Sub-processor Register

Every third party that processes personal data for Leveld, what it does, and where it keeps data.

  • Last updated 26 September 2026
  • 9 active
On this page

This is the closed register of third parties authorised to process personal data for Leveld’s Gmail-only free beta. It is incorporated into the Data Processing Agreement. We give customers at least 30 days’ prior written notice before adding or replacing a sub-processor, except where an urgent security or legal requirement makes advance notice impossible.

A. Sub-processors (UK GDPR Art. 28 processors)

#VendorPurposeDefault location
A1Amazon Web Services EMEA SARLApplication hosting, relational storage, object storage, encryption, secrets, transactional email and content delivery.United Kingdom (AWS eu-west-2) for the primary application and data plane. The marketing-media CDN uses the AWS global edge network.
A2Google Cloud EMEA LimitedGmail connector authorisation and APIs, deployment identity federation, and privacy-filtered product analytics.Google APIs are global services. Leveld analytics datasets are pinned to the European Union multi-region.
A3WorkOS, Inc.Email magic-code authentication and session management.United States.
A4OpenRouter, Inc. and authorised downstream model providersRouting Leveld AI inference to the approved model-provider portfolio.United States and the location disclosed by each authorised downstream provider endpoint.
A5Temporal Technologies, Inc.Managed durable workflow orchestration and workflow history.The production namespace region selected and recorded during the deployment readiness gate.
A6Grafana LabsApplication metrics, logs, traces, dashboards and operational alerting.The European data region selected and recorded during the deployment readiness gate.
A7LangChain, Inc.AI execution tracing, prompt versioning, evaluations and quality review.European Union (EU LangSmith region).
A8incident.ioSecurity and availability incident coordination, escalation and status communication.The contracted service region disclosed in the executed vendor terms.
A9Zendesk, Inc.Customer support requests and support communications.The contracted service region disclosed in the executed vendor terms.

A1. Amazon Web Services EMEA SARL

Processing purpose. Application hosting, relational storage, object storage, encryption, secrets, transactional email and content delivery.

Data categories Leveld sends. Customer content, account and workspace data, encrypted credentials, email delivery data and operational metadata.

Default data location. United Kingdom (AWS eu-west-2) for the primary application and data plane. The marketing-media CDN uses the AWS global edge network.

Transfer mechanism. UK-domestic for the primary region; the AWS Data Processing Addendum applies to any permitted international processing.

Contract and vendor chain. AWS Data Processing Addendum and AWS sub-processor list.

A2. Google Cloud EMEA Limited

Processing purpose. Gmail connector authorisation and APIs, deployment identity federation, and privacy-filtered product analytics.

Data categories Leveld sends. Google account identifiers and OAuth grants, Gmail content selected by the connector, and approved analytics events.

Default data location. Google APIs are global services. Leveld analytics datasets are pinned to the European Union multi-region.

Transfer mechanism. Google Cloud Data Processing and Security Terms, including the applicable EU Standard Contractual Clauses and UK Addendum.

Contract and vendor chain. Google Cloud Data Processing and Security Terms.

A3. WorkOS, Inc.

Processing purpose. Email magic-code authentication and session management.

Data categories Leveld sends. Email address, authentication event metadata, session identifiers and security telemetry.

Default data location. United States.

Transfer mechanism. WorkOS Data Processing Addendum, including EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

Contract and vendor chain. WorkOS Data Processing Addendum and sub-processor list.

The beta sign-in method is email magic code only. Google and Microsoft social sign-in are disabled.

A4. OpenRouter, Inc. and authorised downstream model providers

Processing purpose. Routing Leveld AI inference to the approved model-provider portfolio.

Data categories Leveld sends. Prompt content, retrieved context, tool results and generated responses needed to perform the requested product task.

Default data location. United States and the location disclosed by each authorised downstream provider endpoint.

Transfer mechanism. The OpenRouter agreement and the applicable downstream-provider terms; approved providers and endpoints are allowlisted before activation.

Contract and vendor chain. OpenRouter privacy terms and the approved provider register.

Leveld denies provider data collection for training. Leveld does not request or guarantee zero-data-retention routing, so prompt and response content may be retained under the configured provider’s contract and published terms.

A5. Temporal Technologies, Inc.

Processing purpose. Managed durable workflow orchestration and workflow history.

Data categories Leveld sends. Workflow identifiers, task inputs, execution state, retry metadata and failure details required to operate durable product workflows.

Default data location. The production namespace region selected and recorded during the deployment readiness gate.

Transfer mechanism. Temporal Cloud Data Processing Addendum and the transfer terms applicable to the selected namespace region.

Contract and vendor chain. Temporal Cloud Data Processing Addendum and sub-processor list.

A6. Grafana Labs

Processing purpose. Application metrics, logs, traces, dashboards and operational alerting.

Data categories Leveld sends. Privacy-filtered telemetry, pseudonymous identifiers, runtime metadata and error details. Raw customer content is prohibited telemetry.

Default data location. The European data region selected and recorded during the deployment readiness gate.

Transfer mechanism. Grafana Cloud Data Processing Agreement and the transfer terms applicable to the selected stack region.

Contract and vendor chain. Grafana Cloud Data Processing Agreement and sub-processor list.

A7. LangChain, Inc.

Processing purpose. AI execution tracing, prompt versioning, evaluations and quality review.

Data categories Leveld sends. Content-free execution traces: model and prompt identifiers, tool-call metadata, sizes, timings and pseudonymous tenant, project and user identifiers. Message, email and output text is not sent.

Default data location. European Union (EU LangSmith region).

Transfer mechanism. EU data-region processing and the LangChain Data Processing Addendum, including applicable transfer terms.

Contract and vendor chain. LangChain Data Processing Addendum and sub-processor list.

The lean beta uses base trace retention. Run inputs, outputs and error text are removed before export.

A8. incident.io

Processing purpose. Security and availability incident coordination, escalation and status communication.

Data categories Leveld sends. Incident metadata, affected-system details, responder contact data and privacy-filtered alert context.

Default data location. The contracted service region disclosed in the executed vendor terms.

Transfer mechanism. The executed incident.io data-processing terms and their applicable international-transfer safeguards.

Contract and vendor chain. Executed incident.io data-processing terms and sub-processor list.

A9. Zendesk, Inc.

Processing purpose. Customer support requests and support communications.

Data categories Leveld sends. Customer contact details, support-ticket content, attachments supplied by the customer and ticket metadata.

Default data location. The contracted service region disclosed in the executed vendor terms.

Transfer mechanism. The executed Zendesk data-processing terms and their applicable international-transfer safeguards.

Contract and vendor chain. Executed Zendesk Data Processing Agreement and sub-processor list.

B. Independent controllers

The free beta has no independent third-party controller receiving customer data for payment collection. Leveld does not collect card, bank-account, mandate or payment-transaction data in this release profile.

C. Inactive and future services

Not active in this release

Providers and data flows for inactive connectors, future authentication methods, future billing, and future product surfaces are not authorised beta sub-processors. This register will be updated and customers notified before any such service begins processing customer personal data.

D. Reference data held locally

Leveld works out the approximate location (city, region and country) of the IP address a sign-in comes from using the MaxMind GeoLite2 City database, which we download and hold in our own AWS account. Lookups happen inside Leveld, so no personal data is sent to MaxMind and MaxMind is not a sub-processor. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

Last updated 26 September 2026. Contact get@leveld.ai for sub-processor questions or to subscribe to change notices.