https://myphoneflow.com/legal/subprocessors/v1.0/
PhoneFlow Subprocessor List
Version 1.0 · Effective: 2026-09-27 · Last updated: 2026-09-26
Summary (not a substitute for the terms below):
- These are the outside companies that PhoneFlow uses to process our customers' call, message and account data.
- Most of them process data in the United States. The table shows where each one does.
- We email account administrators 30 days before adding a new subprocessor, and anyone can subscribe to those notices.
- Tools you connect yourself are your own choice, not PhoneFlow subprocessors. That includes CRMs, calendars, webhooks, custom tools and your own AI keys.
- The PhoneFlow Data Processing Addendum (https://myphoneflow.com/legal/dpa/) governs how these subprocessors are engaged, and your right to object.
1. What this list covers #
This list names the third parties that Electric Software LLC d/b/a PhoneFlow ("PhoneFlow") engages to process Customer Personal Data when it provides the Services. Customer Personal Data has the meaning given in the PhoneFlow Data Processing Addendum (https://myphoneflow.com/legal/dpa/) ("DPA"). Some of these providers also process PhoneFlow Account Data, which PhoneFlow controls under the PhoneFlow Privacy Notice (https://myphoneflow.com/legal/privacy/).
PhoneFlow engages each subprocessor under written terms, which may be the provider's standard business or data-processing terms. Providers reached through Twilio (Deepgram, and ElevenLabs for text-to-speech) are engaged by Twilio under Twilio's terms with PhoneFlow, and are marked "Twilio's subprocessor" in the table. PhoneFlow remains responsible for its subprocessors as the DPA provides.
2. Subprocessors #
| Name | Purpose | Data involved | Location |
|---|---|---|---|
| Twilio | Phone numbers and carrier services; inbound and outbound calls; call recording; voicemail; text messages; one-time verification codes; softphone, SIP and web-widget voice connections; real-time voice relay (ConversationRelay) | Calling and called numbers, live call audio, call recordings, voicemail audio, text-message content, verification codes, call metadata | United States |
| Deepgram (Twilio's subprocessor, through Twilio ConversationRelay) | Speech-to-text during live calls and widget sessions | Caller speech audio. Staff directory names are sent as recognition hints | United States |
| ElevenLabs (Twilio's subprocessor for text-to-speech through Twilio ConversationRelay; engaged directly by PhoneFlow through the ElevenLabs API for voice previews and the older agent feature) | Text-to-speech for the AI agent's replies. Voice previews in the dashboard. The older ElevenLabs-hosted agent feature | The AI agent's reply text, including anything it reads back to a Caller. Preview text. For the older agent feature, agent configuration and knowledge-base documents | United States or other locations where the provider operates |
| OpenAI | Default large language model for live conversations; post-call summaries, classification and field extraction; voicemail transcription; knowledge-base embeddings; business research during setup | Live transcripts, agent instructions, knowledge-base excerpts, directory contacts, Caller phone numbers and details, integration results returned during calls, voicemail audio, knowledge-base text, business details entered during setup | United States |
| Anthropic | Optional large language model, when Customer's agent is set to use it; classification and summaries | The same kinds of data as OpenAI, for agents that use Anthropic | United States |
| Supabase | Application database, user authentication, server functions, file storage, knowledge-base search | All Customer Personal Data stored by the Services, and PhoneFlow Account Data | United States |
| Amazon Web Services | Real-time call relay (Amazon ECS); managed secrets; operational logs (Amazon CloudWatch); email delivery (Amazon SES) | Live conversation text and agent instructions handled by the relay; operational logs that may include fragments of Caller speech; email recipients' addresses and email content, including transcripts, summaries and recording attachments that Customer chose to send | United States (us-east-2, Ohio) |
| Stripe | Payment processing for Wallet purchases, Auto-Pay and invoices | Mainly PhoneFlow Account Data: billing contact name and email, organization name, account identifiers, payment method details | United States |
| Cloudflare | Hosting and delivery of the PhoneFlow web application; content delivery; optional bot protection for the web widget (Turnstile) | Visitor IP addresses and request data; bot-check tokens | Global (edge network) |
| Address geocoding and place lookup for service-area checks and setup | Caller and service addresses, business names and ZIP codes | United States | |
| Hunter.io | Business research during agent setup | Customer's company name and domain; business contact details that Hunter returns for that domain | European Union, United States or other locations where the provider operates |
| OpenStreetMap (Nominatim address lookup and map tiles) | Address lookup and maps in the service-area tools | Addresses that Customer Users type into the service-area tools; the user's IP address when map tiles load | Locations where the provider operates, which may be outside the United States |
| ipify | Looks up a Customer User's public IP address for the account audit log | The Customer User's browser IP address | Locations where the provider operates, which may be outside the United States |
| jsDelivr | Delivers the Twilio Voice software library on the web-widget test page | The visitor's IP address and request data | Global (content delivery network) |
3. What is not on this list #
Customer sets up the following. They are Customer's own disclosures, made on Customer's instruction (DPA Section 9.6), and are not PhoneFlow subprocessors:
- Integrations, webhooks and custom HTTP tools that Customer configures, for example CRMs, practice-management and ticketing systems, and booking tools.
- Microsoft 365 / Google Workspace calendar integrations that Customer connects to its own Microsoft or Google account, for staff availability and meeting booking.
- Customer's own AI-provider API key, where Customer's agent is set to use one instead of PhoneFlow's.
- The people and addresses Customer designates to receive call summaries, recordings, emails and text messages.
- The carriers that complete calls and texts beyond Twilio. Twilio and those carriers may also process some telecommunications data as independent controllers under their own legal duties.
4. Changes and how to be notified #
- New subprocessors. PhoneFlow gives at least 30 days' notice before a new subprocessor begins processing Customer Personal Data. The notice is emailed to Customer's account administrators and added to the change log below. Customers may object as DPA Section 9.4 describes. Urgent replacements follow DPA Section 9.5.
- Other updates. Removals, and corrections to a purpose, data or location description that do not widen what a subprocessor does, are posted to the change log without advance notice.
- Subscribe. Anyone can get change notices by email. Write to [email protected] with "Subscribe: subprocessors" in the subject line. To stop, write with "Unsubscribe: subprocessors" in the subject line.
- Versions. This list has its own version number. Earlier versions stay available at their version URL, for example https://myphoneflow.com/legal/subprocessors/v1.0/.
5. Change log #
| Date | Version | Change |
|---|---|---|
| 2026-09-27 | 1.0 | First published list. |
