Sub-processors
This page lists the third parties ("sub-processors") that Aivonic AB engages to deliver its services, and that may process personal data on our customers' behalf. It covers all Aivonic services: Aivonic Workspace, AivoniClaw, our AI chat and email agents, and our Voice AI.
Our Data Processing Agreement grants general authorisation for the sub-processors on this page, so this page is the operative list for the purposes of Article 28(2) of the GDPR. It is kept current.
Which sub-processors apply to a given customer depends on which services and integrations that customer uses. Each section below states who it applies to. A customer who never uses Voice AI has no Voice AI sub-processors; a customer who never uses AivoniClaw outreach has no outreach sub-processors.
We require every sub-processor to offer data-protection guarantees no less protective than our own Data Processing Agreement, and, where it processes data outside the EEA, to be covered by an approved transfer mechanism.
How we notify you of changes
We give at least 30 days' notice before adding or replacing a sub-processor that processes customer personal data, by email and by updating this page. If you object on reasonable data-protection grounds, contact privacy@aivonic.ai. If we cannot resolve the objection, you may terminate the affected service.
Current sub-processors
Infrastructure and hosting
All services.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Hostinger International Ltd | Server hosting (VPS). Runs the voice stack, the Voice AI client portal at voice.aivonic.ai, the agent client portal at agents.aivonic.ai, and the call-recording storage. Hostinger also takes weekly whole-server backup images, which it stores in Lithuania. | Frankfurt, Germany (EEA). Hostinger-held server backups are stored in Lithuania (EEA). | Processing within the EEA |
Aivonic operates its own object storage, its own databases and its own self-hosted language models on the infrastructure above. Those are run by Aivonic and are not third-party sub-processors.
AI and language models
All services, depending on which model answers a given request.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Mistral AI | Language model inference. Mistral is the language model for every Voice AI call. | France (European Union) | Processing within the EEA |
| Anthropic, PBC | Language model inference where an Aivonic-operated model is not used, including the automatic fallback for chat agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| OpenAI, L.L.C. | Language model inference where selected for an Aivonic-operated feature. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Aivonic runs its own language models on its own hardware. Where an Aivonic-operated model answers, no third-party model provider receives the content.
Bring your own key: where a customer configures their own AI provider key, that provider is engaged by the customer under the customer’s own terms with that provider, and is not an Aivonic sub-processor.
Outreach and email
Only customers using the AivoniClaw outreach features.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Smartlead | Email sending, warmup, inbox rotation and reply detection. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Apollo.io | Lead and contact sourcing and enrichment. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| AgentMail | Inbound and outbound email handling for agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| NeverBounce | Email address verification before sending. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Messaging, payments, scheduling and analytics
Customers using the corresponding channel or integration.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Meta Platforms (WhatsApp Cloud API) | WhatsApp messaging, where a customer enables the WhatsApp channel. | Ireland (European Union) and United States | Standard Contractual Clauses where the transfer leaves the EEA |
| Stripe | Subscription billing and payments. | Ireland (European Union) and United States | Standard Contractual Clauses. Stripe acts as an independent controller for card data. |
| Cal.com | Appointment scheduling, where an agent books meetings. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Aivonic's own website and sales lead handling
No customer. These process data about people who visit aivonic.ai or submit our own enquiry form, where Aivonic is the controller. They are recipients under our Privacy Policy, not sub-processors for anyone's data.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Netlify, Inc. | Hosting, CDN and authoritative DNS for the aivonic.ai marketing website. Netlify serves that website only. It is not part of the Voice AI stack, the client portals, Workspace or AivoniClaw, and it never receives customer data. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Google (Analytics and Tag Manager) | Visitor analytics on the aivonic.ai marketing website only, and only where the visitor has accepted analytics cookies. Not present in any product. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Tavily | Extracts the readable text of the website a sales enquiry names, so we can prepare for the call back. Receives the URL supplied on the form, not the enquirer's own details. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| OpenRouter | Generates the business summary and the sales briefing used to prepare for a call back to someone who submitted our enquiry form. Receives the business name, website and the extracted website text. OpenRouter routes the request onward to the model providers it selects. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Voice AI
Only customers using the Voice AI product.
| Sub-processor | Purpose | Entity and location | Transfer mechanism |
|---|---|---|---|
| Deepgram | Speech to text. | United States company. Aivonic routes speech recognition to Deepgram’s EU endpoint by default for all calls. | Standard Contractual Clauses (Module Three, processor to processor) |
| ElevenLabs | Text to speech. Primary voice provider for some agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Inworld | Text to speech. Primary voice provider for some agents. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Cartesia | Text to speech, automatic failover only. Engaged when the selected voice provider is unavailable, so that a provider outage does not drop a call in progress. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
| Mistral AI | Language model for voice agents. | France (European Union) | Processing within the EEA |
| LiveKit | Real-time audio transport. | United States company. Aivonic’s rooms are served from LiveKit’s European region, so call audio in transit is handled within the EEA. | Standard Contractual Clauses (Module Three, processor to processor) |
| 46elks | Telephony and SIP connectivity (Swedish numbers). | Sweden (European Union) | Processing within the EEA |
| Twilio | Telephony and SIP connectivity, where used for a given number. | United States | Standard Contractual Clauses (Module Three, processor to processor) |
Which text-to-speech provider processes a given call depends on the voice selected for that agent. Aivonic confirms on request which providers apply to a specific customer’s agents.
Call recordings are stored on Aivonic’s own infrastructure. No third-party storage provider is engaged for call audio.
The Voice AI client portal at voice.aivonic.ai is Aivonic’s own product, not a third party. It adds no sub-processor, but it is where the customer accesses the data, so the hosting location above governs it.
Voice AI: what is kept, and for how long
Call audio is deleted after 30 days and transcripts after 90 days. Deletion is carried out by a scheduled process that runs nightly, not on request, and the same process also removes audio that is no longer referenced by a call record. When a recording passes its retention period it is deleted from storage and stops being retrievable through the client portal at the same time.
Where a customer has agreed a different retention period in writing, that period governs and the agent is configured to match, so the configured period and the published period cannot diverge.
Whether a voice agent records calls at all is a per-agent setting, made on the customer's instruction. Where recording is switched off, no call audio is created; only a transcript.
What is not a sub-processor
- Aivonic's own storage and databases. Object storage, databases and call-recording storage are operated by Aivonic on the infrastructure listed above, not by a third party.
- Aivonic's own language models. Aivonic runs models on its own hardware. Where one of those answers, no third-party model provider receives the content.
- Providers you connect yourself. Where you supply your own API key for an AI provider, or connect your own third-party account, that provider is engaged by you under your own terms with them.
Contact
Aivonic AB, org. no. 559483-4961, Spovgränd 1, 383 35 Mönsterås, Sweden.
Privacy and data-protection matters: privacy@aivonic.ai