice posted on this page
  • Opportunity to object per your contract terms

Material vs. Non-Material Changes

Material Changes (30-day notice):

  • Adding a new category of subprocessor
  • Changing primary hosting or database providers
  • Subprocessors processing sensitive personal data

Non-Material Changes (immediate update):

  • Updating existing subprocessor details
  • Removing a subprocessor
  • Changes in data location within the same region

Subscribe to Updates

Stay informed about subprocessor changes:

  • Email: subprocessor-updates@inflowence.ai
  • Subject line: "Subscribe to Subprocessor Updates"
  • Include your account email address

Compliance Certifications

Many of our subprocessors maintain industry-standard certifications:

Common Certifications:

  • SOC 2 Type II: Security, availability, processing integrity, confidentiality, privacy
  • ISO 27001: Information security management
  • PCI DSS: Payment card industry data security (Stripe)
  • CCPA Compliance: California consumer privacy act

Healthcare (HIPAA). Inflowence does not directly process Protected Health Information ("PHI") and does not sign Business Associate Agreements. HIPAA-regulated Customers may elect the GoHighLevel HIPAA add-on, which establishes a direct Business Associate relationship between the Customer and GoHighLevel. When the HIPAA add-on is active, the Customer must confine all PHI to GoHighLevel and must not use Inflowence features that route data outside GoHighLevel (including the public demo-creation flow, Supabase-backed storage, or any Inflowence subprocessor other than GoHighLevel and its own subprocessors).

Verification: Contact compliance@inflowence.ai to request copies of certifications.

Data Processing Addendum

This Subprocessors List is part of our Data Processing Addendum, which governs data processing relationships for business customers.

Key DPA Sections:

  • Roles and responsibilities (Controller vs. Processor)
  • Data processing scope and limitations
  • Security requirements and incident response
  • Data subject rights and assistance
  • International transfer mechanisms
  • Subprocessor management (this list)

Contact Information

Questions About Subprocessors

  • General Inquiries: privacy@inflowence.ai
  • Legal/DPA Questions: legal@inflowence.ai
  • Security Questions: security@inflowence.ai
  • Compliance Questions: compliance@inflowence.ai

Objecting to a Subprocessor

To object to a subprocessor:

  1. Email legal@inflowence.ai
  2. Include "Subprocessor Objection" in subject line
  3. Specify which subprocessor and reason for objection
  4. Allow 10 business days for response

Requesting Subprocessor Information

To request additional information:

  • Email with specific questions or requirements
  • Indicate if request relates to an audit or compliance requirement
  • Response time: 10-15 business days for detailed requests

Related Documents

  • Privacy Policy
  • Data Processing Addendum
  • Terms of Service
  • Security Overview

Changelog

July 4, 2026

  • Reconciled the list to the services actually integrated: added Resend, PostHog (EU), Firecrawl, Google (Places/Analytics), Microsoft Clarity, AgentMail, and DataForSEO; removed AWS, Sentry, and Cloudflare; reframed Twilio and Mailgun as sub-subprocessors engaged through GoHighLevel; added Stripe (billing).

December 19, 2025

  • Initial publication of Subprocessors List
  • All current subprocessors documented
  • Notification process established

Commitment to Transparency: Inflowence is committed to transparency in our data processing practices. We carefully vet all subprocessors and require them to meet our high standards for security and privacy.

If you have questions or concerns about any subprocessor, please don't hesitate to contact us.

Inflowence LogoInflowence

Every call answered. Reviews on autopilot. Built for local businesses.

Done-for-you Google reviews for Houston HVAC, plumbing, & home inspectors.

Services

  • All services
  • Google review automation
  • Missed call text back
  • AI answering service
  • For home inspectors
  • Pricing
  • Best review software for HVAC
  • Review automation in Houston

Resources

  • Missed call calculator
  • Blog
  • Contact
  • Sitemap

Legal

  • Terms of Service
  • Privacy Policy
  • Messaging & SMS Terms
  • Datenschutz
  • Impressum

© 2026 Inflowence LLC. All rights reserved.

525 Randall Ave Ste 100 PMB 1133, Cheyenne, WY 82001, USA

Your phone is ringing
Get Started