Sub-processors
Who processes customer data on Actessia's behalf, for what, and where.
Last updated: 14 September 2026. Customers are notified 30 days before a change.
| Provider | Purpose | Location | What they receive |
|---|---|---|---|
| Supabase | Postgres with row-level security, dashboard authentication, file storage | European Union (Frankfurt) | All customer data at rest, encrypted; per-tenant keys are wrapped by Actessia's own key |
| Anthropic | Model inference: intent classification, answers, tool planning | United States | The conversation turn and the retrieved passages; never a credential; no retention of content |
| Voyage AI | Text embeddings for retrieval | United States | Document chunks and questions; no user identity |
| Stripe | Billing, invoicing, EU VAT | European Union / United States | The customer's billing profile and payments; no conversation data |
| Container host | The agent runtime, the broker, the ingestion worker | European Union | Named, with the region, in the list delivered with the DPA before the pilot starts |
| Transactional email | Escalation emails, billing notices | European Union | Named in the same list |
Actessia's own staff access customer data only through the dashboard's impersonation, which requires a written reason and appears in the customer's audit log, or through the internal admin application from allowed networks, where every action is recorded.