Sub-processors
Third-party providers Send4.ai uses to deliver the service.
Last updated: 13 July 2026 · Version 2026-07-13
What this list is
Send4 uses the following sub-processors to provide the platform. Each processes personal data only for the purpose listed, under a data processing agreement with us. Where a provider processes data outside the European Economic Area, transfers are protected by the safeguards shown — see our Privacy Policy for how international transfers work.
Current sub-processors
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| OpenAI Ireland Ltd. (OpenAI OpCo, LLC) | AI reply generation | Message content and conversation context sent to generate replies | United States (EU data residency available; not currently enabled) | DPA with SCCs. OpenAI is not certified under the Data Privacy Framework, so SCCs are the sole safeguard. API data is not used to train OpenAI models; abuse-monitoring logs are retained for up to 30 days. |
| Twilio Ireland Limited (Twilio Inc.) | SMS delivery | Lead phone numbers, message bodies, delivery metadata | United States | DPA with EU-U.S. Data Privacy Framework (Twilio Inc., active), Binding Corporate Rules approved by EU authorities, and SCCs as fallback. |
| Vonage B.V. (Vonage Holdings Corp.) | SMS delivery | Lead phone numbers, message bodies, delivery metadata | Netherlands / United States | DPA with EU-U.S. Data Privacy Framework (Vonage Holdings Corp., active) and SCCs as fallback. |
| Resend (Plus Five Five, Inc.) | Transactional email | User names and email addresses, email content | United States (account data, logs and metadata are stored in the US even when an EU sending region is used) | DPA with SCCs. Resend also holds an EU-U.S. Data Privacy Framework listing, but we rely on the SCCs in its DPA as the primary safeguard. |
| Cloudflare, Inc. | Bot protection (Turnstile), CDN and edge security | IP addresses, request metadata | Global edge network | DPA with EU-U.S. Data Privacy Framework (Cloudflare, Inc., active), with SCCs as fallback. |
| Google Ireland Limited (Google LLC) | “Continue with Google” sign-in | Google profile name, email address, account identifier | EU / United States | Not a sub-processor: for Google sign-in, Google acts as an independent controller under its own privacy policy. Transfers to Google LLC (US) are covered by the EU-U.S. Data Privacy Framework (active). |
| DigitalOcean, LLC | Application hosting and managed database | All platform data (encrypted at rest) | European Union — Frankfurt, Germany (fra1) | DPA with EU-U.S. Data Privacy Framework (DigitalOcean, active), with SCCs and the UK Addendum as fallback. Data is hosted in the EU; DigitalOcean is a US company and its support staff may access it, which is what the DPF and SCCs cover. |
| Plausible Insights OÜ | Privacy-friendly, cookie-less web analytics | Aggregated page-view statistics; no persistent identifiers | European Union (Estonia / EU hosting) | EU-based processing — no third-country transfer. |
Changes to this list
We will update this page before engaging a new sub-processor that handles customer personal data, and customers with a data processing agreement will be notified with 30 days to object as set out in that agreement. Questions: [email protected].