Sub-processors
Every vendor that touches customer data, what it receives, and where it operates. The model vendor is on the list, which is the row most vendor lists leave out.
Version 1.0.0 Effective 2026-08-24 Last updated 2026-08-24
In short
Applies to: Procurement and security reviewers
- The model vendor is named, which is the row most vendor lists leave out.
- The underlying cloud is named for any vendor reselling infrastructure.
- Changes carry 30 days of notice before processing begins.
The list
A row marked as not chosen is a decision we have not taken. It is on the list so that a reviewer can see the shape of the finished list rather than discovering a new vendor after signature.
| Vendor | What it does | Data it receives | Where | Status |
|---|---|---|---|---|
| Google Cloud, Vertex AI | Runs the personas. Receives the brief, the session audio and the transcript | Your audio, your transcript, the brief, persona speech | us-central1, United States | Confirmed |
| Google Cloud, Speech-to-Text | Transcribes what you say so the personas can read it | Your audio, your transcript | us-central1, United States | Confirmed |
| Media server | Carries audio between your browser and the personas | Your audio and persona audio, in transit | Decided with the vendor | Vendor not chosen yet |
| Paddle, merchant of record | Takes subscription payments as the seller of record, and issues the invoice. No card number reaches us | Billing identifiers and transaction metadata | Decided with the vendor | Vendor not chosen yet |
| Application hosting | Serves this website and the application | Request metadata, account data, transcripts, the brief | Decided with the vendor | Vendor not chosen yet |
| Brevo, transactional email | Sends verification, receipts, billing notices and erasure certificates | Your email address and the content of the message | Decided with the vendor | Vendor not chosen yet |
| WorkOS, enterprise federation | Carries single sign-on and directory sync for a company that signs in through its own identity provider | Your email address, your name, and the group memberships your employer syncs | Decided with the vendor | Vendor not chosen yet |
| Error monitoring | Reports faults so they can be fixed | Stack traces. No request bodies | Decided with the vendor | Vendor not chosen yet |
Total vendors that will touch customer data: 8
What the model vendor does with your session
Audio and text sent to Vertex AI are processed to generate the personas' responses. Google states that customer data submitted to Vertex AI is not used to train or fine-tune its models without permission, that cached content is held for up to 24 hours in the data centre serving the request, and that prompts may be logged for abuse detection unless an exception is agreed.
Google, Vertex AI data governance opens in a new tab
That is Google's commitment and not ours. We do not restate a vendor's promise as though we made it. Ours is the sentence above it: we do not use your sessions to train anything.
Sub-sub-processors
Where a vendor is itself reselling infrastructure, the underlying cloud is named in its row. A list that stops at the reseller tells a reviewer nothing, and it is the omission our own extraction criticises in the vendor lists we read.
Changes
Related questions
Who can hear my strategic weaknesses?
Nobody else joins a Tingvar room: the participants are you and the AI personas, and the audio is not stored for anyone to play back later. The transcript is the part that persists, and it reaches our model vendor as part of the personas' context. Every vendor that touches customer data is named on the sub-processors page, including the model vendor. Who at Tingvar can read a transcript, and in what circumstances, is stated at tingvar.com/trust/your-data.
Is my data used to train AI models?
No, Tingvar does not use your brief, your transcript or your audio to train models. Google, which runs the model, states that customer data submitted to Vertex AI is not used to train or fine-tune its models without permission, that cached content is held for up to 24 hours in the data centre serving the request, and that prompts may be logged for abuse detection unless an exception is agreed. It is linked from our sub-processors page so you can check it.
Who are your sub-processors?
Tingvar publishes every vendor that touches customer data at tingvar.com/subprocessors, including the model vendor, with the jurisdiction each one operates in. The list names the underlying cloud for any vendor that is itself reselling infrastructure, because a list that stops at the reseller tells a reviewer nothing. We give 30 days' notice before a new sub-processor begins processing customer data, and you can subscribe to changes. The page carries an effective date, so you can tell how current it is.