Subprocessors
Subprocessors
Version 1.0 · in force from 4 August 2026 · a binding agreement between you and Klair Tech, Hyderabad, India
The short version
Five companies process personal data on our behalf. Services you connect yourself, such as your warehouse or a vendor tool server, are not on this list because they are yours, not ours.
This summary is for orientation. The clauses below are the agreement.
A subprocessor is a company we engage to process personal data in order to run Insighter. This page names each one, what it does, and where it does it.
1. What is on this list
These are the companies Klair Tech engages to process personal data so that Insighter can run. We choose them, we contract with them, and we remain answerable to you for what they do with data we send them. That is what makes them subprocessors rather than simply vendors.
2. Current subprocessors
- Amazon Web Services. Hosting, file storage, outbound email, and AI model inference through Amazon Bedrock. Our infrastructure runs in the Mumbai region. Inference runs through an Asia Pacific regional profile, so a request may be handled in Mumbai or in another AWS Asia Pacific region.
- Anthropic. AI model inference, United States. Used as the backup path when Bedrock is unavailable.
- Supabase. Managed Postgres database holding accounts, organizations, conversations, and connector configuration.
- Razorpay. Payment processing, India. Card details are entered on Razorpay's own checkout and never reach our servers.
- Google. Analytics on our public website only, through Google Analytics and Google Tag Manager, and only if you accept analytics cookies. Your IP address is truncated before Google receives it. No question, answer, or connected data reaches Google through this.
3. Services you connect yourself
When you connect a data source or a vendor tool server, that provider is not our subprocessor. It is either your own system, such as your warehouse, or your own vendor, such as your CRM. You hold the relationship and their terms govern what they do with the data in their system.
What we are responsible for is the part in our hands: sending them only what your request needs, storing the credential encrypted, keeping the source read-only unless someone with manage access enables an action, and letting you disconnect at any time. Clause 5 of the Privacy Policy describes how data moves to and from them.
Some sources need no credential at all, such as public documentation and reference servers. We have no agreement with those operators, so anything sent to one should be treated as public. The Data page marks which sources these are.
4. Changes to this list
We keep this page current. Adding a subprocessor that processes customer content is a material change to the Privacy Policy and is announced the way clause 14 of that policy describes. If your organization needs advance notice of additions under a signed agreement, that agreement governs.
Something here unclear, or your legal team needs a signed copy? Ask us and a person will answer.
Contact us