Skip to content
InstagramWhatsAppMessengerTikTokMyndchat AI
By business typefor Creatorsfor eCommercefor SM Marketersfor Agenciesfor Brands
By use caseCollect EmailsRequest to FollowRespond to CommentsFollow to DM
AboutPricingSecurity
en
  • InstagramAutomate your Instagram marketingWhatsAppConnect with your customers instantlyMessengerAutomated replies on Facebook MessengerTikTokTurn views into salesMyndchat AIA smarter way to automate chat
  • By business type
    for Creatorsfor eCommercefor SM Marketersfor Agenciesfor Brands
    By use case
    Collect EmailsRequest to FollowRespond to CommentsFollow to DM
  • About
  • Pricing
  • Security
Terms of ServicePrivacy PolicyData Processing AddendumSubprocessor ListCookie PolicyAcceptable Use PolicyRefund Policy
Verified on: 19 August 2026

Myndchat Subprocessors

A subprocessor is a provider that carries out part of our service and, in doing so, processes personal data on our behalf or on behalf of our customers. This page lists all of them, with each one's exact role, what it receives and where it processes.

It is versioned on purpose. A customer who approved Myndchat against a list of providers must be able to check, later, what changed and when — not discover a new provider by accident.

  • who already processes data today, and who does not process anything yet;
  • which data each one receives, rather than just the company's name;
  • in which country each one processes, and under which international transfer mechanism;
  • which functions have no provider chosen yet — because the gap is information too.

This list separates who already processes data from who does not yet. The Myndchat platform is under construction as of this date, and only the website is live. Publishing all thirteen providers as a single list, as though all of them were already operating, would declare processing that does not exist. That is why the list is split by state rather than alphabetically.

This page forms part of the Data Processing Addendum. The prior-notice obligations, the right to object and its consequences are written there, in section 8, and are not repeated here.

Contents

  1. 1. How to read this list
  2. 2. In use today
  3. 3. Planned for the platform
  4. 4. Functions with no provider chosen
  5. 5. International transfers
  6. 6. How we announce a change
  7. 7. What is not a subprocessor of ours
  8. 8. Version history
  9. 9. Contact

1. How to read this list

Each provider appears once, in the section matching its state. The three states are:

StateWhat it meansWhere it appears
In useThe provider processes personal data right nowSection 2
PlannedThe provider has been chosen and engaged for a platform function, but processes nothing yet, because the function is not liveSection 3
No providerThe function is required by the product specification and processes personal data, but no provider has been chosen yetSection 4

A provider moves from Planned to In use the moment its function goes live. That move is a change to this list and follows the notice procedure in section 6 — it does not happen quietly just because the name was already on the page.

The data category column describes what that provider actually receives, not everything Myndchat processes. A billing provider does not see conversations; a channel provider does not see card data.

The date at the top of this page is the date on which every row was verified, one by one. It is not the date of the last wording change.

2. In use today

One provider. Today Myndchat operates only the website, and the only third party processing personal data is the one hosting and delivering the pages. No third-party script is loaded in your browser — that was measured, and the measurement is described in the Cookie Policy.

ProviderExact role in the productData category receivedCountry of processingTransfer mechanism
VercelHosting, delivery of the website's pages and execution of scheduled tasksRequest data: IP address, browser headers and the in-transit content of the pages servedOutside BrazilStandard contractual clauses

Hosting is subprocessing even when the visitor cannot tell: whoever serves the page sees the IP address that asked for it. That is why the row exists, even though the browser contacts no third-party host.

The two cookies the site sets are first-party and pass through no provider at all. The Cookie Policy describes both, with what they store and for how long.

3. Planned for the platform

These providers have been chosen for platform functions and do not process any data yet, because the platform is not live. Each begins processing when its function goes into operation and a customer uses it.

