Sub-Processors

Last updated: August 28, 2026

Soofte, Inc. (d/b/a “Humalike AI”) acts as a processor (or sub-processor) of customer data. Under GDPR Article 28(2) and our Data Processing Agreements, we maintain a current list of the sub-processors we use to deliver our services and notify customers before changes. This page is that list.

Sub-processor list

The following vendors are sub-processors because they process customer data (API request/response content, account data, usage data, or billing data). Other vendors in our stack do not process customer data and are managed as ordinary suppliers.

Sub-processorPurposeCustomer data processedLocation / transfer mechanism
Amazon Web Services (AWS)Cloud hosting (compute, RDS, S3, SQS, CloudWatch, networking)All customer data stored or processed by the platformEU/US; SCCs / EU–US DPF per AWS DPA
GoogleAI model inference (Gemini) and business email (Google Workspace)Conversation and prompt content sent to Gemini models; customer contact and support communication dataEU/US; SCCs / EU–US DPF per Google DPA
AnthropicAI model inferenceConversation and prompt content sent to modelsUS; SCCs / EU–US DPF per vendor DPA
DeepgramSpeech-to-text transcriptionEnd-user voice audio and resulting transcriptsUS; SCCs per vendor DPA
ElevenLabsText-to-speech synthesisNPC reply text sent for audio generationUS; SCCs per vendor DPA
Parallel.aiPersona grounding briefsPersona content submitted for research groundingUS; SCCs per vendor DPA
ClerkAuthentication and identity for the customer consoleCustomer account and session dataUS; SCCs / EU–US DPF per Clerk DPA
StripePayment processingCustomer billing and payment dataUS; SCCs / EU–US DPF per Stripe DPA
ResendTransactional email deliveryCustomer contact details and email contentUS; SCCs per vendor DPA
PostHogProduct analyticsCustomer account and product usage dataUS; SCCs per vendor DPA
VercelWeb and console hostingFrontend traffic and API route request dataUS; SCCs per vendor DPA
Better StackMonitoring, logging, status pageService logs that may contain customer request metadataUS (telemetry region); SCCs per vendor DPA
DiscordCustomer support conversationsCustomer contact details and support message contentUS; SCCs per vendor DPA

Processing locations and transfer mechanisms above reflect each vendor’s standard Data Processing Agreement terms and are verified when this list is reviewed — at least annually and on every change. This list is referenced from our Data Processing Agreement.

Adding or replacing a sub-processor

  1. We assess a new vendor before engagement: what customer data it will process and its security posture (certifications, data processing terms, transfer mechanism).
  2. A Data Processing Agreement (or equivalent data processing terms) with the vendor must be in place before any customer data is processed.
  3. We update this public list at least 10 days before the new sub-processor begins processing customer data. Customers who have subscribed to updates are notified; this notice period is the customer’s opportunity to object under our Data Processing Agreement.
  4. The notice states the sub-processor’s name, purpose, data processed, and location, and reminds customers of their right under our Data Processing Agreement to object within the notice period by replying to the notice or emailing us.
  5. Removals and non-material changes (e.g. a vendor rename) are reflected on this list without advance notice.

Changelog

  • 2026-08-28 — List reconciled against the deployed codebase. Added Deepgram, ElevenLabs, Parallel.ai, and Vercel; expanded the Google entry to cover Gemini model inference alongside Google Workspace. Removed OpenAI, OpenRouter, and Slack, which are not in use.
  • 2026-08-27 — Initial list published.

Subscribe to updates

To be notified before a new sub-processor begins processing customer data, subscribe to sub-processor updates.