Subprocessors & Third-Party Services
Current and feature-dependent external services used by COLEUS Rooms. A provider receives data only when the corresponding integration or feature is used.
1. About this list
A subprocessor is a service provider that processes personal information on behalf of COLEUS Systems, Inc. Some third parties listed here may instead act as an independent controller, public authority, professional registry, browser asset host, payment processor, or dynamic destination.
This page is designed to be updated as integrations, contracts, and deployment status change. Planned, not-deployed, development-only, and disabled providers are not represented as current production recipients.
Processing location, contract, retention, training, and transfer terms may vary by provider, service variant, and account plan. Regulated processing is not approved solely because a provider appears in this list.
2. Core infrastructure, authentication, and delivery
| Provider / service | Purpose | Data that may be processed | When used / status |
|---|---|---|---|
| Nebius Compute | Application hosting, PostgreSQL hosting, local file storage | Account, workspace, session, source, artifact, verification, billing, and technical data | Core production infrastructure |
| Google Identity Services | Google Sign-In and ID-token verification | Google sub, email, verification flag, name, profile image URL, security metadata |
When a user signs in with Google |
| Resend | Transactional, security, verification, and notification email | Email address, name, email content, delivery metadata | Core production email |
| Namecheap | Domain registration and authoritative DNS | DNS and technical request metadata; no ordinary session content | Core domain/DNS infrastructure |
| Google Fonts | Browser font delivery | IP address, user agent, request metadata | When pages load Google-hosted fonts |
| jsDelivr | Browser asset delivery | IP address, user agent, request metadata | When pages load CDN-hosted assets |
| Google Cloud Platform services | Cloud Run proxies, build, container registry, and secret management | Code, container images, secrets; selected request content where a Google proxy is invoked | Feature/deployment dependent |
3. AI and language-model providers
The following providers may receive selected prompts, messages, source excerpts, files, task context, transcripts, or other inputs only when the relevant feature selects that provider.
| Provider / integration | Typical purpose | Data that may be processed | Status |
|---|---|---|---|
| OpenAI API | Dialogue assistance, drafting, analysis, translation, Context/Studio functions | Selected prompts, messages, context, Sources, drafts, model parameters | Feature-dependent |
| OpenAI Audio / Realtime | Speech-to-text, text-to-speech, voice analysis, future conference transcription | Audio, transcript text, voice settings, technical metadata | Feature-dependent; realtime may be configured but not generally enabled |
| Anthropic Messages API | Studio setup/work, Review, Council, Prism, translation, analysis | Selected task, draft, context, and source content | Feature-dependent |
| Google Gemini API / Cloud Run proxy | Prism and Brainstorm generation; selected language-model functions | Selected prompts, context, and attachments | Currently constrained to enabled Prism/Brainstorm paths |
| Groq | Matching and lightweight routing/classification | Query, candidate summaries, broad location, selected source context | Feature-dependent |
| xAI | Prism/Brainstorm generation | Selected prompt and context | Feature-dependent |
| DeepSeek | Prism/Brainstorm generation | Selected prompt and context | Feature-dependent |
| Alibaba Cloud / DashScope (Qwen) | Prism/Brainstorm generation and diagnostics | Selected prompt and context | Feature-dependent |
| Nebius AI Studio | Prism/Brainstorm generation | Selected prompt and context | Feature-dependent |
| Perplexity Sonar | AI-assisted web research | Research query and selected context | Feature-dependent |
COLEUS Rooms may change models or providers while preserving the applicable data and policy controls. Provider-specific regulated use requires separate approval.
4. Search, research, and web-content services
| Provider / service | Purpose | Data that may be processed | When used |
|---|---|---|---|
| Brave Search API | Web search and source discovery | Search query and limited context | User starts a supported research function |
| Exa | Search, research, and source retrieval | Search query and limited context | User starts a supported research function |
| Tavily | Search and research | Search query and limited context | User starts a supported research function |
| Perplexity Search API | Search and source retrieval | Search query and limited context | User starts a supported research function |
| Jina Reader | Retrieve and transform public webpage content | Requested URL and technical metadata | A supported Source feature retrieves a webpage |
| Firecrawl | Scrape and retrieve public webpage content | Requested URL and technical metadata | A supported Source feature retrieves a webpage |
| User-selected external websites | Direct retrieval of a URL chosen by the user | IP/server request metadata and the requested URL | User asks COLEUS Rooms to retrieve that site |
External websites are not fixed COLEUS subprocessors. The destination receives the ordinary web request and applies its own privacy practices.
5. Communications and conferencing
| Provider / service | Purpose | Data that may be processed | When used |
|---|---|---|---|
| Telegram Bot API | Connected notifications or messaging | Telegram identifier, message/notification content, delivery metadata | User connects or invokes Telegram functionality |
| Twilio WhatsApp | WhatsApp messaging and delivery status | Phone/WhatsApp identifier, message content, delivery metadata | User connects or invokes WhatsApp functionality |
| Daily | Audio/video room creation and conferencing | Participant metadata, room tokens, audio/video streams, recording/transcription data if enabled | User joins an enabled conference feature |
Email, Telegram, WhatsApp, and conferencing providers have their own terms and may process data as independent controllers for parts of their services.
6. Identity, billing, verification, and security services
| Provider / service | Purpose | Data that may be processed | When used / status |
|---|---|---|---|
| Stripe Identity | Expert identity verification | Identity documents, selfie/biometric verification data where used, verification result, technical metadata | When an expert starts identity verification |
| Stripe Billing / Checkout | Subscriptions, credits, invoices, customer portal, payment status | Contact, payment, billing, transaction, tax, and fraud metadata | Prelaunch-configured; used when paid billing is enabled |
| OpenTimestamps public calendars | Timestamp anchoring for artifact hashes | Cryptographic hash/proof metadata, not the document contents | When a finalized artifact requests timestamp anchoring |
Stripe Connect, consultation payouts, escrow, Checkr, Certn, external address verification, and analytics providers are not listed as current production processors because those functions are planned, pending, disabled, or not deployed.
7. Public authorities and professional registry sources
Professional credential checks may consult public authorities or professional registries. These sources are generally not subprocessors. They provide public or authority-maintained information and are governed through the separate Professional Verification source catalog.
Current or reviewed source families may include:
- U.S. Patent and Trademark Office OED practitioner roster;
- CMS/NPPES identifier data;
- HHS-OIG LEIE exclusion data;
- State Bar of California attorney search; and
- other sources added only after their access, automation, evidence, display, and retention policies are reviewed.
A configured source is not necessarily queried automatically or enabled in production.
8. Changes, review, and contact
We may add, remove, or change a provider as the Service evolves. Material changes will be reflected on this page and, where required, communicated through account, contractual, or privacy notices.
Before publication, COLEUS Systems, Inc. must confirm each listed provider’s current legal entity, contract/DPA status, processing locations, retention, training use, transfer mechanism, and production enablement.
Questions: privacy@coleussystems.com