ProviderExact role in the productData category receivedCountry of processingTransfer mechanism
SupabaseDatabase, authentication, media storage, realtime and similarity searchPractically all of the customer's account data and their end contacts' dataTo be determined before the platform goes liveAdequacy decision or standard contractual clauses, depending on the region chosen
StripeSubscription billing and payment processingName, e-mail, tax number, billing address and card data, the latter collected directly by their component without passing through our serversUnited States and other locations of the groupStandard contractual clauses
Meta PlatformsWhatsApp Business Platform, Instagram Direct and Facebook Messenger channelsMessage content, phone number, end contact identifier and profile, mediaUnited States and globalStandard contractual clauses plus the data protection addendum incorporated into the technology provider terms
TikTokTikTok direct message channelMessage content and end contact identifierGlobalStandard contractual clauses
AnthropicReply generation, summarisation and translation in the artificial intelligence layerThe conversation slice described in section 14 of the Data Processing AddendumUnited StatesStandard contractual clauses, with a contractual obligation not to train models on the content and to delete it within 30 days
OpenAIConversion of text into a numeric representation for similarity searchText of the questions and answers registered by the customer and of the indexed conversationsUnited StatesStandard contractual clauses, with no use for training and abuse-monitoring records kept for up to 30 days
GoogleAssisted address completion in the platform's formsThe text typed into the address field and the IP addressUnited States and globalStandard contractual clauses
Google AnalyticsAudience measurement for the websiteMeasurement identifier, IP address and browsing dataUnited States and globalStandard contractual clauses. Only loads after consent in the Analytics category
SentryError capture with already-filtered contextRoute, correlation identifier and a slice of screen state, with no message contentTo be determined along with the database regionTo be confirmed with the region

Two rows say the country is to be determined, and that is deliberate. The country of processing determines which mechanism in article 33 of the LGPD applies, and writing down a country that has not been chosen would also make the mechanism stated beside it false. Both rows are closed before the platform goes live, and closing them moves this page to a new version.

Google Analytics is on this list and is not in use. It is the only entry in this section that concerns the website rather than the platform, and even so it does not load: the Analytics category in the privacy panel starts switched off and today has no service attached to it. It appears here because the decision to adopt it has already been taken, and whoever reads this page has a right to know that in advance.

Each of these providers is bound by contract to data protection obligations no less stringent than those in the Data Processing Addendum, limited to the function it performs. Myndchat is answerable to the customer for their acts as if they were its own.

4. Functions with no provider chosen

Three functions required by the platform specification process personal data and have no provider decided yet. They appear here because the gap is relevant information for anyone evaluating Myndchat: these are three names that will come onto this page.

FunctionWhich data it will processWhen it arrives
Transactional e-mail: account verification, password recovery, team invitations and notificationsName and e-mail address of the customer's userBefore the platform opens for sign-up
Rate limit counting per IP address, user, organisation and routeIP address and account identifiersBefore the platform opens for sign-up
Verifying that the visitor is not a bot, at sign-up, sign-in and account recoveryIP address and browser signalsBefore the platform opens for sign-up

Declaring the gap is more useful than hiding the function. A customer who approves providers one by one needs to know that these three decisions are still to come, so as not to discover three new names after signing. When each is decided, the provider enters section 3 or section 2, as the case may be, with the prior notice described in section 6.

Until a provider is chosen, none of these functions is operating — which also means the platform is not open for sign-up.

5. International transfers

Practically all of the providers above process data outside Brazil. That follows directly from the messaging channels being operated by foreign companies, and is not a choice that could be undone by switching provider.

MechanismWhen it appliesLegal basis
Adequacy decisionA provider processing in a country recognised by the national authority as offering adequate protectionArticle 33, I, of the LGPD
Standard contractual clausesA provider processing in a country without an adequacy decision — today, most of the rows aboveArticle 33, II, point b, with the standard clauses approved by the national authority
Performance of a contract with the data subjectSpecific situations where the transfer is necessary to deliver what the data subject asked forArticle 33, IX

The standard clauses adopted are those approved by the national authority, incorporated in full and without changes to their text. The regulatory deadline for incorporating them has already passed, and Myndchat has treated them as in force since then.

