Sub-processors
Last reviewed: 25 July 2026
PanLuma engages the third parties below to operate the platform. Each is bound by a Data Processing Agreement (DPA) and uses appropriate technical and organisational measures to protect customer data.
This list is reviewed annually and updated whenever a sub-processor is added, replaced, or removed. The authoritative, version-controlled source is docs/security/policies/07-sub-processor-list.md in our repository, which records the full data categories and DPA reference for each entry.
Material additions are communicated to customers in advance per their DPA.
Always-on sub-processors (required for platform operation)
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting infrastructure: application, database, cache, object storage, CDN/WAF, secrets, logs, DNS. | us-east-1 (N. Virginia) |
| Anthropic (Claude) | LLM provider for in-app AI assistants, AI agents, AI Chat, AI evaluation, and coding tasks. Does not train on API customer data. | United States, EU SCCs |
| Twilio / SendGrid | Transactional email (notifications, password resets, customer-portal invites, support replies). | United States, EU SCCs |
| MaxMind (GeoLite2) | IP-to-geolocation lookup via a local database. No live API calls. | Local processing only |
| Stripe | Payment processing for your own PanLuma subscription and usage billing. Card details are entered directly into Stripe’s hosted fields. | United States, EU SCCs |
User-initiated integrations
These sub-processors receive customer data only when a customer explicitly connects the integration in their workspace, by granting OAuth access or entering an API key. Disconnecting revokes the grant.
| Sub-processor | Purpose | Region |
|---|---|---|
| Gmail, Drive, Sheets, Docs, Calendar, Maps, Google SSO. Also Google Ads lead forms and offline conversion import for marketing. | United States, EU SCCs | |
| Microsoft | Microsoft SSO, Outlook Mail, Outlook Calendar, OneDrive, Excel. | Multi-region, EU SCCs |
| Apple | Sign in with Apple (SSO), including the optional private email relay. | United States, EU SCCs |
| Notion | Notion workspace access for the connecting user. | United States, EU SCCs |
| Meta | Meta Lead Ads and WhatsApp Business inbound messages become leads and contacts; Meta Conversions API sends server-side conversion events. | United States / Ireland, EU SCCs |
| Stripe | Card payment collection from your customers via Stripe Connect, settling to your own Stripe account. Separate from the always-on entry above, which is your own PanLuma bill. | United States, EU SCCs |
| Plaid | Bank-feed aggregation for the accounting module (balances, transactions, account metadata). | United States, EU SCCs |
| Mercury | Direct bank-feed sync for Mercury accounts in the accounting module. | United States |
| Shopify | Two-way commerce sync: product catalogue, stock levels, orders imported as sales orders, shoppers imported as contacts. | Canada / United States, EU SCCs |
| Ocean carriers (DCSA Track & Trace) | Direct-from-carrier container milestone tracking for the shipments module. Each carrier is bound by your own contract with that carrier. | Carrier-dependent (global) |
| OpenAI | Alternative LLM provider — only when the tenant supplies their own API key. | United States, EU SCCs |
| Google Gemini API | Alternative LLM provider — only when the tenant supplies their own API key. | United States, EU SCCs |
| Morning (Green Invoice) | Statutory Israeli tax invoicing — only when the tenant supplies their own API key. Receives the invoice or receipt pushed for issuance. | Israel |
Supporting sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| PostHog | Product analytics for the application (opt-out available per tenant). | EU (Frankfurt) |
| Plausible | Privacy-first, cookie-free analytics for the marketing site only. | EU (Germany) |
| Serper.dev | Web search service used by AI agents. | United States, EU SCCs |
| ShipsGo | Default ocean-container tracking provider. Receives container and booking references. | Italy / EU |
| Terminal49 | Alternative ocean-container tracking provider. Receives container and booking references. | United States |
| OpenRouter | AI model pricing reference data. No customer data sent. | United States |
| Simli | Avatar video generation for the avatar feature. | United States, EU SCCs |
| Deepgram | Speech-to-text for avatar / voice features. | United States, EU SCCs |
| Cartesia | Text-to-speech for avatar / voice features. | United States, EU SCCs |
| E2B | Code-execution sandboxes for the coding module and certain agent tools. | United States, EU SCCs |
| Yahoo Finance | Public financial data. No customer data sent. | United States |
| GitHub | Source-code hosting for PanLuma’s own engineering. No customer data flows at runtime. | United States, EU SCCs |
Pending sub-processors (not yet active)
The integrations below are configured as coming_soon in our catalogue. They do not currently process any customer data, and each will be promoted to the lists above — with advance notice per your DPA — when it goes live: Slack, GitHub (as a user-facing integration, distinct from source-code hosting above), Jira, Salesforce, HubSpot, QuickBooks, Zendesk, E2open / INTTRA (ocean-carrier booking, shipping-instruction and VGM messaging), FullEnrich (business-email finding for prospecting), and ZeroBounce (email-deliverability verification for prospecting).
Questions
For sub-processor questions or to request our customer DPA, email privacy@panluma.ai.
