Last Updated: 2026-09-19
GDPR Compliance: This page lists all third-party subprocessors (service providers) that process personal data on behalf of OmniOps. We maintain Data Processing Agreements (DPAs) with all subprocessors and ensure they comply with GDPR Article 28 requirements.
As a data controller, OmniOps uses various third-party service providers (subprocessors) to deliver our services. This list is maintained in compliance with:
We will notify customers at least 30 days before adding new subprocessors or making changes to existing ones.
To receive notifications about subprocessor changes:
Enterprise customers can object to new subprocessors within the notification period.
AI features are not anonymized. When you use the AI assistant, the AI receptionist, or voice input, the customer records the assistant looks up are sent to the AI provider as they are stored — including names, phone numbers, email addresses, service addresses and free-text notes — and voice input is sent as recorded audio for transcription. We do not de-identify or tokenize this data before transmission. If your organization needs AI features disabled, contact us.
| Subprocessor | Purpose | Data Processed | Location | Compliance |
|---|---|---|---|---|
Vercel Inc. | Application hosting and CDN | Application data, Usage logs | United States | SOC 2 Type IIEU-U.S. Data Privacy Framework |
Supabase Inc. | Database hosting and authentication | Customer data, User credentials, Business data | United States | SOC 2 Type II |
Stripe, Inc. | Payment processing | Payment information, Billing details | United States | PCI DSS Level 1SOC 2 Type II |
Twilio Inc. | SMS messaging | Phone numbers, Message content | United States | SOC 2 Type IIISO 27001 |
Resend | Transactional email delivery | Email addresses, Email content | United States | SOC 2 Type II |
OpenAI, L.L.C. | AI assistant, AI-powered features, and voice transcription | Customer names, phone numbers, email addresses and service addresses, Job, quote, invoice and message content, Recorded voice input (audio) for transcription | United States | SOC 2 Type II |
Anthropic PBC | AI assistant and AI-powered features | Customer names, phone numbers, email addresses and service addresses, Job, quote, invoice and message content | United States | SOC 2 Type II |
TypeSafe AI, Inc. | Optional Jev tool-routing pilot, with separate user permission | Current questions and earlier user requests needed for follow-ups, Names and other details included in those requests; no tool results, photos or audio | United States | Data Processing Addendum |
Google LLC | Maps, geocoding, address autocomplete (Places), and Google Sign-In | Location data, Address search text, Sign-in identity tokens (email, name) | United States / Global | ISO 27001SOC 2/3 |
Apple Inc. | App Store subscriptions (in-app purchase) and Sign in with Apple | Purchase and subscription records, Sign-in identity tokens (email or relay address, name) | United States / Global | ISO 27001SOC 2 |
RevenueCat, Inc. | In-app subscription management and receipt validation for the iOS app | Workspace (organization) identifier used as the subscriber id, App Store purchase and subscription records | United States | SOC 2 Type II |
Expo (650 Industries, Inc.) | Mobile push notification delivery, app builds and over-the-air updates | Device push tokens, Notification titles and bodies | United States | SOC 2 Type II |
Open-Meteo | Weather shown on the mobile Today screen | Device coordinates at the time of the request (no account or identifier) | Germany / Global | Open data service — no personal account |
Mapbox, Inc. | Address search and geocoding | Address search text | United States | SOC 2 Type IIISO 27001 |
Sentry | Error monitoring and performance tracking | Error logs, Performance metrics, OmniOps account ID, Device and installation identifiers | United States | SOC 2 Type IIEU-U.S. Data Privacy Framework |
Upstash | Rate limiting and caching | Request metadata, Cache data | United States | SOC 2 Type II |
For subprocessors located outside the European Economic Area (EEA), we use the following safeguards:
Before engaging any subprocessor, we:
As an OmniOps customer, you have the right to:
For questions about our subprocessors or to exercise your rights:
Email: hello@getomniops.com