Teamly
How it worksPricing
Log inGet Started
How it worksPricing
Log inGet Started

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use
  • Subprocessors
  • Licenses

Legal

Subprocessors

Last updated: 2026-05-19

Overview

The table below lists every third party (“subprocessor”) to which Teamly may disclose personal data in order to operate the Service. The list is published in addition to the categorical summary in § 5 of our Privacy Policy.

Each subprocessor processes personal data only on documented instructions from us and is bound by contractual confidentiality and data-protection obligations consistent with our Privacy Policy. We notify primary account contacts by email and bump the version stamp on this page when we add or remove a subprocessor. If you object to a new subprocessor your remedy is to terminate your subscription in line with our Terms of Service.

Categories that are not subprocessors but warrant disclosure for transparency: (i) external services you yourself connect via Integrations (Slack, Gmail, Stripe, etc., listed below in the Composio downstream toolkits section), where you remain the controller of the data shared with those services; and (ii) any “Bring Your Own Key” (BYOK) LLM provider for which you have supplied your own API credential, where Teamly acts only as a conduit.

LLM inference providers

SubprocessorJurisdictionPurposeData sharedTransfer basis
Anthropic, PBCUnited StatesPrimary large language model (Claude family) used for agent inference.Prompts, conversation context, file contents you reference, tool descriptions.SCCs (Module 2) + EU–US Data Privacy Framework certification.
OpenAI, OpC, LLCUnited StatesFallback / configurable large language model inference (GPT family).Prompts, conversation context, file contents you reference, tool descriptions.SCCs (Module 2) + EU–US Data Privacy Framework certification.
Google LLC (Generative AI)United StatesLarge language model inference (Gemini family).Prompts, conversation context, file contents you reference, tool descriptions.SCCs (Module 2) + EU–US Data Privacy Framework certification.
OpenRouter Inc.United StatesModel-routing layer that forwards inference requests to multiple model providers.Prompts, conversation context, model selection metadata.SCCs (Module 2 via OpenRouter); user retains downstream-provider relationship.
MiniMax (Hailuo)Singapore / ChinaRegional fallback large language model inference.Prompts, conversation context.Explicit consent at the point of model selection (GDPR Art. 49(1)(a)); use is opt-in.
Mimo / Xiaomi MiMoChinaOptional regional large language model inference (BYOK).Prompts, conversation context, only when the user selects the model.Explicit consent at the point of model selection (GDPR Art. 49(1)(a)); BYOK only.
Z.AI / Zhipu AIChinaOptional regional large language model inference (BYOK).Prompts, conversation context, only when the user selects the model.Explicit consent at the point of model selection (GDPR Art. 49(1)(a)); BYOK only.

Integration broker

SubprocessorJurisdictionPurposeData sharedTransfer basis
Composio Tech Inc.United StatesIntegration broker: stores encrypted OAuth tokens for the third-party services listed below, executes tool calls on the user's behalf.Encrypted OAuth tokens, integration-specific request and response payloads (e.g. email bodies you draft, Sheets rows you read or write, Slack messages you post).SCCs (Module 3).

Composio downstream toolkits

The following services may receive data from your Cell when you have connected the corresponding Integration and authorised an Agent to act on it. The relationship between you and each of these services is direct (under your own user / workspace account and subject to that service's own terms of service and privacy policy); Composio brokers the connection and Teamly orchestrates the calls but neither becomes a party to your relationship with the downstream service.

