Subprocessors
Last updated Effective Avalon Flow Inc., a subsidiary of Questili LLPsupport@avalonflow.com
For this policy, "Avalon," "we," "us," or "our" means Avalon Flow Inc., a subsidiary of Questili LLP, unless a signed order form or customer agreement identifies a different contracting entity.
This Subprocessor List identifies providers that Avalon uses or may use to provide, secure, support, analyze, bill for, and improve Avalon. Some providers apply only when a feature, deployment path, payment method, support channel, analytics tool, or integration is enabled.
A "subprocessor" is a third-party service provider that may process Customer Content or personal information to help Avalon provide the service. Customer-controlled systems, including customer local models, customer custom endpoints, customer Google accounts/Google Workspace tenants, customer Microsoft tenants, customer Slack workspaces, and customer Salesforce/MCP systems, may process data as customer-selected systems rather than Avalon subprocessors, depending on the configuration.
Core subprocessors
| Provider | Purpose | Use status | Data categories |
|---|---|---|---|
| Google APIs / Gmail / Google Workspace | Gmail mailbox, Google Calendar, Google Drive where enabled, Google identity/OAuth, and Pub/Sub notifications | Core where Google/Gmail features are enabled | account identity, OAuth tokens, mailbox metadata/content, labels, calendar context, Drive/file context where enabled, Pub/Sub metadata |
| Microsoft Graph / Microsoft identity | Outlook/Microsoft mailbox, calendar, identity, OAuth, and Microsoft account integration | Core where Microsoft/Outlook features are enabled | account identity, OAuth tokens, mailbox metadata/content, calendar context |
| Amazon Web Services | Production cloud infrastructure for supported AWS deployment paths, including EC2/ECS/Fargate or related AWS services where configured | Core where Avalon uses an AWS production path | account, workflow, mailbox, AI context, logs, audit, privacy request, and operational data |
| Prisma Postgres | Production database | Core where enabled | account, session, OAuth, mailbox, workflow, Flowboard, AI context, calendar, admin, audit, billing data |
| Upstash Redis/QStash | Queue, cache, retry, idempotency, background processing | Core where enabled | workflow execution and observability metadata |
| Sentry | Error tracking | Core where enabled | error and observability data; account identifiers may appear in diagnostics |
| PostHog | Product analytics | Core where enabled | account and usage analytics metadata |
| Resend | Transactional email | Core where enabled | account identity and email delivery metadata |
Conditional subprocessors and connected services
| Provider | Purpose | Applies when | Data categories |
|---|---|---|---|
| Slack | Messaging integration | A customer connects Slack | OAuth tokens, Slack identity, channel/message metadata, selected workflow context |
| Salesforce / Salesforce MCP | CRM integration through MCP | A customer connects Salesforce or Salesforce MCP | CRM metadata/content selected by customer configuration |
| OpenAI | Hosted AI provider | Enabled as an AI provider | AI context and relevant mailbox/workflow content |
| Anthropic | Hosted AI provider | Enabled as an AI provider | AI context and relevant mailbox/workflow content |
| Google AI | Hosted AI provider | Enabled as an AI provider | AI context and relevant mailbox/workflow content |
| Groq | Hosted AI provider | Enabled as an AI provider | AI context |
| OpenRouter | Hosted AI router | Enabled as an AI provider or router | AI context and relevant mailbox/workflow content |
| Vercel AI Gateway | Hosted AI gateway | Enabled as an AI gateway | AI context |
| AWS Bedrock | Hosted/private AI provider | Enabled as an AI provider | AI context |
| Perplexity | Hosted AI/search provider | Enabled as an AI/search provider | AI context and relevant mailbox/workflow content |
| Customer custom/local AI endpoints | BYO key, custom endpoint, local model, private model, or self-hosted inference processing | Customer configures customer-controlled model routing | AI context and relevant mailbox/workflow content, controlled by customer configuration |
| Stripe | Payments and subscriptions | Customer pays through Stripe | billing and account identity data |
| Google Analytics / Google Ads | Marketing analytics and advertising measurement | Enabled on public marketing pages and acquisition/conversion flows | campaign, page-view, browser/device, event, and conversion metadata |
| Dub | Referral and link analytics | Enabled for referral/link tracking | account and observability metadata |
| Meta Conversions API | Conversion analytics and advertising measurement | Enabled for marketing measurement | conversion, campaign, browser/device, event, and observability metadata |
Marketing integration caveat
Avalon should not add a new client-side tag, tag manager, or third-party script that processes personal information or Customer Content unless that provider is reviewed, added to this list or otherwise disclosed where required, and approved under the application-integrity control.
Non-subprocessor operational providers
Some providers support Avalon operations without intentionally processing Customer Content as customer-facing subprocessors. For example, GitHub may be used for source control and CI/CD, and Let's Encrypt / Certbot may be used for TLS certificate issuance and renewal.
