Sub-processors
Last updated: 17 August 2026 · v2026.08
A sub-processor is a third party that processes personal data on our behalf in order to deliver the Service. This page names every one, what it does, what data reaches it, and where it processes that data.
Customers are the data controllers for the CRM records and mail content they bring to the Service; we are the processor, and the parties below are our sub-processors. See the Privacy Policy for the full picture.
Current sub-processors
| Sub-processor | Purpose | Data categories | Region | Terms |
|---|---|---|---|---|
| Amazon Web Services | Hosting and compute for the platform and every tenant runtime; database and object storage; backup archives | All Customer data at rest and in processing | United States | aws.amazon.com/service-terms |
| Cloudflare | DNS and edge termination for nurturecrm.ai and tenant subdomains |
Request metadata — IP address, user agent, requested host and path | Global edge network | cloudflare.com/privacypolicy |
| Stripe | Subscription billing and payment processing | Customer billing contact, subscription state, payment method details collected directly by Stripe | United States, with global processing | stripe.com/privacy |
| Microsoft | Microsoft Graph access to connected Microsoft 365 mailboxes | Message headers, bodies and metadata from the consenting mailbox; the mailbox owner's identity | Determined by the Customer's own Microsoft 365 tenant region | microsoft.com/privacystatement |
| Gmail API access to connected Gmail mailboxes; Cloud Pub/Sub for change notifications | Message headers, bodies and metadata from the consenting mailbox; labels; the mailbox owner's identity | United States | policies.google.com/privacy | |
| OpenAI | AI text generation, summarization, scoring, and batch audio transcription | The scoped context sent for a specific AI request, which may include CRM records and mail content | United States | openai.com/policies |
| Anthropic | AI text generation and summarization | The scoped context sent for a specific AI request, which may include CRM records and mail content | United States | anthropic.com/legal/privacy |
| AssemblyAI | Live speech-to-text for meeting transcription, only where that provider is configured for the deployment. Otherwise transcription uses OpenAI | Meeting audio streamed during a recorded session, and the resulting transcript | United States | assemblyai.com/legal/privacy-policy |
| Amazon Rekognition (AWS) | Face detection and matching on event photos, where the Customer uses Marketing Events | Photographs uploaded by the Customer and facial-geometry templates derived from them, held in a collection scoped to that Customer | United States | aws.amazon.com/service-terms |
| Resend | Transactional email sent from a Customer's runtime — booking confirmations, form notifications | Recipient address, sender identity, message content of the transactional message | United States | resend.com/legal/privacy-policy |
| Amazon SES | Platform email sent by NurtureCRM itself — signup, credentials and account notices | Administrator email address and the content of the platform notice | United States | aws.amazon.com/service-terms |
Microsoft and Google are listed here because they process data on our behalf when we call their APIs for a connected mailbox. They are also independent controllers of their own platforms, and their own terms govern the mailbox itself.
Amazon Rekognition is listed separately from general AWS hosting because the data category is different in kind: facial-geometry templates may be biometric data under some privacy laws. It is used only if the Customer uses Marketing Events and uploads event photographs.
Customer-configured integrations
These are not our sub-processors. Each is enabled by the Customer, using the Customer's own account and API credential, and the Customer directs what is sent. We transmit data to them only because the Customer configured us to.
| Integration | What the Customer uses it for | Credential |
|---|---|---|
| Apify | Web and LinkedIn scraping for contact and company enrichment | The Customer's own Apify API key, stored in their organization settings |
| Exa | AI-assisted web search for enrichment | The Customer's own Exa API key, stored in their organization settings |
| GoHighLevel and other form-forwarding destinations | Forwarding form submissions to a system the Customer runs | The Customer's own integration token |
Where a Customer enables one of these, that provider's terms and the Customer's own agreement with them govern the transfer. Disabling the integration or removing the credential stops it. Customers acting as controllers should account for these in their own records of processing.
Commitments
- No training on Customer data. No AI provider above uses Customer data — including mail content — to train or improve any model. For OpenAI and Anthropic that is the contractual default. For AssemblyAI it is an account-level opt-out that must be, and is, enabled wherever that provider is configured; a deployment that cannot enable it does not use AssemblyAI. The per-provider basis is set out in the AI Policy.
- Google user data. Transfers of Google user data to any party on this list are limited to those permitted by the Google API Services User Data Policy, as set out at Google Limited Use.
- Contractual terms. Each sub-processor is engaged under terms requiring confidentiality, appropriate security measures, and processing only on our instructions.
- International transfers. Where personal data originating in the European Economic Area or the United Kingdom reaches a sub-processor in the United States, the transfer is made under Standard Contractual Clauses or another lawful transfer mechanism.
Changes to this list
We will give Customers at least 30 days' advance notice before adding a new sub-processor that processes Customer data, by updating this page and notifying the Customer's registered contact. The version and effective date at the top of this page change with every addition or removal.
A Customer with a data processing agreement in place may object to a new sub-processor as that agreement provides.
Contact
Questions about this list, or a request to be notified of changes: support@aicoaches.com
AiCoaches dot com LLC 111 NE 1ST ST, 8TH FLOOR 89145, Miami, Florida, USA 33132