ToolkitJurisdictionPurposeData sharedTransfer basis
Google GmailUSEmail integration.Messages, drafts, recipients, attachments you send or read via the agent.Governed by Google Workspace DPA.
Google CalendarUSCalendar integration.Events, attendees, descriptions, availability.Governed by Google Workspace DPA.
Google DriveUSFile storage integration.File contents, file metadata, folder structure you operate on.Governed by Google Workspace DPA.
Google DocsUSDocument integration.Document contents, comments, metadata.Governed by Google Workspace DPA.
Google SheetsUSSpreadsheet integration.Cell values, formulas, sheet metadata, formatting.Governed by Google Workspace DPA.
Google SlidesUSPresentation integration.Slide contents, speaker notes, metadata.Governed by Google Workspace DPA.
Google TasksUSTask integration.Task titles, notes, due dates.Governed by Google Workspace DPA.
Google MapsUSMaps / Places lookups.Search queries, place IDs.Governed by Google Workspace DPA.
Google AnalyticsUSAnalytics property queries.Analytics property IDs, query parameters.Governed by Google Workspace DPA.
Google AdsUSAd account integration.Campaign data, ad copy you draft.Governed by Google Workspace DPA.
Google PhotosUSPhoto library integration.Image metadata, album structure (where invoked).Governed by Google Workspace DPA.
Google ClassroomUSEducation-platform integration.Course metadata, roster information (where invoked).Governed by Google Workspace DPA.
YouTubeUSVideo metadata integration.Video IDs, channel data, captions (where invoked).Governed by Google DPA.
Microsoft OutlookUSEmail integration.Messages, drafts, recipients, attachments.Microsoft DPA.
Microsoft TeamsUSChannel / chat integration.Messages, channels you post to.Microsoft DPA.
Microsoft ExcelUSSpreadsheet integration.Cell values, formulas.Microsoft DPA.
Microsoft OneDriveUSFile storage integration.File contents, file metadata.Microsoft DPA.
SlackUSWorkspace messaging integration.Channel names, message content, user mentions.Slack DPA.
DiscordUSServer messaging integration.Channel content, server metadata.Discord DPA.
Telegram (Bot API)United Arab Emirates (Telegram FZ-LLC, Dubai) / British Virgin Islands (Telegram Messenger Inc., infra)Bot messaging integration.Chat IDs, message content.Telegram TOS; SCCs not available — used only with explicit user consent.
WhatsApp BusinessMeta Platforms Ireland Ltd. (EU controller) / Meta Platforms Inc. (US infra)Messaging integration.Conversation content, recipient phone numbers.Meta DPA (WhatsApp). Note Meta's standing CJEU adequacy issues for EU-US transfers.
ZoomUSMeeting integration.Meeting metadata, attendees, recordings (where invoked).Zoom DPA.
SalesforceUSCRM integration.Account, contact, opportunity records.Salesforce DPA.
HubSpotUSCRM / marketing integration.Contact, company, deal records.HubSpot DPA.
IntercomUSCustomer messaging integration.Conversation content, contact metadata.Intercom DPA.
ZendeskUSSupport-ticket integration.Ticket content, requester metadata.Zendesk DPA.
LinearUSIssue tracker integration.Issue content, project metadata.Linear DPA.
JiraUS / AUIssue tracker integration.Issue content, project metadata.Atlassian DPA.
AsanaUSTask tracker integration.Task content, project metadata.Asana DPA.
ClickUpUSTask tracker integration.Task content, list metadata.ClickUp DPA.
Monday.comUSWork-OS integration.Board content, item metadata.Monday DPA.
TrelloUS / AUBoard integration.Card content, board metadata.Atlassian DPA.
NotionUSKnowledge-base integration.Page content, database properties.Notion DPA.
ConfluenceUS / AUKnowledge-base integration.Page content, space metadata.Atlassian DPA.
AirtableUSDatabase integration.Record content, base metadata.Airtable DPA.
CrowdinEstoniaLocalisation integration.String content, project metadata.Crowdin DPA.
GitHubUSSource-control integration.Repository content, issue / PR content, branch metadata.Microsoft DPA.
GitLabUSSource-control integration.Repository content, issue / MR content.GitLab DPA.
BitbucketUS / AUSource-control integration.Repository content, issue / PR content.Atlassian DPA.
FigmaUSDesign-file integration.File names, component metadata, comments.Figma DPA.
CanvaAUDesign integration.Design metadata, project content.Canva DPA.
StripeUSPayment / billing integration (read-only recommended).Customer records, transaction metadata, invoices (read-only where possible).Stripe DPA.
QuickBooksUSAccounting integration.Ledger entries, customer records, invoices.Intuit DPA.
MailchimpUSEmail-marketing integration.Audience contacts, campaign content.Mailchimp DPA.
GumroadUSCommerce integration.Product metadata, sales records.Gumroad DPA.
EventbriteUSEvent-management integration.Event metadata, attendee data.Eventbrite DPA.
DubUSLink-management integration.Link metadata, click statistics.Dub DPA.
CalendlyUSScheduling integration.Event types, invitee data, scheduled meetings.Calendly DPA.
Cal.comUS / EUScheduling integration.Event types, invitee data, scheduled meetings.Cal.com DPA.
BoxUSFile-storage integration.File contents, file metadata.Box DPA.
DropboxUSFile-storage integration.File contents, file metadata.Dropbox DPA.
SupabaseUS / EUDatabase integration.Database row content, schema metadata.Supabase DPA.
DigitalOceanUSCloud-infrastructure integration.Resource metadata, server logs.DigitalOcean DPA.
Hugging FaceUS / FRModel and dataset integration.Search queries, model identifiers.Hugging Face DPA.

The catalogue of integrations available through the Service evolves regularly. If a service you have connected does not appear in the table above, treat it as governed by the same general principle: you are the controller, the third party processes the data on your behalf, and the third party's own privacy policy applies.

