Legal
Sub-processors
The third parties we rely on to run FluxDM, what each one handles, and where it sits. We keep this list current as part of shipping changes, not as a periodic review.
Last updated 1 September 2026
How to read this list
Some of these are used for every workspace. Others only apply if you connect the channel in question — if you never connect TikTok, TikTok never receives anything from us. The channel rows are there so you can see exactly what connecting a channel implies before you do it.
Where a row says a provider receives message content, that is because delivering a message on their platform means handing them the message. That is the nature of the channel, not a choice we make on top of it.
The Google Workspace and Microsoft mailbox rows are published before inbox access is enabled. They do not mean either provider connection is available today. If a workspace never connects one of them, that provider receives no mailbox data from FluxDM. Sending and inbox access also need separate admin consent.
The task and contact integration rows are also published before their release flags are enabled. A listed provider receives nothing unless a workspace admin connects it and selects a sync scope. A disabled or incomplete provider stays unavailable in the product.
Current sub-processors
| Sub-processor | What it does | Data involved | Where |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, PostgreSQL database, Redis | All workspace data, including conversation content | Germany (EU) |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, TLS termination, media storage (R2) | Traffic metadata, IP addresses, uploaded media attachments | Global edge network |
| Meta Platforms, Inc. | Sending and receiving messages on WhatsApp Business, Instagram and Messenger | Message content, platform account identifiers, attachments | United States and global |
| Telegram Messenger Inc. | Sending and receiving Telegram messages via the Bot API | Message content, Telegram user and chat identifiers | Global |
| TikTok Pte. Ltd. | Sending and receiving TikTok business messages | Message content, TikTok account identifiers | Global |
| X Corp. | Sending and receiving direct messages on X | Message content, X account identifiers | United States and global |
| Twilio Inc. | Sending and receiving SMS | Message content, phone numbers | United States and global |
| Resend (Plus Five Five, Inc.) | Outbound transactional email (invitations, notifications) and inbound email ingestion | Email addresses, email subject and body content | United States |
| Google LLC | Google sign-in (OAuth) for account authentication | Name, email address, Google account identifier | United States and global |
| Google Firebase Cloud Messaging | Push notifications to the FluxDM mobile apps | Device push tokens, notification title and preview text | United States and global |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact details and payment method. Card details are handled by Stripe and never reach FluxDM systems. | United States and global |
| Reprobox | Frontend error and incident diagnostics for the web application (bug reports and captured browser errors) | Staff (workspace member) role and workspace identifier, browser error and diagnostic metadata, and network request metadata. Excludes end-customer message content, which is never captured. | Germany (EU) |
| Google LLC (Gmail API and Google Cloud Pub/Sub) | Only when a workspace admin connects it: sending email from the authenticated primary Gmail mailbox and, under a separate optional grant, syncing new Inbox email into FluxDM | Primary mailbox address and outbound email content for sending. For optional inbox sync: new email headers, body content, attachments and provider identifiers from the connection time, plus watch and sync metadata. No old mailbox history. | United States and global |
| Microsoft Corporation (Microsoft Graph) | Only when a workspace admin connects it: sending email from the authenticated primary Outlook mailbox and, under a separate optional grant, syncing new Inbox email into FluxDM | Primary mailbox address and outbound email content for sending. For optional inbox sync: new email headers, body content, attachments and provider identifiers from the connection time, plus subscription and sync metadata. No old mailbox history. | United States and global |
| Google LLC (Gemini API) | AI processing of conversation content — generating bot answers, reply drafts, conversation summaries, automated follow-ups and voice-note transcriptions | The conversation content an enabled AI feature operates on (customer message text and thread context) and voice-note audio when transcription is used. Sent only for workspaces that use an AI feature. No sign-in identifiers, billing details, credentials or push tokens are sent for this purpose. | United States and global |
| Trello (Atlassian Pty Ltd) | Two-way task synchronisation — pushing a conversation task to a connected Trello board and reading its status back | A task's title and its status only (the status becomes the board list the card sits in). No message content, internal notes, customer identifiers or attachments are ever sent to Trello. | United States and global |
| Salesforce, Inc. | Only when a workspace admin connects it and enables Contact Change Data Capture: synchronising Salesforce Contacts | Contact name, email, phone, Salesforce Contact id and durable Pub/Sub replay id. No company or Account mapping. No cases, tasks, message content, internal notes or raw CDC payloads. | United States and global |
| Xero Limited | Only when a workspace admin connects it: synchronising Contacts for the selected Xero organisation | Contact name, email and phone plus stable provider identifiers. No invoices, payments, tax records, message content or internal notes. | New Zealand, Australia, United States and global |
| Klaviyo, Inc. | Only when a workspace admin connects it: synchronising customer profiles without changing marketing consent | Customer name, email, phone, company and FluxDM tags. No subscription status, list enrolment, campaign, flow, message content or internal notes. | United States and global |
