Sub-processors

Third-party providers Send4.ai uses to deliver the service.

Last updated: 13 July 2026 · Version 2026-07-13

What this list is

Send4 uses the following sub-processors to provide the platform. Each processes personal data only for the purpose listed, under a data processing agreement with us. Where a provider processes data outside the European Economic Area, transfers are protected by the safeguards shown — see our Privacy Policy for how international transfers work.

Current sub-processors

Provider Purpose Personal data Location Transfer safeguard
OpenAI Ireland Ltd. (OpenAI OpCo, LLC) AI reply generation Message content and conversation context sent to generate replies United States (EU data residency available; not currently enabled) DPA with SCCs. OpenAI is not certified under the Data Privacy Framework, so SCCs are the sole safeguard. API data is not used to train OpenAI models; abuse-monitoring logs are retained for up to 30 days.
Twilio Ireland Limited (Twilio Inc.) SMS delivery Lead phone numbers, message bodies, delivery metadata United States DPA with EU-U.S. Data Privacy Framework (Twilio Inc., active), Binding Corporate Rules approved by EU authorities, and SCCs as fallback.
Vonage B.V. (Vonage Holdings Corp.) SMS delivery Lead phone numbers, message bodies, delivery metadata Netherlands / United States DPA with EU-U.S. Data Privacy Framework (Vonage Holdings Corp., active) and SCCs as fallback.
Resend (Plus Five Five, Inc.) Transactional email User names and email addresses, email content United States (account data, logs and metadata are stored in the US even when an EU sending region is used) DPA with SCCs. Resend also holds an EU-U.S. Data Privacy Framework listing, but we rely on the SCCs in its DPA as the primary safeguard.
Cloudflare, Inc. Bot protection (Turnstile), CDN and edge security IP addresses, request metadata Global edge network DPA with EU-U.S. Data Privacy Framework (Cloudflare, Inc., active), with SCCs as fallback.
Google Ireland Limited (Google LLC) “Continue with Google” sign-in Google profile name, email address, account identifier EU / United States Not a sub-processor: for Google sign-in, Google acts as an independent controller under its own privacy policy. Transfers to Google LLC (US) are covered by the EU-U.S. Data Privacy Framework (active).
DigitalOcean, LLC Application hosting and managed database All platform data (encrypted at rest) European Union — Frankfurt, Germany (fra1) DPA with EU-U.S. Data Privacy Framework (DigitalOcean, active), with SCCs and the UK Addendum as fallback. Data is hosted in the EU; DigitalOcean is a US company and its support staff may access it, which is what the DPF and SCCs cover.
Plausible Insights OÜ Privacy-friendly, cookie-less web analytics Aggregated page-view statistics; no persistent identifiers European Union (Estonia / EU hosting) EU-based processing — no third-country transfer.

Changes to this list

We will update this page before engaging a new sub-processor that handles customer personal data, and customers with a data processing agreement will be notified with 30 days to object as set out in that agreement. Questions: [email protected].