Legal
Subprocessors
Last updated: August 19, 2026
Primagery AI uses the following categories of third-party subprocessors to deliver the Services. This list is provided for transparency under GDPR Article 28 and client diligence requests. We require subprocessors to protect personal data under contractual obligations.
Updates: We will update this page when we add or replace subprocessors with material impact. Enterprise clients may subscribe to change notifications via info@primagery.com. The engineering source of truth is the application subprocessor registry (updated when vendors are added or removed in code).
| Subprocessor | Purpose | Processing location | Data processed |
|---|---|---|---|
| Vercel Inc. | Application hosting, edge network, serverless functions, deployment, AI Gateway | United States (global edge) | Application logs, request metadata, environment configuration; AI Gateway request metadata when enabled |
| Neon Tech Inc. | Managed PostgreSQL database | United States (region configurable) | Account data, Client Data stored in application tables |
| Vercel Blob Storage | Document vault object storage (when enabled) | United States | Uploaded files and associated metadata |
| Resend Inc. | Transactional and operator email (outbound send, inbound routing via webhooks) | United States | Recipient email, message content, delivery events |
| Upstash Inc. | Distributed rate limiting / Redis (when configured) | United States / EU (region dependent) | IP hashes, rate-limit counters |
| Google LLC (optional OAuth) | Sign-in with Google when enabled by deployment configuration | United States / global | OAuth profile claims (name, email) per Google privacy policy |
| Stripe Inc. | Payment processing (when used) | United States / global | Billing contact, payment method tokens, card data on Stripe |
| Anthropic PBC | AI model inference for operator Wolfie, Help assistant, and briefs (commercial API / Gateway) | United States | Prompts and context limited to feature scope; commercial API. No training on API data by default |
| Cloudflare, Inc. | DNS and optional edge/WAF for primagery.com (when configured) | United States / global edge | DNS records, request metadata when proxied |
| HighLevel (LeadConnector), transitional | Legacy CRM contact pull (read-only) until fully cut over | United States | Contact records when HighLevel integration is enabled |
| PostHog Inc. | Product analytics, session replay, and Replay Vision scanners for operator/portal diagnostics (when NEXT_PUBLIC_POSTHOG_KEY is set); optional marketing pageviews with cookie consent | United States or EU (project region) | Pseudonymous user ids, pageviews, custom diagnostic events, masked session replays, and scanner-generated observations on replays; no email in event properties by default |
Additional subprocessors
Clients may enable or request integrations (analytics, CRM, hospitality PMS, etc.) that act as separate processors under the Client's control. Those relationships are outside this default list unless Primagery operates the integration centrally.
Security and compliance documentation
SOC 2 reports, penetration test summaries, or security questionnaire responses may be available under NDA for qualified clients. Contact info@primagery.com.