LEGAL

Sub-processors.

Last updated: 9 August 2026. The third parties that may process personal data on our behalf when we act as processor for a customer.

Controller TMMA SRLS
Applies to Processor activities
Last updated 9 August 2026

1. How to read this list

When MessageMind processes personal data on a customer's behalf we act as processor under Article 28 GDPR. The companies below are our sub-processors: they may process that data to deliver part of the service.

Not every sub-processor applies to every customer. A vendor is only engaged where the customer enables the corresponding channel, integration or feature. Systems the customer connects themselves — their own CRM, shop, PMS or booking platform — are the customer's own controllers or processors, not ours.

2. Current sub-processors

Sub-processorPurposeData categoriesProcessing location
Meta Platforms Ireland LtdWhatsApp Business and Instagram messaging channelsMessage content, profile identifiers, phone numbersEU / US
OpenAI, L.L.C.Text generation for AI agent repliesConversation content submitted for generationUS
ElevenLabs Inc.Speech synthesis and voice agent audioText prompts and generated or supplied audioUS / EU
Twilio Inc.SMS and voice telephonyPhone numbers, message content, call metadataUS / EU
Telnyx LLCTelephony and messaging (alternative carrier)Phone numbers, message content, call metadataUS / EU
Stripe Payments Europe LtdSubscription billing and customer depositsBilling contact, payment metadata (no full card data)EU / US
Google Ireland LtdCalendar, mailbox, Business Profile and website analyticsCalendar events, mailbox content where connected, usage eventsEU / US
Microsoft Ireland Operations LtdOutlook / Microsoft 365 mailbox and calendar integrationMailbox and calendar content where connectedEU / US
Amazon Web Services EMEA SARLObject storage for media, attachments and exportsFiles, images, recordings and generated exportsEU
MongoDB LtdPrimary application databaseAll platform records, including conversation contentEU
Pinecone Systems Inc.Vector index for knowledge retrievalEmbeddings derived from customer knowledge contentUS / EU
Cloudinary LtdImage and media transformation and deliveryImages and media supplied by the customerEU / US
Cloudflare Inc.CDN, DNS and DDoS protection for the websiteIP address, request metadataGlobal edge

Hosting and infrastructure providers used to run the platform are held in the EU. The complete current list, including infrastructure providers and their regions, is available for vendor security reviews on request at [email protected].

3. Contractual safeguards and transfers

Each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than those in our own DPA, including confidentiality, security measures and assistance duties.

Where a sub-processor processes data outside the EU/EEA we rely on an adequacy decision or on Standard Contractual Clauses with supplementary measures where required. Details are available on request.

4. Changes and right to object

We keep this page current. Customers who have asked to be notified receive at least 30 days' notice before a new sub-processor starts processing their data, or as soon as practicable where a change is urgent for security or continuity.

A customer may object to a new sub-processor on reasonable data-protection grounds within that notice period. If we cannot offer a workable alternative, the customer may terminate the affected part of the service. To subscribe to notifications, write to [email protected].