Identity & authentication

SubprocessorJurisdictionPurposeData sharedTransfer basis
Clerk Inc.United StatesAuthentication, identity, and session management.Email address, name, OAuth identifiers, device-level session metadata, IP address, multi-factor secrets.SCCs (Module 2) + EU–US Data Privacy Framework certification.
Svix Inc.United StatesWebhook delivery and signature verification (used by Clerk for user-event webhooks).Webhook payloads originated by Clerk (user lifecycle events).SCCs (Module 3).

Payments

SubprocessorJurisdictionPurposeData sharedTransfer basis
Polar Software Inc. (Polar.sh)United States (Delaware-incorporated)Subscription billing, checkout, customer portal, invoicing, dunning.Email address, name, billing address, plan and purchase metadata, payment-method tokens (no full card numbers retained by Teamly).SCCs (Module 2); Polar.sh acts as merchant of record.
Stripe Payments Europe Ltd. (Polar.sh sub-processor)Ireland (EU)Card-network acquiring and payment-method processing for Polar.sh.Payment-method data (cards, bank), transaction metadata. Teamly does not access raw card data.SCCs where applicable; EU-resident processor.

Compute & hosting

SubprocessorJurisdictionPurposeData sharedTransfer basis
Fly.io (Hydrobyte Inc.)United States (primary region: sjc, San José, California)Hosting of the Teamly platform and of per-user Cells (isolated VMs with their own filesystem volumes).Cell volume contents (encrypted workspace state, installed skills, agent-execution scratch space), platform machine logs, network metadata.SCCs (Module 2 / Module 3 depending on data category) + EU–US Data Privacy Framework certification.

Storage

SubprocessorJurisdictionPurposeData sharedTransfer basis
AWS S3-compatible object storage (PSCloud, region configurable)Configurable (current production: Kazakhstan-based provider PSCloud)Backup and media-archive storage for Cell workspaces and uploaded files.Encrypted tar.gz workspace backups, user file uploads, generated media assets.Direct contractual confidentiality with the storage provider; data is encrypted at rest.

Database & real-time

SubprocessorJurisdictionPurposeData sharedTransfer basis
Convex Inc.United StatesReal-time application database (chat history, user profiles, sessions, billing records, audit logs).All user records and chat content as listed in the Privacy Policy §§ 3.1–3.9.SCCs (Module 2) + EU–US Data Privacy Framework certification.

Error monitoring

SubprocessorJurisdictionPurposeData sharedTransfer basis
Functional Software Inc. d/b/a SentryCalifornia, United States (Functional Software Inc.); data centre in Frankfurt, Germany (ingest.de.sentry.io)Error tracking, performance monitoring, session replay on errors.Error stack traces, sanitised request / response payloads, user context (Clerk user ID), release build identifiers. Sentry US personnel may have administrative access (support, billing, RBAC) under Sentry's sub-processor terms.Storage is within the EU. Administrative access from the US is covered by SCCs (Module 3) and Sentry's EU–US DPF certification.

Analytics

SubprocessorJurisdictionPurposeData sharedTransfer basis
Google Analytics 4 (GA4)United StatesSite-wide analytics: page views, user journey, conversion events.Page URLs, anonymised user ID, device data, GA client ID, purchase event metadata.SCCs + Google Consent Mode v2 (subject to your consent state).
Google Tag Manager (GTM)United StatesTag orchestration layer for analytics.Page metadata, custom event parameters.SCCs + Google Consent Mode v2.
GA Measurement Protocol (server-side)United StatesServer-side deduplication and validation of purchase events (called from the Polar.sh webhook).Transaction ID, monetary value, currency, plan, anonymised user ID.SCCs.

Transactional email

SubprocessorJurisdictionPurposeData sharedTransfer basis
Resend, Inc.United StatesTransactional email (waitlist, onboarding, account notifications).Recipient email address, recipient name, email subject and body.SCCs (Module 2).

DDoS protection & CDN

SubprocessorJurisdictionPurposeData sharedTransfer basis
Cloudflare, Inc.United States / global edgeDDoS mitigation, bot challenge, content delivery for static assets.Request IP address, request headers, challenge tokens.SCCs (Module 3) + EU–US Data Privacy Framework certification.

How we update this list

We bump the “Last updated” date at the top of this page whenever the list changes. For material additions (a new subprocessor that processes personal data of customer end-users), we will additionally notify the primary email address on the account at least 14 days before the change takes effect, except where a shorter notice period is required by law.

Earlier versions of this list are available on request from privacy@teamly.to.