Subprocessors
Last updated: June 18, 2026
KlicForge engages the third-party service providers ("subprocessors") listed below to help deliver our services. This list is maintained as part of our Data Processing Addendum and is designed to support transparency under GDPR, CCPA/CPRA, and Singapore PDPA.
Active subprocessors
| Provider | Purpose | Region | DPA | Status |
|---|---|---|---|---|
| DigitalOcean Cloud infrastructure | Application compute, managed PostgreSQL database, managed Valkey/Redis cache, and automated database backups. | Singapore (sgp1) | Yes | Active |
| Cloudflare Edge network / storage / security | AI Gateway (LLM request routing), R2 object storage (knowledge files, uploads), Turnstile (bot mitigation), CDN/TLS, and Pages hosting for the dashboard. | Global edge network, United States | Yes | Active |
| Stripe Payments / billing | Subscription billing, payment processing, and invoicing. | United States, Global | Yes | Active |
| OpenAI LLM provider / voice transcription | Voice-note transcription (Whisper API) and large-language-model inference for agent responses, structured output, and tool use when an OpenAI model is selected. | United States | Yes | Active |
| Anthropic Downstream LLM provider (via OpenRouter) | Large-language-model inference (Claude family) when an Anthropic model is selected. KlicForge has no direct Anthropic account — requests are routed through OpenRouter / Cloudflare AI Gateway. | United States | — | Active |
| Google (Gemini / Workspace) OAuth / productivity integration; Gemini LLM downstream via OpenRouter | Google OAuth sign-in and optional Google Workspace / Drive MCP integrations (direct). Gemini model inference is reached via OpenRouter — KlicForge holds no direct Gemini API account. | United States, Global | Yes | Active |
| OpenRouter LLM aggregator | Routing layer aggregating multiple LLM providers (used for forge model tiers and intent classification). | United States, Global | Yes | Active |
| Resend Transactional email | Delivery of transactional and notification emails (verification, alerts, operator notifications). | United States | Yes | Active |
| GitHub CI/CD / source / secrets / registry | Source control, CI/CD pipelines, encrypted deployment secrets, and container image registry (GHCR). | United States | Yes | Active |
| Sentry (Functional Software, Inc.) Error monitoring | Application error and exception monitoring for the API service. General log aggregation remains on the hosting platform (DigitalOcean App Platform). | United States | Yes | Active |
| Meta Platforms (WhatsApp Business Cloud API) Messaging channel (tenant-connected) | Delivery and receipt of WhatsApp messages for agents whose workspace connects a WhatsApp Business account. Only active for tenants that enable the WhatsApp channel. | United States, Global | Yes | Active |
| Telegram Messenger Inc. Messaging channel (tenant-connected) | Delivery and receipt of Telegram messages for agents whose workspace connects a Telegram bot. Only active for tenants that enable the Telegram channel. | United Arab Emirates, Global | — | Active |
Planned & inactive
| Provider | Purpose | Region | DPA | Status |
|---|---|---|---|---|
| Analytics provider Product analytics | Planned product/usage analytics. No third-party analytics processor is currently integrated. | TBD | — | Planned |
AI model providers.When an agent uses an AI model, prompts, messages, files, and tool outputs included in the agent's context are sent to the selected model provider for processing. KlicForge does not use customer data to train models. Each provider's handling of data depends on the selected model and that provider's policies — see the links above. OpenRouter's Zero Data Retention (ZDR) setting is enabled on our account, which restricts routing to providers/model endpoints that don't retain or train on request data.
To request advance notice of changes to this list, contact privacy@klicforge.ai.