What this list is
A sub-processor is a company Wilph uses to run the service, and which therefore handles some of the data you put into it. Article 28 of the GDPR requires us to name them, and your Data Processing Agreement is your authorisation for us to use them.
Current sub-processors
| Vendor | What it does | What it processes | Where |
|---|---|---|---|
| Vercel | Application hosting and serverless compute | Everything the application handles, in transit and in memory while a request is served | United States |
| Neon | Managed PostgreSQL database | All stored service data: accounts, tickets, messages, contacts, encrypted integration credentials | United States (AWS us-east-1) |
| Resend | Receiving and sending email | Support email content, sender and recipient addresses, message headers | United States |
| AI text generation (Gemini) for drafts and answersA deployment configured to use the Vercel AI Gateway instead routes the same content to that gateway and the model provider behind it. | The question being answered, the relevant passages from your own website, your enabled skills, and recent conversation turns | United States | |
| Stripe | Subscription billing | Billing contact details and subscription state. Card details are entered on Stripe's own pages and never reach Wilph. | United States and Ireland |
| Google Analytics | Optional website analytics on wilph.comLoads only after a visitor accepts analytics cookies, and never inside the signed-in dashboard. | Page views and approximate location for visitors to the public website only. No account or support data. | United States |
Where the data actually sits
Worth saying plainly rather than leaving to be inferred from the table: Wilph’s database is hosted in the United States (AWS us-east-1). Tickets, messages, contacts and crawled pages are stored there, not in the EU.
For a European customer that is an international transfer under Chapter V of the GDPR, and it relies on the European Commission’s standard contractual clauses in our agreements with those vendors. If EU-only data residency is a requirement for you, tell us before you sign — it is a real constraint today, not a setting we can flip.
Systems you connect, which are not sub-processors
These are your own accounts on your own systems. Wilph reads from them, or delivers your reply through them, because you connected them and told it to. The data was already yours and already there, so calling them sub-processors would misdescribe who decided what — but you should still know exactly which ones the product talks to.
| System | What Wilph does with it |
|---|---|
| Shopify | Reads order, fulfillment, tracking and refund details for a customer's order. Nothing is stored. |
| Meta (Instagram and Facebook Messenger) | Receives direct messages from your Page and delivers your replies to them. |
| Freshdesk, Dixa | Reads a bounded sample of your past conversations for the Replay lab, when you connect them. |
| Gmail, Google Workspace, Microsoft 365 | Read-only access to a mailbox you nominate, for the Replay lab only. Wilph never sends from it. |
Disconnecting one on the Integrations or Channels page stops Wilph reaching it.
Being told about changes
Before we add a sub-processor or replace one, we will email the workspace owner at least 30 days in advance and update this page. If you reasonably object to a new sub-processor on data-protection grounds, tell us at info@wilph.com within that notice period; if we cannot resolve it, you may cancel your subscription without penalty for the remainder of the term.
How to reach us
Questions about this document, or any request about your data, go to info@wilph.com. We answer in English or Danish.