COLEUS RoomsLegal & policies

Subprocessors & Third-Party Services

Last updated: July 27, 2026 · Version 1.0 · Effective July 27, 2026

Current and feature-dependent external services used by COLEUS Rooms. A provider receives data only when the corresponding integration or feature is used.

1. About this list

A subprocessor is a service provider that processes personal information on behalf of COLEUS Systems, Inc. Some third parties listed here may instead act as an independent controller, public authority, professional registry, browser asset host, payment processor, or dynamic destination.

This page is designed to be updated as integrations, contracts, and deployment status change. Planned, not-deployed, development-only, and disabled providers are not represented as current production recipients.

Processing location, contract, retention, training, and transfer terms may vary by provider, service variant, and account plan. Regulated processing is not approved solely because a provider appears in this list.

2. Core infrastructure, authentication, and delivery

Provider / service Purpose Data that may be processed When used / status
Nebius Compute Application hosting, PostgreSQL hosting, local file storage Account, workspace, session, source, artifact, verification, billing, and technical data Core production infrastructure
Google Identity Services Google Sign-In and ID-token verification Google sub, email, verification flag, name, profile image URL, security metadata When a user signs in with Google
Resend Transactional, security, verification, and notification email Email address, name, email content, delivery metadata Core production email
Namecheap Domain registration and authoritative DNS DNS and technical request metadata; no ordinary session content Core domain/DNS infrastructure
Google Fonts Browser font delivery IP address, user agent, request metadata When pages load Google-hosted fonts
jsDelivr Browser asset delivery IP address, user agent, request metadata When pages load CDN-hosted assets
Google Cloud Platform services Cloud Run proxies, build, container registry, and secret management Code, container images, secrets; selected request content where a Google proxy is invoked Feature/deployment dependent

3. AI and language-model providers

The following providers may receive selected prompts, messages, source excerpts, files, task context, transcripts, or other inputs only when the relevant feature selects that provider.

Provider / integration Typical purpose Data that may be processed Status
OpenAI API Dialogue assistance, drafting, analysis, translation, Context/Studio functions Selected prompts, messages, context, Sources, drafts, model parameters Feature-dependent
OpenAI Audio / Realtime Speech-to-text, text-to-speech, voice analysis, future conference transcription Audio, transcript text, voice settings, technical metadata Feature-dependent; realtime may be configured but not generally enabled
Anthropic Messages API Studio setup/work, Review, Council, Prism, translation, analysis Selected task, draft, context, and source content Feature-dependent
Google Gemini API / Cloud Run proxy Prism and Brainstorm generation; selected language-model functions Selected prompts, context, and attachments Currently constrained to enabled Prism/Brainstorm paths
Groq Matching and lightweight routing/classification Query, candidate summaries, broad location, selected source context Feature-dependent
xAI Prism/Brainstorm generation Selected prompt and context Feature-dependent
DeepSeek Prism/Brainstorm generation Selected prompt and context Feature-dependent
Alibaba Cloud / DashScope (Qwen) Prism/Brainstorm generation and diagnostics Selected prompt and context Feature-dependent
Nebius AI Studio Prism/Brainstorm generation Selected prompt and context Feature-dependent
Perplexity Sonar AI-assisted web research Research query and selected context Feature-dependent

COLEUS Rooms may change models or providers while preserving the applicable data and policy controls. Provider-specific regulated use requires separate approval.

4. Search, research, and web-content services

Provider / service Purpose Data that may be processed When used
Brave Search API Web search and source discovery Search query and limited context User starts a supported research function
Exa Search, research, and source retrieval Search query and limited context User starts a supported research function
Tavily Search and research Search query and limited context User starts a supported research function
Perplexity Search API Search and source retrieval Search query and limited context User starts a supported research function
Jina Reader Retrieve and transform public webpage content Requested URL and technical metadata A supported Source feature retrieves a webpage
Firecrawl Scrape and retrieve public webpage content Requested URL and technical metadata A supported Source feature retrieves a webpage
User-selected external websites Direct retrieval of a URL chosen by the user IP/server request metadata and the requested URL User asks COLEUS Rooms to retrieve that site

External websites are not fixed COLEUS subprocessors. The destination receives the ordinary web request and applies its own privacy practices.

5. Communications and conferencing

Provider / service Purpose Data that may be processed When used
Telegram Bot API Connected notifications or messaging Telegram identifier, message/notification content, delivery metadata User connects or invokes Telegram functionality
Twilio WhatsApp WhatsApp messaging and delivery status Phone/WhatsApp identifier, message content, delivery metadata User connects or invokes WhatsApp functionality
Daily Audio/video room creation and conferencing Participant metadata, room tokens, audio/video streams, recording/transcription data if enabled User joins an enabled conference feature

Email, Telegram, WhatsApp, and conferencing providers have their own terms and may process data as independent controllers for parts of their services.

6. Identity, billing, verification, and security services

Provider / service Purpose Data that may be processed When used / status
Stripe Identity Expert identity verification Identity documents, selfie/biometric verification data where used, verification result, technical metadata When an expert starts identity verification
Stripe Billing / Checkout Subscriptions, credits, invoices, customer portal, payment status Contact, payment, billing, transaction, tax, and fraud metadata Prelaunch-configured; used when paid billing is enabled
OpenTimestamps public calendars Timestamp anchoring for artifact hashes Cryptographic hash/proof metadata, not the document contents When a finalized artifact requests timestamp anchoring

Stripe Connect, consultation payouts, escrow, Checkr, Certn, external address verification, and analytics providers are not listed as current production processors because those functions are planned, pending, disabled, or not deployed.

7. Public authorities and professional registry sources

Professional credential checks may consult public authorities or professional registries. These sources are generally not subprocessors. They provide public or authority-maintained information and are governed through the separate Professional Verification source catalog.

Current or reviewed source families may include:

A configured source is not necessarily queried automatically or enabled in production.

8. Changes, review, and contact

We may add, remove, or change a provider as the Service evolves. Material changes will be reflected on this page and, where required, communicated through account, contractual, or privacy notices.

Before publication, COLEUS Systems, Inc. must confirm each listed provider’s current legal entity, contract/DPA status, processing locations, retention, training use, transfer mechanism, and production enablement.

Questions: privacy@coleussystems.com