Data supply chain

Subprocessors and service providers

These are the providers Wazzl currently relies on to deliver, secure, monitor, and support the service. Not every provider receives every category of data.

Current as of 26 August 2026Questions: [email protected]

1. How to read this list

When Wazzl processes workspace content for a customer, a provider that receives that content to perform a service can act as Wazzl’s subprocessor. For Wazzl’s own account, support, or security data, the same organisation may instead be a service provider to Wazzl as controller. “Potential data” describes the data a provider can receive based on how the service is used.

WhatsApp Platform data boundary: Meta / WhatsApp is the messaging channel and source. After Wazzl receives data from that channel, AWS is the only external infrastructure provider Wazzl intends to use to store or process the resulting contacts, phone numbers, Meta identifiers, messages, media, delivery events, or business-account content. The other providers below serve separated website, account-email, support, or availability functions and are not intended to receive that Meta-derived content.

2. Current providers

ProviderServicePotential data
Amazon Web Services (AWS)Production compute, database infrastructure, media or service storage, and database backups.Account and workspace data, including the Meta-derived contact, message, media, delivery, business-account, operational, and backup data needed to host Wazzl. When optional first-party acquisition measurement is enabled and permitted, AWS also stores its unlinked allowlisted event/session records and content-free retry receipts until scheduled expiry.
CloudflarePublic website hosting, DNS, content delivery, and network protection.Public-site requests, IP and network metadata, and content submitted through browser requests routed to Wazzl.
Meta / WhatsAppWhatsApp Business Platform channel, provider identifiers, media retrieval, messages, and delivery events.WhatsApp phone numbers, profiles supplied by the channel, messages, media, templates where applicable, delivery status, and business-account metadata.
ResendTransactional email for account invitations, password resets, security notices, public-form deletion communications, and workflow-review enquiries.Recipient email address and transactional account content. A workflow-review email contains only the submitted name, work email, company, team-size range, weekly-enquiry range, and contact consent. Signed Meta deletion callbacks remain in AWS and do not generate Resend email.
SentryError reporting for non-Meta contexts when separately configured.Sentry is disabled in the Meta-connected production runtime and browser builds, so Wazzl does not intend to send Meta-derived content or diagnostics from those builds to Sentry.
Tawk.toEmbedded support chat on the public support page.Chat content, contact details a visitor supplies, browser/device information, IP and support-session metadata. Visitors are prohibited from submitting WhatsApp or Meta content.
Google (Google Fonts and Gmail)Direct webfont delivery on public marketing pages and signed-in or authentication application pages; support, privacy, security, and operational email communications; and workflow-review receipt while the monitored privacy mailbox remains the configured fallback destination.When one of those browser pages loads typography from fonts.googleapis.com and fonts.gstatic.com, Google can receive the requested font resources plus ordinary IP, browser, and network request metadata. Wazzl does not place form, account, workspace, message, contact, or Meta content in a font request. Email use can include addresses, headers, and message content a sender chooses to provide. A fallback workflow-review email contains the submitted name, work email, company, team-size range, weekly-enquiry range, and contact consent. Senders are prohibited from submitting WhatsApp or Meta content or inbox screenshots.
PRavatarDelivery of one fixed fictional demo-contact avatar in the signed-in application.The image request can expose ordinary IP, browser, and network metadata plus a fixed fictional seed alias. Wazzl does not place a customer, workspace, contact, phone number, message, media, credential, or Meta-derived value in that request.
UptimeRobotPublic website and API availability monitoring and alerting.Health-check responses, response time, availability events, endpoint address, and alert-contact details.

Optional acquisition measurement adds no analytics vendor or advertising subprocessor. The browser sends the finite first-party measurement contract directly to Wazzl’s API, and the resulting unlinked records stay in the existing AWS-hosted application database. Wazzl does not send those records to Sentry, ad platforms, or the workflow-review email path.

3. Processing locations

These providers can process data in multiple countries through their infrastructure and support operations. Wazzl does not present one country as the exclusive location for every provider. Applicable agreements and provider transfer mechanisms govern international processing where required.

4. Changes to providers

Wazzl may add, replace, or remove a provider as the service changes. This page will be updated before or when a material provider change takes effect. A customer that needs contractual advance notice or an objection process should request and execute an appropriate data-processing agreement; this public list alone does not create a negotiated notice period.

5. Questions

For security or data-protection information about a provider, email [email protected] and identify the provider and workspace relationship. See the data-processing terms summary for Wazzl’s processor commitments.