Where the country column says it is to be determined, the mechanism is left undetermined with it — and it could not be otherwise. Both cells are settled at the same time.

6. How we announce a change

Every change to this list moves the page to a new version and follows the procedure below, which is the same one written in section 8 of the Data Processing Addendum:

EventWhat Myndchat doesDeadline
A new providerPublishes the change here and notifies the customer at the account contact addressAt least 30 days before the provider begins processing data
A provider is replacedSame procedure, identifying who leaves and who arrivesAt least 30 days beforehand
A provider moves from Planned to In useSame procedure: the move is treated as an arrivalAt least 30 days beforehand
A listed provider changes its country of processingPublishes and notifies, stating the new transfer mechanismAt least 30 days beforehand

A customer may object to a new provider, with reasons, and we reply within 15 days looking for a technical alternative. Where there is no alternative, we say so in writing and the customer may terminate without penalty, exporting their data. The honest caveat is in the Data Processing Addendum: the channel providers and the infrastructure provider cannot be substituted, because they are the very service the customer subscribed to.

To receive these notices, simply keep the account contact e-mail up to date. Anyone who is not yet a customer and wants to follow along may write to juridico@myndchat.com asking to be added to the notification list.

Corrections to wording, links or descriptions that change neither the provider, nor the data processed, nor the country do not trigger prior notice, but do appear in the history in section 8.

7. What is not a subprocessor of ours

Not every third party that touches data is a Myndchat subprocessor, and conflating the two would inflate this list until it stopped being useful. The following are not subprocessors of ours:

  • systems the customer integrates themselves — a webhook endpoint, their own API or a third party's that they chose. From the moment data leaves for a destination the customer determined, the customer answers for it;
  • the messaging platforms in their relationship with the end contact. Meta and TikTok are our subprocessors as to what passes through our integration, and are independent controllers as to what they do as owners of the channel, under their own policies;
  • the providers of our customer's own customers, which never touch our infrastructure;
  • suppliers Myndchat engages that process no personal data of customers or end contacts, such as internal administrative services.

Authorities that receive data under a legal order do not belong on this list either. That sharing is not subprocessing, has rules of its own, and is described in the Privacy Policy and in section 10 of the Data Processing Addendum.

8. Version history

Every published version is recorded here, with what changed. It is this history that lets a customer verify which list of providers governed each period.

VersionDateWhat changed
1.019 August 2026First publication. One provider in use, nine planned and three functions with no provider chosen

Previous versions stay available. When the list changes, the new row goes to the top of this table and the date at the top of the page becomes that of the new verification.

9. Contact

Questions about a provider, requests for contractual documentation, or a reasoned objection to an addition should go to the addresses below.

SubjectAddress
Objection to a provider, documentation and change noticesjuridico@myndchat.com
Privacy and data subject rightsprivacidade@myndchat.com
Data Protection Officerencarregado@myndchat.com

Myndchat is MYNDCHAT TECNOLOGIA LTDA, company number (CNPJ) 65.434.606/0001-80, registered at Avenida Brigadeiro Faria Lima, 1811, Sala ESC 1119, Jardim Paulistano, São Paulo/SP, 01452-001, Brazil. The Data Protection Officer is Bernardo Prantz Pin.

© 2026, Myndchat, Inc.

en
Product
InstagramTikTokWhatsAppMessengerMyndchat AISMS marketingFor BrandsFor eCommerceIntegrationsPricing
Resources
Help centerCommunityBlogChronically onlineHow toVideo courseChatbot examples
Myndchat
AboutManifestoCareersPressPrivacy & security
Problems
Can't keep upViral but brokeWrong link, wrong timeCan't log offRenting your audienceDrowning in comments
Partners
Myndchat for agenciesHire an agencyJoin the affiliate program
Other
Status pageChangelogPrivacy policyTerms of service
Get started freeGet started freeGet started free