WhatsApp calling is live — answer customer calls right inside your inbox.

Back home

Subprocessor List

Every third party that touches your data to make Instant work — what each one does, what it can see, and how to object if you would rather we did not use one.

Last updated: 5 August 2026

1What a subprocessor is

To run Instant we rely on other companies — a database provider, the messaging platforms themselves, a payment processor. Where one of them processes personal data on our behalf in the course of providing the Service to you, it is a subprocessor, and you are entitled to know who it is.

This page is that list. It forms part of our Data Processing Agreement, and the authorisation you give us there is an authorisation to use the providers named below.

Each is engaged under a written contract with data protection obligations no less protective than those in our DPA, and we remain responsible to you for what they do with your data.

2Core platform subprocessors

These are engaged for every customer — the Service cannot run without them.

  • Supabase — managed PostgreSQL database, authentication and file storage. Sees essentially all workspace data: account and user records, contacts, message history, attachments and avatars. This is where your workspace lives.
  • Meta Platforms — the WhatsApp Business Platform, Instagram and Messenger. Sees the messages, phone numbers and profile identifiers of every conversation on those channels, necessarily, because it is the network carrying them. Meta acts as an independent controller under its own terms, not merely as our subprocessor.
  • Hostinger for application hosting, with Cloudflare R2 for media delivery — application hosting and content delivery for the Instant web application and its APIs. Processes request data including IP addresses, and handles data in transit.

Workspace data is hosted in Mumbai, India (ap-south-1). Meta processes message data across its own global infrastructure under its terms, which is outside our control and unavoidable on any WhatsApp Business Platform product.

3Billing

  • Razorpay — payment processing for subscriptions. Sees your billing name, email, and the payment instrument details you enter directly with it. Card and UPI details go straight to Razorpay and are never stored on our servers; we retain only the plan, invoice and transaction reference.

Meta bills conversation charges to your own WhatsApp Business Account separately from your Instant subscription. That relationship is between you and Meta.

4Used only if you enable the feature

These process data only when you switch on the feature that needs them. Leave the feature off and no data reaches them.

  • Google — two separate things, both optional. Sign-in with Google, where you or your team choose it, sees the email address and basic profile of the person signing in, and only at sign-in. Google Analytics 4 runs on the public marketing pages only, and only for visitors who accept cookies: it sees the pages visited and the coarse technical details any web request carries. Neither touches the signed-in app or any of your workspace data.
  • Umami — cookieless page-view analytics, where enabled on this deployment. Sees the page visited plus the coarse technical details any web request carries (browser, device type, approximate country from IP). It sets no cookies, does not follow visitors between sites, and does not receive any of your workspace data.
  • OpenAI — AI reply generation and embeddings, when you configure an OpenAI key. Sees the prompts, knowledge-base content and message text needed to draft a reply.
  • Anthropic — AI reply generation, when you configure an Anthropic key. Same scope as above.
  • OpenRouter — AI model routing, when you configure an OpenRouter key. Same scope, forwarded to the model provider you select there.

AI is bring-your-own-key: the model provider is your account and your contract with them, and we send only what is needed to answer the specific message. We do not use your conversations to train general-purpose models, and neither arrangement gives us a right to.

5Providers you introduce yourself

When you connect your own systems, you extend the chain beyond this list and take responsibility for that part of it:

  • Outbound webhooks deliver event data to endpoints you nominate — Zapier, Make, n8n or your own backend.
  • API keys let software you choose read and write your workspace data.
  • Data you export leaves the Service entirely.

We are not the processor for what happens downstream of those, and they are not covered by this list.

6Changes and how to object

  • We will give reasonable advance notice before adding or replacing a subprocessor, so you have time to consider it. The "last updated" date above tracks changes to this page.
  • To be told directly rather than checking here, email contact@instant.nebkern.com asking to be added to subprocessor change notifications.
  • If you object on reasonable data protection grounds, write to us within 30 days of the notice. We will try to find a workable alternative; if there is none, you may terminate the affected part of the Service and we will refund prepaid fees for the unused period.

Questions about anything on this list: contact@instant.nebkern.com.