Skip to content
Kanesh

Legal

Sub-processors

The providers Number Studios SL uses to deliver Kanesh that process personal data of our customers and their end customers, under the general authorisation in the data processing agreement.

Last updated:

This English text is a courtesy translation. In case of discrepancy the Spanish version prevails.

1.Current list

Kanesh sub-processors: provider, purpose, data, location and transfer safeguard
ProviderPurposeDataData locationTransfer safeguard
Amazon Web Services (US)Application infrastructure (compute, database and storage) and email sending (Amazon SES)All service dataEU (Ireland, eu-west-1 region)EU-US Data Privacy Framework (Amazon.com, Inc. certification, which covers AWS)
Cloudflare (US)DNS, delivery network and protection (proxy) for the service's domains; hosting of this websiteTechnical request data (IP address, headers) and the traffic that passes through its networkGlobal network; per the provider's termsEU-US Data Privacy Framework (Cloudflare is certified)
Google (Gemini API)AI processing: drafting replies, checking them and searching the customer's knowledgeConversation content, customer knowledge and the order data needed to replyPer the provider's termsEU-US Data Privacy Framework (Google LLC is certified)
Meta Platforms (WhatsApp, Instagram, Messenger)Messaging channels, when the customer connects themContact identifiers and message contentPer the provider's termsMeta contracts in the EU from Ireland; transfers to its US parent rely on the EU-US Data Privacy Framework
360dialog (Germany)WhatsApp Business Solution Provider, when usedPhone numbers and WhatsApp message contentPer the provider's termsProvider established in the EU; onward transfers per its terms
Telnyx (US)Voice calls, only when the customer enables voicePhone numbers, call audio, and recordings and transcripts if enabledPer the provider's termsEU-US Data Privacy Framework (Telnyx is certified)
StripeBilling for Kanesh accounts and the prepaid balanceOur customers' billing and payment data (not their end customers')Per the provider's termsStripe contracts in the EU from Ireland; transfers to its US parent rely on the EU-US Data Privacy Framework

The regions shown are the documented ones. Where it says “per the provider's terms”, the provider doesn't commit to a specific region for that processing.

2.International transfers

Amazon Web Services, Cloudflare, Google, Meta, Telnyx and Stripe are based in the United States or have a US parent. 360dialog is established in Germany. Even when data is stored in the EU, a US provider may access it from outside, so we treat all those cases as international transfers.

  • Providers certified under the EU-US Data Privacy Framework (today, all the US providers on this list): the transfer relies on the European Commission's adequacy decision, Implementing Decision (EU) 2023/1795 of 10 July 2023 (GDPR article 45).
  • If a provider isn't certified or its certification lapses: the transfer relies on the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (GDPR article 46), incorporated in its data processing agreement.

Each provider's certification status comes from its own public statements, reviewed on 30 September 2026. We check it against the official list (dataprivacyframework.gov) before onboarding a provider and periodically afterwards.

Where a transfer relies on standard contractual clauses, we document a transfer impact assessment and, where needed, supplementary measures. You can ask us about any provider's safeguard at [email protected].

3.What isn't on this list

Services each customer connects and authorises itself, such as its Shopify store, its Klaviyo account, its Google Workspace or Microsoft 365 mailbox, or its marketplaces and carriers, are not our sub-processors: the customer deals with them directly, under their terms, and data flows because it decides so.

Providers we use for our own processing as a controller (for example, our company email) are listed in the privacy policy.

4.Changes to this list: prior notice and objection

  • 30 days' notice. Before a new or replacement sub-processor processes a customer's data, we will email the customer's account administrator and publish the change on this page, at least 30 days in advance.
  • Subscribing to changes. Anyone can receive these notices by email: write to [email protected] with the subject “Suscripción subencargados”.
  • Right to object. Within those 30 days, the customer may object on reasonable data protection grounds, explained in writing. We will look in good faith for a solution, such as not using that provider for its data or an alternative configuration.
  • If there is no solution. The customer may terminate the contract for the affected service without penalty, and we will refund the pro-rata part of any fees it prepaid for the unused period.
  • Urgent replacement. If a sub-processor has to be replaced urgently for security or service-continuity reasons, we will give notice as soon as possible, explain why, and the right to object applies in the same way from that notice.

This list and this procedure are part of the general authorisation in the data processing agreement (GDPR article 28.2).

5.Change log

Change log of the sub-processor list
DateChange
October 2026Initial publication of the list.