Last updated · May 19, 2026

Subprocessors

These are the categories of third-party service providers that may process data on Channl’s behalf to operate the Service. The current named list — including vendor, processing location, contract dates, and links to each vendor’s DPA — is available to customers and prospective customers under non-disclosure agreement. Material changes to the list (a new category or a new vendor in an existing category) are announced at least 30 days before they take effect. Subscribe to notifications at security@channl.ai.

Every sub-processor is bound by a written Data Processing Addendum requiring (a) processing only on Channl’s documented instructions, (b) confidentiality, (c) appropriate technical and organizational security measures, (d) assistance with data-subject-rights and incident response, and (e) SOC 2 Type 2 attestation, ISO 27001, or equivalent security-program documentation appropriate to the data they process.

CategoryPurposeData processed
Cloud hosting and edge networkApplication hosting, content delivery, function runtime, log aggregationHTTP request metadata, application logs, client IP at the edge
Managed databasesRelational, document, vector, and graph storage for product data and Customer DataCustomer Data, account records, audit logs
Caching, rate limiting, and queuesEphemeral state, rate-limit counters, and background job dispatchSession and request metadata; no Customer Data at rest beyond TTL windows
AI / large language model providersGenerative-AI features (research, drafting, scoring, summarization, classification, search)Prompts and inputs required to deliver the requested feature; no training on Customer Data
Embedding providersVector embeddings for retrieval and semantic searchText and metadata being embedded
Error and exception monitoringServer and client error tracking and performance monitoringStack traces and scrubbed request metadata; PII removed before transmission
Product and performance analyticsAggregated usage and performance measurement (reverse-proxied)Event payloads, distinct ID, session ID; PII fields explicitly excluded
Uptime and availability monitoringSynthetic health checks against public endpointsResponse codes and latencies; no request payloads
Internal alerting and notificationsInternal alerts to Channl personnel (e.g., new lead submissions)Lead email, role, and company rendered as an internal message
Payment processingSubscription billing and invoicingBilling contact, card brand, last four digits, expiration, and payment-method tokens
Transactional email deliveryAccount, security, and billing emailsRecipient email address and message body
Newsletter deliveryOpt-in marketing newsletter for Channl-published contentSubscriber email and open/click events
Customer-authorized email integrationsOAuth-based access to a customer-authorized email account where you connect oneTokens and message data the customer authorizes, scoped to the integration
Event registration platformEvent sign-ups embedded on the marketing siteData the visitor submits inside the embed; separately governed by that vendor
Public-data collection infrastructureRetrieval of publicly available information used by research featuresPublic-source URLs and content; no submitted credentials

Production data is processed and stored in the United States. Where personal data subject to GDPR, UK GDPR, or the Swiss FADP is transferred to a third country that has not received an adequacy determination, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss FDPIC-approved variant, supplemented by encryption, access controls, and pseudonymization where appropriate.

← Back to security