Subprocessors
Last updated: August 11, 2026
KlicForge engages the third-party service providers ("subprocessors") listed below to help deliver our services. This list is maintained as part of our Data Processing Addendum and is designed to support transparency under GDPR, CCPA/CPRA, and Singapore PDPA.
Active subprocessors
| Provider | Purpose | Region | DPA | Status |
|---|---|---|---|---|
| DigitalOcean Cloud infrastructure | Application compute, managed PostgreSQL database, managed Valkey/Redis cache, scheduled maintenance jobs, and automated database backups. | Singapore (sgp1) App region sgp1 (Singapore); managed database and cache clusters inherit the app region. | Yes | Active |
| Cloudflare Edge network / AI inference / storage / security | AI Gateway (request routing for Workers AI models), Workers AI (model inference and text embeddings), Vectorize (per-tenant knowledge vector index), R2 object storage (knowledge files, uploads), Turnstile (bot mitigation), CDN/TLS, and Pages hosting for the dashboard and the klicforge-inbox operator PWA. A second Turnstile widget also runs on the public end-user chat widget, distinct from the auth-form widget. | Global edge network, United States R2 buckets use provider-managed placement (region 'auto'); Vectorize indexes are provider-managed/global. Object and index jurisdiction is not pinned to Singapore. | Yes | Active |
| Stripe Payments / billing | Subscription billing, payment processing, and invoicing. | United States, Global | Yes | Active |
| OpenAI Voice transcription and image generation (direct API); LLM downstream via OpenRouter | Voice-note transcription (Whisper API) via a direct OpenAI account, used only for agents with voice notes enabled. OpenAI chat models available in the KlicForge catalog (e.g. gpt-4o-mini) are reached via OpenRouter, not this direct account. Also reachable directly for image generation (dall-e-3 / gpt-image-1) for agents with the image-generation skill enabled and OpenAI selected as the image provider. Optional — only active when your workspace enables this feature. | United States | Yes | Active |
| Firecrawl Web crawling (tenant-triggered) | Crawls and extracts content from tenant-chosen public URLs for Website Knowledge Import, so a workspace can turn its own website into agent knowledge without hand-uploading documents. Optional — only active when your workspace enables this feature. | United States | — | Active |
| Google (Gemini / Workspace) OAuth / productivity integration; Gemini LLM downstream via OpenRouter | Google OAuth sign-in and optional Google Workspace / Drive MCP integrations (direct). Gemini model inference is reached via OpenRouter — KlicForge holds no direct Gemini API account. Image generation for agents with the image-generation skill enabled routes directly to Google's Vertex AI (Imagen), a separate direct integration. Optional — only active when your workspace enables this feature. | United States, Global | Yes | Active |
| OpenRouter LLM aggregator | Routing layer aggregating multiple LLM providers. Carries all KlicForge platform model tiers and internal AI subtasks (intent classification, summarisation, vision, generation). | United States, Global | Yes | Active |
| Resend Transactional email | Delivery of transactional and notification emails (verification, alerts, operator notifications, privacy-request exports). | United States | Yes | Active |
| GitHub CI/CD / source / secrets / registry | Source control, CI/CD pipelines, encrypted deployment secrets, and container image registry (GHCR). | United States | Yes | Active |
| PostHog, Inc. Product analytics | Product and usage analytics for the marketing site and dashboard, and exception capture for the API and the embedded widget. Used to understand feature usage and to diagnose errors. | United States | Yes | Active |
| Sentry (Functional Software, Inc.) Error monitoring | Application error and exception monitoring for the API service. General log aggregation remains on the hosting platform (DigitalOcean App Platform). | United States | Yes | Active |
| Meta Platforms (WhatsApp Business Cloud API) Messaging channel (tenant-connected) | Two uses: (1) delivery of one-time-passcode verification messages via a KlicForge-owned WhatsApp Business number, sent on behalf of every tenant that has WhatsApp OTP enabled (tenants.whatsapp_otp_enabled defaults TRUE — this use is platform-level, not opt-in); (2) delivery and receipt of WhatsApp messages for agents whose workspace connects its own WhatsApp Business account, which remains tenant opt-in. | United States, Global | Yes | Active |
| Telegram Messenger Inc. Messaging channel (tenant-connected) | Delivery and receipt of Telegram messages for agents whose workspace connects a Telegram bot. Only active for tenants that enable the Telegram channel. Optional — only active when your workspace enables this feature. | United Arab Emirates, Global | — | Active |
| Slack Technologies (Salesforce) Operator notifications (tenant-connected) | Outbound operator notifications for workspaces that connect a Slack bot token. Only active for tenants that enable the Slack notification channel. Optional — only active when your workspace enables this feature. | United States, Global | Yes | Active |
| DocuWare Document management integration (tenant-connected) | Document search and retrieval for workspaces that connect their own DocuWare cloud account. Only active for tenants that enable the DocuWare integration. Optional — only active when your workspace enables this feature. | Germany, United States | Yes | Active |
| Browser push services (Google FCM / Mozilla / Apple) Web push delivery | Delivery of operator web-push notifications to subscribed browsers. The delivery endpoint is chosen by the subscriber's browser vendor. Optional — only active when your workspace enables this feature. | Global | — | Active |
| Brave Search Web search (skill) | Web search for agents with the research skill enabled. Optional — only active when your workspace enables this feature. | United States | — | Active |
| Open-Meteo Weather data (skill) | Weather and geocoding lookups for agents with the weather skill enabled. Optional — only active when your workspace enables this feature. | European Union, Global | — | Active |
| WeatherAPI.com Weather data (skill) | Weather lookups for agents with the premium weather skill enabled. Optional — only active when your workspace enables this feature. | United Kingdom, Global | — | Active |
| Google Fonts Font delivery (CDN) | Webfont delivery for the KlicForge dashboard. | United States, Global | — | Active |
| unpkg (npm CDN) Widget SDK delivery (CDN) | CDN delivery of the embeddable widget script for sites that install the widget via the CDN snippet rather than the npm package. Optional — only active when your workspace enables this feature. | United States, Global | — | Active |
Planned & inactive
| Provider | Purpose | Region | DPA | Status |
|---|---|---|---|---|
| Anthropic LLM provider (not currently in use) | Not currently in the production path — no Anthropic model is in the KlicForge model catalog. Anthropic models are only reachable if a workspace registers its own bring-your-own-key model via OpenRouter, in which case the provider relationship is the workspace's own. Optional — only active when your workspace enables this feature. | United States | — | Disabled |
AI model providers.When an agent uses an AI model, prompts, messages, files, and tool outputs included in the agent's context are sent to the selected model provider for processing. KlicForge does not use customer data to train models. Each provider's handling of data depends on the selected model and that provider's policies — see the links above. OpenRouter's Zero Data Retention (ZDR) setting is enabled on our account, which restricts routing to providers/model endpoints that don't retain or train on request data.
To request advance notice of changes to this list, contact [email protected].