Plain-English summary (non-binding). These are the third-party services we use to run Chantro — cloud infrastructure, AI model providers, email delivery, error monitoring, and customer-authorized integrations. Each provider is bound by a written agreement that requires them to protect Customer Data.
1. Overview
A subprocessor is a third-party service provider that processes Personal Data on Chantro's behalf to help us deliver the Service. This page lists the subprocessors engaged by SmartTech ProServe LLC, the purpose of each engagement, the categories of data each provider receives, and the region in which processing takes place. It supplements our Privacy Policy and Data Processing Addendum.
We enter into written contracts with each subprocessor that impose data-protection obligations substantially similar to those we owe Customers under the DPA. We also perform pre-engagement vendor reviews and re-review material vendors at least annually.
2. Infrastructure & hosting
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Primary cloud infrastructure — compute (ECS/Fargate), managed database (RDS for PostgreSQL), managed Redis (ElastiCache), application load balancing, DNS (Route 53), and networking. Additional AWS-managed services (for example, CloudFront CDN and AWS WAF) may be introduced as part of ongoing production hardening. | All Customer Data, Personal Data, operational logs, backups. | United States (us-east-1 primary). |
3. Storage & secrets
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| AWS S3 & KMS | Object storage for uploads, exports, and backups (S3). Envelope encryption of data keys (KMS). | Uploaded documents, photos, exports, encrypted secrets. | United States. |
4. Email & messaging
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Amazon Simple Email Service (SES) | Outbound transactional email (sign-in, invitations, proposals, billing, product notices). | Recipient email address, display name, message content and metadata. | United States. |
5. AI model providers
We route AI requests to the provider best suited to each task. Provider selection is summarized in our AI Transparency Statement. We configure each provider's API to prohibit training on Customer inputs and outputs where that provider's tier supports such controls, and we negotiate stronger commitments (for example, zero-retention or enterprise terms) as we move providers onto paid/enterprise tiers.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Anthropic, PBC | Large-language-model inference for the conversational assistant, summarization, and related AI features. | Prompts, task context, and workspace content needed to answer the request; AI Output returned. | United States (API endpoints). |
| OpenAI, LLC | Large-language-model inference and, where enabled, text-to-speech for voice mode. | Prompts, task context, and workspace content needed to answer the request; AI Output returned. | United States (API endpoints). |
| Google LLC (Generative AI APIs) | Optional model provider for multimodal tasks and text-to-speech. | Prompts, task context, and content needed to perform the request; audio synthesized. | United States. |
6. Voice (speech-to-text / text-to-speech)
Voice providers operate only when a User actively starts a voice-mode session. Audio is streamed to the provider, transcribed, and the transcript is stored within the User's workspace.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Deepgram, Inc. | Speech-to-text transcription for the Chantro voice assistant. | Audio streams captured during voice-mode sessions; text transcripts. | United States. |
7. Customer-authorized integrations
Customer-authorized integrations exchange data with third parties only after a Workspace administrator explicitly connects them. The User is instructing Chantro to share data on their behalf for the specific integration they enable.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Google LLC (Google Workspace APIs) | Customer-authorized integration with Gmail and Calendar for the Chantro calendar and email workflows. | OAuth tokens, calendar events, and email metadata/content that the User has granted Chantro permission to read or write. | Google-operated infrastructure worldwide; EU-to-non-EU transfers covered by Google's DPA and SCCs as referenced in the Chantro DPA. |
8. Security & observability
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Application error monitoring, crash reporting, and performance traces. | Error messages, stack traces, session identifiers, sanitized request metadata. We do not intentionally send workspace content. | United States. |
| Cloudflare, Inc. | Bot and abuse protection on the marketing website (Turnstile CAPTCHA) and edge DDoS protection where applicable. | IP address, visitor signals required to score traffic. | Global edge, Customer may be routed to the nearest PoP. |
9. Product & website analytics
Chantro's product analytics are first-party by default. When we enable a third-party web analytics provider (for example, on the public marketing site), we will update this section and our Cookie Policy.
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Chantro first-party product analytics | Core feature usage metrics, error rates, and performance measured within the product. | Aggregated usage events and device metadata; identifiers pseudonymized where possible. | United States (AWS). |
10. Support & operations
| Provider | Purpose | Data categories | Region |
|---|---|---|---|
| Google Workspace (internal Chantro use) | Corporate email, documents, and meetings used by Chantro staff to operate the business and deliver support. | Business contact details, support correspondence. | United States. |
11. Notifications about changes
We update this page when we engage a new subprocessor or replace an existing one. Customers subject to our DPA may subscribe to advance-notice emails for subprocessor changes by writing to privacy@chantro.com. We will give at least thirty (30) days' notice before a new subprocessor begins processing Customer Data, except in emergencies or where a change is needed to maintain the security or availability of the Service.
12. Contact
Questions, objections, or notification subscriptions: privacy@chantro.com.