Sub-Processors
A sub-processor is a third-party data processor engaged by Warm Deals to assist in providing the Service. Sub-processors may have access to or process Personal Data only to deliver the services Warm Deals has retained them to provide, and they are prohibited from using that data for any other purpose.
Warm Deals maintains a written contract with each sub-processor that requires them to protect Personal Data with controls at least as strict as our own. The table below lists every sub-processor Warm Deals currently uses. Customers will receive at least 30 days' advance notice before any new sub-processor is added.
| Sub-Processor | Purpose | Data Categories | Location | Compliance |
|---|---|---|---|---|
| SendGrid (Twilio) | Transactional and outbound email delivery | Recipient email, message content, engagement events | United States | SOC 2 Type II, ISO 27001, GDPR DPA |
| Mailgun | Transactional and outbound email delivery (alternate provider) | Recipient email, message content, engagement events | United States | SOC 2 Type II, GDPR DPA |
| Postmark | Transactional and outbound email delivery (alternate provider) | Recipient email, message content, engagement events | United States | SOC 2 Type II, GDPR DPA |
| Twilio | SMS and voice campaign delivery | Phone number, message content, call metadata | United States | ISO 27001, SOC 2, GDPR DPA |
| ElevenLabs | Voice AI synthesis for outbound calling | Synthesised speech transcripts (script content) | United States | SOC 2 (in progress), GDPR DPA |
| Anthropic | AI features (Claude — LLM email/SMS generation, copilot) | Prompt content (may include CRM context provided by customer) | United States | SOC 2 Type II |
| OpenAI | AI features (GPT — fallback LLM provider) | Prompt content (may include CRM context provided by customer) | United States | SOC 2 Type II |
| LiteLLM / Groq | LLM routing and inference (model fallback layer) | Prompt content | United States | SOC 2 |
| Stripe | Billing and payments | Billing contact, payment method, invoice history | United States / Ireland | PCI DSS Level 1, SOC 1/2, ISO 27001 |
| AWS | Cloud infrastructure (compute, networking, storage) | All customer data at rest (encrypted) | United States and European Union | SOC 1/2/3, ISO 27001, ISO 27017/27018, GDPR DPA |
| MinIO | Object storage (recordings, attachments, exports) | Call recordings, file uploads, generated exports | Self-hosted within Warm Deals infrastructure | Inherits AWS controls |
| PostgreSQL | Primary application database | All structured customer data (leads, campaigns, settings) | Self-hosted within Warm Deals infrastructure | Inherits AWS controls |
| Redis | Cache, task queue (Celery), session/rate-limit state | Ephemeral cache keys, task payloads | Self-hosted within Warm Deals infrastructure | Inherits AWS controls |
| Sentry | Error tracking and performance monitoring | Stack traces, redacted request metadata | United States | SOC 2 Type II, ISO 27001 |
| HubSpot, Pipedrive, SalesforceOptional | Optional CRM sync — only if the customer connects them | Contact and deal data the customer chooses to sync | Customer-controlled | Inherits the CRM's own certifications |
| Hunter.io, Apollo.ioOptional | Optional contact enrichment — only if the customer connects them | Lead identifiers (name, company, email) | United States | GDPR DPA |
Questions or objections?
To object to a sub-processor on reasonable grounds, or to receive change notifications, email privacy@warm.deals. Enterprise customers can sign our Data Processing Agreement and exercise audit rights as described therein.
Last updated: 2026-05-25