Legal document

Sub-processor List

The third parties Desklly uses to deliver the Service. All sub-processors are contractually bound to protect personal data to at least the standard required by UK GDPR.

Version 1.0Last updated 7 July 2026Governing law England & Wales

How we manage sub-processors

Each sub-processor is risk-assessed before engagement and reviewed annually. Contracts include GDPR Article 28 terms, appropriate international transfer safeguards, and confidentiality obligations. Customers can subscribe to sub-processor change notifications at info@desklly.ai and will receive at least 30 days' notice of any addition or replacement.

Cloud infrastructure — Amazon Web Services (AWS)

Purpose: compute, storage, and database hosting. Location: London (eu-west-2). Data: all customer data at rest and in transit within the platform.

Edge and CDN — Cloudflare

Purpose: DNS, DDoS protection, TLS termination, static asset delivery. Location: UK/EEA edge nodes. Data: request metadata, IP addresses.

Telephony — Twilio Ireland Limited

Purpose: inbound and outbound voice and SMS. Location: EU (Ireland). Data: caller/recipient phone numbers, call metadata, SMS content, transient audio.

Speech-to-text and text-to-speech

Purpose: real-time transcription and voice synthesis for the AI receptionist. Location: UK/EEA regions where offered by the provider. Data: transient call audio and transcripts. Providers are contractually prohibited from using customer data to train their foundation models.

Language model provider

Purpose: natural-language understanding and response generation. Location: UK/EU regions with zero data retention configured. Data: call transcript context passed at inference time. Zero-retention and no-training clauses are in place.

Email delivery — Postmark

Purpose: transactional email (appointment confirmations, receipts, support). Location: EU. Data: recipient email address, message content.

Product analytics — self-hosted PostHog

Purpose: privacy-preserving product analytics for the dashboard. Location: UK. Data: pseudonymised usage events.

Error monitoring — Sentry (EU region)

Purpose: application error monitoring. Location: EU (Frankfurt). Data: stack traces, request metadata; scrubbed of personal data before transmission.

Payment processing — Stripe Payments UK Ltd

Purpose: billing and subscription management. Location: UK/EU. Data: billing contact, card token, invoice history. Desklly does not store card numbers.

Customer support — Intercom

Purpose: support ticketing and knowledge base. Location: EU (Dublin). Data: support correspondence and contact details.