Customer-controlled systems
When a customer enables its own Google account/Google Workspace tenant, Microsoft tenant, Slack workspace, Salesforce instance, MCP server, custom endpoint, BYO AI provider, local model, private model, self-hosted inference system, or model gateway, that system may process Customer Content according to the customer's configuration and the system's own terms and security controls. Customers are responsible for confirming authorization, security, licensing, retention, logging, and privacy posture for customer-controlled systems.
Subprocessor changes
Avalon may update this list as providers, features, or deployment paths change. When required by an applicable agreement, Avalon will provide notice of material subprocessor changes through the product, website, email, account notice, or customer agreement process.
Contact
For questions about subprocessors or customer-controlled systems, contact support@avalonflow.com.
Code-backed vendor registry
Avalon also maintains this page from the same internal vendor registry used by compliance checks, so public disclosure does not drift from the production provider inventory.
| Provider | Purpose | Use status | Data classes |
|---|---|---|---|
| Microsoft Graph / Microsoft identity | Mailbox, calendar, identity, OAuth provider | Customer-facing subprocessor | ACCOUNT_IDENTITY, OAUTH_SECRET, MAILBOX_METADATA, MAILBOX_CONTENT_CACHE, CALENDAR_DRIVE_CONTEXT |
| Google APIs | Calendar and Drive integrations when enabled | Conditional or customer-enabled | OAUTH_SECRET, CALENDAR_DRIVE_CONTEXT |
| Slack | Messaging integration when enabled | Conditional or customer-enabled | OAUTH_SECRET, CALENDAR_DRIVE_CONTEXT |
| Upstash Redis/QStash | Queue, cache, retry, idempotency | Customer-facing subprocessor | WORKFLOW_EXECUTION, OBSERVABILITY |
| Amazon Web Services EC2 | Production compute for the EC2, Node.js, and Nginx deployment path | Customer-facing subprocessor | ACCOUNT_IDENTITY, AUTH_SESSION, OAUTH_SECRET, MAILBOX_METADATA, MAILBOX_CONTENT_CACHE, WORKFLOW_CONFIG, WORKFLOW_EXECUTION, FLOWBOARD_STATE, AI_CONTEXT, CALENDAR_DRIVE_CONTEXT, ORG_ADMIN, API_ACCESS, AUDIT_LOG, PRIVACY_REQUEST, BILLING, OBSERVABILITY |
| Prisma Postgres | Production Postgres database | Customer-facing subprocessor | ACCOUNT_IDENTITY, AUTH_SESSION, OAUTH_SECRET, MAILBOX_METADATA, MAILBOX_CONTENT_CACHE, WORKFLOW_CONFIG, WORKFLOW_EXECUTION, FLOWBOARD_STATE, AI_CONTEXT, CALENDAR_DRIVE_CONTEXT, ORG_ADMIN, API_ACCESS, AUDIT_LOG, PRIVACY_REQUEST, BILLING |
| Let's Encrypt / Certbot | TLS certificate issuance and renewal for production domains | Operational provider | OBSERVABILITY |
| OpenAI | Hosted AI provider when enabled | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE |
| Anthropic | Hosted AI provider when enabled | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE |
| Google AI | Hosted AI provider when enabled | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE |
| Groq | Hosted AI provider when enabled | Conditional or customer-enabled | AI_CONTEXT |
| OpenRouter | Hosted AI router when enabled | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE |
| Vercel AI Gateway | Hosted AI gateway when enabled | Conditional or customer-enabled | AI_CONTEXT |
| AWS Bedrock | Hosted/private AI provider when enabled | Conditional or customer-enabled | AI_CONTEXT |
| Perplexity | Hosted AI/search provider when enabled | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE |
| OpenAI ChatGPT OAuth / Codex backend | User-connected ChatGPT sign-in model provider | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE, ACCOUNT_IDENTITY |
| Customer custom/local AI endpoints | BYO key, custom endpoint, or local model processing | Conditional or customer-enabled | AI_CONTEXT, MAILBOX_CONTENT_CACHE |
| Sentry | Error tracking | Customer-facing subprocessor | OBSERVABILITY, ACCOUNT_IDENTITY |
| PostHog | Product analytics | Customer-facing subprocessor | OBSERVABILITY, ACCOUNT_IDENTITY |
| Stripe | Payments and subscriptions | Conditional or customer-enabled | BILLING, ACCOUNT_IDENTITY |
| Resend | Transactional email | Customer-facing subprocessor | ACCOUNT_IDENTITY, OBSERVABILITY |
| GitHub | Source control and CI/CD | Operational provider | OBSERVABILITY |
| Google Analytics / Google Ads | Marketing analytics and advertising measurement | Conditional or customer-enabled | OBSERVABILITY |
| Dub | Referral and link analytics when enabled | Conditional or customer-enabled | ACCOUNT_IDENTITY, OBSERVABILITY |
| Meta | Conversion analytics when enabled | Conditional or customer-enabled | OBSERVABILITY |