| Intuit Mailchimp | Only when a workspace admin connects it and selects an audience: synchronising audience members without changing marketing consent | Customer name, email, phone and FluxDM tags. Missing members are created as transactional only. No campaign, message content, internal notes or marketing opt-in is sent. | United States and global |
| Intuit Inc. (QuickBooks Online) | Only when a workspace admin connects it: synchronising QuickBooks Customers with FluxDM customers | Customer name, email, phone and company. No invoices, payments, tax data, accounting transactions, message content or internal notes. | United States and global |
| Google LLC (Google Calendar and Google Meet) | Only when a member connects it: creating and managing confirmed customer meetings on that member's primary calendar | Confirmed event title, start and end time, time zone, a stable event id and, only when explicitly supplied, the attendee email address. No message content, transcript, internal notes, attachments or raw provider payload. | United States and global |
| Microsoft Corporation (Outlook Calendar and Microsoft Teams) | Only when a member connects it: creating and managing confirmed customer meetings, with a Teams join link, on that member's own Outlook calendar | Confirmed event title, start and end time, time zone, a stable event id and, only when explicitly supplied, the attendee email address. No message content, transcript, internal notes, attachments or raw provider payload. | United States, European Union and global |
| Calendly LLC | Only when a workspace admin connects it: syncing Calendly invitees and appointments that were already booked or cancelled in Calendly | Invitee name and email, appointment start and end time, time zone, status, join URL or location, and stable provider identifiers. No booking answers, description, message content, transcript, internal notes or raw provider payload. | United States and global |
| Cal.com, Inc. | Only when a workspace admin connects it: syncing attendees and appointments already booked, rescheduled or cancelled in Cal.com | Attendee name and email, appointment start and end time, time zone, status, join URL or location, and stable provider identifiers. No booking answers, description, message content, transcript, internal notes, ICS attachment or raw provider payload. | United States and global |
| monday.com Ltd. | Two-way task synchronisation with a connected monday.com board | A task's title and status only. No message content, internal notes, customer identifiers or attachments. | United States, European Union and global |
| ClickUp (Mango Technologies, Inc.) | Two-way task synchronisation with a connected ClickUp list | A task's title and status only. No message content, internal notes, customer identifiers or attachments. | United States and global |
| Notion Labs, Inc. | Two-way task synchronisation with a connected Notion database | A task's title and status only. No message content, internal notes, customer identifiers or attachments. | United States and global |
| Atlassian (Atlassian Pty Ltd) | Two-way task synchronisation with a connected Jira Cloud project | A task's title and status only. No message content, internal notes, customer identifiers or attachments. | United States and global |
| Asana, Inc. | Two-way task synchronisation with a connected Asana project | A task's title and status only. No message content, internal notes, customer identifiers or attachments. | United States and global |
| Airtable (Formagrid, Inc.) | Two-way task synchronisation with a connected Airtable base | A task's title and status only. No message content, internal notes, customer identifiers or attachments. | United States and global |
| Basecamp (37signals LLC) | Two-way task synchronisation with a selected Basecamp project and to-do list | Task title, completion status and a stable FluxDM task id pointer used only to make create retries idempotent. No message content, internal notes or attachments. | United States and global |
| Linear Orbit, Inc. | Two-way task synchronisation with issues in a connected Linear team | Task title, status and a stable FluxDM task id pointer used only to make create retries idempotent. No message content, internal notes, customer identifiers or attachments. | United States and global |
| HubSpot, Inc. | Two-way contact and task synchronisation with a connected HubSpot account | Customer name, email address, phone number and company when contact sync is enabled; task title and status when task sync is enabled. No message content, internal notes or attachments. | United States and global |
| Zoho Corporation | Only when a workspace admin connects it: two-way contact synchronisation with Zoho CRM | Customer name, email address and phone number. FluxDM also stores provider contact identifiers and notification verification metadata. Poll cursors and completion state stay in FluxDM's shared integration state, not the provider credential bundle. No message content, transcript, internal notes, attachments or raw provider payload. | United States, European Union, India and global regional data centres |
| Pipedrive OÜ | Two-way contact synchronisation with a connected Pipedrive account | Customer name, email address and phone number. No message content, internal notes, invitee answers, transcripts, attachments or raw provider payloads. | European Union, United States and global |
Where your data lives
The FluxDM application, its database and its cache run on infrastructure in Germany. Your conversation history sits in the EU. The channel providers above are separate — a WhatsApp message travels through Meta’s infrastructure wherever that sits, because that is how WhatsApp works.
FluxDM is operated by a US company, so administrative access to that EU infrastructure comes from the United States. If that matters to your assessment, say so and we will put it in writing rather than leaving you to infer it.
Changes to this list
We will give notice before adding a sub-processor that handles conversation content. If you have a data processing agreement with us, the notice period and your right to object are set out there.
- To be told when this page changes, email [email protected] and ask to be added to sub-processor notifications.
- Connecting a new channel inside your workspace adds that platform’s provider to the list of parties handling your data. That is your action, not ours, so it happens without separate notice.
Questions about anything on this page? [email protected].