Subprocessors

Last updated: 2026-07-08

InterviewerAI (KwantumLabs, Inc.) uses the following subprocessors to provide the service. We provide 30 days' advance notice (email to organization admins) before adding or replacing a subprocessor that processes respondent data. A machine-readable register of data flows is available to authenticated customers at GET /api/v1/gdpr/data-flows.

Active subprocessors

Subprocessor Role Data categories Region Data-protection terms Privacy policy
Railway Corp. Application hosting and managed PostgreSQL database All platform data (account data; respondent data incl. encrypted transcripts, session metadata) United States Railway DPA (standard) railway.com/legal/privacy
Amazon Web Services (S3) Object storage for audio recordings and export artifacts (server-side encryption) Respondent audio recordings; export files United States (per deployment configuration) AWS GDPR DPA (auto-incorporated in AWS Service Terms) aws.amazon.com/privacy
OpenAI, L.L.C. AI voice interviews (realtime speech), speech-to-text, text-to-speech, adaptive follow-up generation, response quality checks Respondent audio and transcripts; survey question text United States (API) OpenAI API DPA; API data not used to train models; no BAA — no PHI permitted (see Acceptable Use Policy) openai.com/policies/privacy-policy
Anthropic, PBC LLM for questionnaire import/editing; translation of survey content and responses where enabled; automated quality checks on open-ended answers (e.g. machine-generated-text detection) Customer questionnaire/config content; respondent open-ended answer text (translation and quality checks, where enabled) United States (API) Anthropic Commercial Terms incl. data-protection addendum; API data not used to train models anthropic.com/legal/privacy
Resend, Inc. Transactional email (login magic links, operational notices) Customer/team-member email addresses and email content United States Resend DPA (standard) resend.com/legal/privacy-policy
Tremendous, Inc. Respondent incentive fulfillment — customer-directed: rewards are issued from the customer's own funded Tremendous account Respondent reward redemption data (delivery contact as chosen by respondent) United States Customer's own Tremendous agreement governs; the platform passes redemption instructions only tremendous.com/privacy

Announced / upcoming (not yet processing data)

Subprocessor Role Data categories Region Data-protection terms Privacy policy
Stripe, Inc. Payment processing (checkout, subscriptions, billing portal) Customer billing data (card data held by Stripe, not by us) United States/global Stripe DPA (standard) stripe.com/privacy
PostHog, Inc. Product analytics — customer dashboard surface only; never on survey/respondent pages Customer dashboard usage events keyed to org/team member US or EU cloud (decided at integration) PostHog DPA (standard) posthog.com/privacy

Rows in this second table are published for transparency ahead of launch; they will move to "Active" (with completed region/terms columns) before any data flows to them.

Not subprocessors: panel providers and customer-directed services

Sample/panel providers (e.g., Prolific, Dynata, Cint, and any panel the customer connects via generic redirect links) are NOT InterviewerAI subprocessors. The customer selects, contracts with, and pays these providers directly; they act as independent parties (typically independent controllers of their panelist data, under their own linked privacy policies). InterviewerAI provides technical integration only (entry links, completion redirects, status callbacks) — panels receive completion-status signals and the pseudonymous IDs they issued, never response content.

Tremendous sits at the boundary: the account and funds are the customer's, but reward instructions transit our systems — hence its listing above.

Infrastructure notes