Subprocessors
Home»Subprocessors
Who else touches your data
A subprocessor is a third-party provider that processes customer data on BMaiKR's behalf as part of delivering a service. This list is kept current as providers are confirmed or change — anything not yet verified against provider documentation is marked accordingly rather than guessed at.
| Provider | Purpose | Data processed | Location | Status | Last reviewed |
|---|---|---|---|---|---|
| HostPowr | Infrastructure and hosting | Application data, files, and backups for hosted workloads | Europe | Requires provider documentation | To be documented |
| External AI providers | AI reasoning and response generation | Task-relevant context only — scope depends on the specific automation configured | Depends on the provider selected for the workload | Provider dependent | Reviewed per project configuration |
| Email delivery provider | Transactional and notification email | Name, email address, message content submitted through site forms | To be documented | To be documented | To be documented |
| Analytics | Website usage analytics | Depends on the analytics configuration deployed for a given site | To be documented | Customer configuration | To be documented |
| Monitoring | Infrastructure and application monitoring | Technical/operational logs — not intended to include customer content | To be documented | To be documented | To be documented |
| DNS / CDN / WAF | Domain resolution, content delivery, and web application firewall | Request metadata (IP address, headers) required to route and protect traffic | Global edge network — varies by provider | To be documented | To be documented |
| Messaging integrations | Customer communication channels (e.g. WhatsApp Business) | Message content and contact details for the conversations routed through the integration | Provider-specific | Customer configurable | Reviewed per integration |
| CRM and third-party integrations | Business systems a customer chooses to connect | Depends entirely on the integration a customer selects and configures | Depends on the integration selected | Customer configurable | Reviewed per integration |
HostPowr
Requires provider documentation- Purpose
- Infrastructure and hosting
- Data processed
- Application data, files, and backups for hosted workloads
- Location
- Europe
- Transfer mechanism
- Not applicable — EU-based hosting
- Last reviewed
- To be documented
External AI providers
Provider dependent- Purpose
- AI reasoning and response generation
- Data processed
- Task-relevant context only — scope depends on the specific automation configured
- Location
- Depends on the provider selected for the workload
- Transfer mechanism
- Provider-specific terms apply
- Last reviewed
- Reviewed per project configuration
Email delivery provider
To be documented- Purpose
- Transactional and notification email
- Data processed
- Name, email address, message content submitted through site forms
- Location
- To be documented
- Transfer mechanism
- To be documented
- Last reviewed
- To be documented
Analytics
Customer configuration- Purpose
- Website usage analytics
- Data processed
- Depends on the analytics configuration deployed for a given site
- Location
- To be documented
- Transfer mechanism
- To be documented
- Last reviewed
- To be documented
Monitoring
To be documented- Purpose
- Infrastructure and application monitoring
- Data processed
- Technical/operational logs — not intended to include customer content
- Location
- To be documented
- Transfer mechanism
- To be documented
- Last reviewed
- To be documented
DNS / CDN / WAF
To be documented- Purpose
- Domain resolution, content delivery, and web application firewall
- Data processed
- Request metadata (IP address, headers) required to route and protect traffic
- Location
- Global edge network — varies by provider
- Transfer mechanism
- Provider-specific terms apply
- Last reviewed
- To be documented
Messaging integrations
Customer configurable- Purpose
- Customer communication channels (e.g. WhatsApp Business)
- Data processed
- Message content and contact details for the conversations routed through the integration
- Location
- Provider-specific
- Transfer mechanism
- Provider-specific terms apply
- Last reviewed
- Reviewed per integration
CRM and third-party integrations
Customer configurable- Purpose
- Business systems a customer chooses to connect
- Data processed
- Depends entirely on the integration a customer selects and configures
- Location
- Depends on the integration selected
- Transfer mechanism
- Provider-specific terms apply
- Last reviewed
- Reviewed per integration
