Subprocessors
Last updated 5 August 2026
These are the third parties that may process customer data when you use Nsesa's managed cloud. Each is bound by contract to protect the data and process it only on our instructions. We will give customers advance notice before adding a new subprocessor that affects them.
Always used (managed cloud)
| Provider | Purpose | Data it receives | Can it be avoided? |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | All workspace data: accounts, documents, meetings, transcripts, chats | Yes — deploy against your own Supabase project or self-host |
| Anthropic (Claude) | AI chat answers and meeting analysis | Your question plus the document or transcript excerpts needed to answer it | Yes — local AI mode |
| Resend | Transactional email (invitations, action-item reminders) | Recipient name, email address, and task titles. No document content | No, unless email notifications are disabled |
Used only if you enable the relevant feature
| Provider | Purpose | Data it receives | Can it be avoided? |
|---|---|---|---|
| Groq | Speech-to-text for uploaded recordings; optional AI fallback if Claude is unavailable | Meeting audio; prompt content only if fallback is switched on | Yes — fallback is off by default and must be enabled by an administrator; transcription can run on a local Whisper server |
| Google (Workspace, Drive, Meet) | Directory import, document sync, meeting bot | Only the directory and files your administrator chooses to connect | Yes — do not connect the integration |
| Microsoft (Entra ID, OneDrive, SharePoint, Teams) | Directory import, document sync, meeting bot | Only the directory and files your administrator chooses to connect | Yes — do not connect the integration |
| Zoom | Meeting bot joins and records scheduled calls | Meeting audio for calls you schedule the bot into | Yes — do not schedule the bot |
What never leaves your infrastructure
Semantic indexing — the step that makes your documents searchable — always runs inside the application server itself using a local model. No document text is sent to an external service for indexing, in any deployment mode.
Avoiding subprocessors entirely
Nsesa can be deployed against a database your organisation owns, or fully on-premises with AI models running on your own hardware. In that configuration no document, transcript, or chat message reaches any third party — if the local model is unavailable the application returns an error rather than quietly falling back to a cloud provider. Ask us for the deployment guide.
Questions
Contact privacy@nsesa.space for our data processing agreement or a completed security questionnaire.