legal

Subprocessors.

version 1.3 · effective september 7, 2026

We use a small set of third-party services to operate the Zentrr platform. The list below is the current set. We will provide at least thirty (30) days' notice before adding or replacing a sub-processor that handles Customer Content materially, via email to account admins or via in-product notification, so that Customer can raise reasonable objections.

Amazon Web Services, Inc.

infrastructure

Cloud infrastructure: AI inference (Bedrock), identity (Cognito), database (Aurora), storage (S3), email (SES), CDN (CloudFront), compute (ECS / Lambda), workflow orchestration (Step Functions), encryption (KMS), audit logging (CloudTrail).

location
United States (us-east-1)
notes
HIPAA-eligible under the AWS Business Associate Addendum.

Stripe, Inc.

billing

Subscription billing, Checkout, and Customer Portal. Payment card data flows directly to Stripe; Zentrr does not store full card numbers.

location
United States

Google LLC (Google Analytics + Google Ads + Google Tag Manager)

analytics

Marketing-site analytics and ad-conversion measurement.

location
United States / European Union
notes
Loaded only on the marketing site, and only when consent is granted via the cookie banner. Disabled in the authenticated application.

Anthropic, PBC

model provider

Foundation model provider (Claude models). Listed for transparency. For the default model lineup, not a direct Zentrr sub-processor — those Claude models run entirely inside AWS Bedrock and Anthropic does not have access to customer prompts, completions, or logs.

location
United States (only for opted-in provider-data-share models; otherwise n/a)
notes
Anthropic's Usage Policy and commercial terms are flowed down through our Acceptable Use Policy. Exception — provider-data-share models: a small set of Anthropic models served via AWS Bedrock are offered only under data_retention_mode=provider_data_share. These are OFF by default. If an org admin explicitly opts a specific agent into one, that agent's prompts and completions are shared with Anthropic and retained up to 30 days for trust & safety and abuse detection — never for model training. The opt-in is per agent and recorded in the org's audit log; all other agents and models keep the no-provider-access default.

Functional Software, Inc. (Sentry)

analytics

Application error monitoring and performance tracing for the Zentrr web application AND the Zentrr mobile app, which report to the same Sentry project. Captures stack traces, request metadata, and diagnostic breadcrumbs.

location
United States
notes
What is removed before transmission, stated precisely rather than as "PII is scrubbed". Both platforms strip authorization and cookie headers, the request body, and the user email and IP address — a crash is correlated by an opaque user id only. The mobile app additionally strips URL query strings and reduces breadcrumb data to a scrubbed URL and status code. On web, exception messages, breadcrumbs and custom context are NOT scrubbed, so a developer-authored error string could carry customer data; we treat that as a code-review obligation rather than claiming a filter that does not exist.

Twilio Inc.

communications

Telephony for the voice channel: inbound and outbound call audio, caller and recipient phone numbers, and call metadata (duration, direction, disposition).

location
United States
notes
Applies only to organizations that enable the phone channel. Call audio is streamed in both directions in real time so a Specialist can answer the call; Zentrr stores call metadata and, where the organization enables it, the transcript. Numbers are provisioned under per-organization subaccounts of a Zentrr-held master account.

Exponent, Inc. (Expo) — with Google LLC (FCM) and Apple Inc. (APNs)

communications

Mobile push notification delivery. Expo relays a notification to Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS) for delivery to the device.

location
United States
notes
Applies only to users of the Zentrr mobile app who enable notifications. Unlike Web Push, an Expo payload is not end-to-end encrypted, so a notification title and body — which may name a message or a task — are readable in transit by Expo and by the platform relay. Turn notifications off in the mobile app if that is not acceptable for your content. This is separate from the Google entry above, which covers marketing-site analytics only.

Channel and connector sub-processors

When you connect a channel (Slack, Microsoft Teams, WhatsApp, Outlook, Gmail, etc.) or a knowledge connector (Epic on FHIR, QuickBooks, Salesforce, Confluence, SharePoint, Google Drive, Notion, etc.) to your Zentrr workspace, that third party becomes a sub-processor for the data you send through the integration. Each integration is opt-in by your admin; the active list for your workspace is visible at /connections inside the product. Documents you upload as exports (for example AMS or GL exports) do not create a sub-processor relationship — they are files processed inside Zentrr.

Questions

Contact privacy@zentrr.com for sub-processor questions or to subscribe to change notifications.