Sub-processors

The third parties that help us run Agily, and how we notify you of changes.

Last updated: 2026-09-12 · Effective: 2026-09-12

We are finalizing our legal documentation ahead of general availability. These pages describe our current practices; contact legal@agily.app with any questions.

Agily engages the third parties below to help provide the Service. Each is bound by a written contract with data-protection terms consistent with our Data Processing Agreement. We remain responsible for their performance.

How to get change notifications

Customers can subscribe to sub-processor change notifications by emailing legal@agily.app with the subject “subscribe: sub-processors”. Before a new sub-processor begins processing customer personal data, we will post it here and notify subscribers with at least 30 days’ notice. Customers may object on reasonable data-protection grounds as described in the DPA.

1. Core infrastructure sub-processors (used for every customer)

Sub-processorFunctionData processedLocation
Amazon Web Services, Inc. (AWS)Cloud hosting and compute; object storage (Amazon S3) for uploaded files, avatars, and organization logos; malware scanning of uploads (Amazon GuardDuty)Customer data and account data at rest and in transit within our infrastructure; uploaded file bytes[AWS region — to confirm]
[frontend host — e.g. Vercel]Hosting and delivery of the web frontendServes the application shell to browsers; may process request metadata (IP, user-agent) at the edgeTo confirm
[transactional email provider]Sending transactional email (verification, password reset, invitations, notifications)Recipient email address and name; email contentTo confirm
Managed Redis providerQueueing and read-model for standup dispatch and inbound chat-event ingestion; distributed rate limitingTransient job payloads and inbound provider event payloads (may include message text and user identifiers)To confirm
Error-monitoring / log-aggregation providerApplication error tracking, log aggregation, and alertingApplication logs and error events, configured to minimize personal dataTo confirm
Paddle.com Market LtdPayment processing, mandate setup, and automatic debit for paid subscriptions, in all billing currencies. Acts as merchant of record: calculates, collects, and remits applicable tax (for example, GST for transactions billed in India) on our behalf.Billing contact details; payment instrument (held by the processor; we receive only a token and a display hint); transaction dataUnited Kingdom
Razorpay Software Private LimitedPayment processing, e-mandate setup, and automatic debit for paid subscriptions billed in INR that started before we moved to Paddle. Not used for new subscriptions.Billing contact details; payment instrument (held by the processor; we receive only a token and a display hint); transaction dataIndia

2. Feature-triggered sub-processors (only when a customer enables the feature)

2.1 Chat / messaging integrations

Enabled per organization by a customer administrator.

Sub-processorFunctionData processed
Slack Technologies, LLC (Salesforce)Deliver messages to and receive events from a connected Slack workspaceMessage content; Slack user IDs and usernames of linked members; the workspace’s OAuth token
Microsoft Corporation (Microsoft Teams)Deliver messages to a connected Teams environmentMessage content; Teams/Azure user identifiers
Telegram MessengerDeliver DMs/prompts and receive replies via a Telegram botMessage content; Telegram user IDs and usernames
Discord Inc.Deliver channel messages and receive DM replies via a Discord botMessage content; Discord user IDs and usernames

2.2 Data import integrations

Connected by a customer administrator to import an existing Jira project or Confluence space into the Service at the Customer’s explicit request. Unlike the chat integrations above, this is a one-time import, not an ongoing sync — we do not continue exchanging data with Atlassian after an import completes. The connection is authenticated with an API token the Customer generates and supplies (not OAuth), stored encrypted at rest, and can be permanently deleted by an administrator at any time from Settings → Integrations, which immediately and irrecoverably removes the stored token from our database.

Sub-processorFunctionData processed
Atlassian Pty Ltd (Jira & Confluence Cloud)Read a connected Jira project’s issues, or a Confluence space’s pages, for one-time importIssue/page titles, descriptions, comments, and attachments; Jira assignee/comment-author email addresses used for best-effort matching to existing members; the Customer-supplied Atlassian API token

2.3 AI providers

Used by AI-assisted features (standup summarization; editor writing assistant). In “Managed” mode the provider is one we select from the list below; in “bring-your-own-key” mode it is the provider whose API key the customer supplies. These providers are contractually prohibited from using the data to train models.

Sub-processorFunctionData processedLocation
OpenAI, L.L.C.Text generation for AI features (Managed and/or BYOK)Prompt text derived from customer content; generated outputUnited States
Anthropic, PBCText generation for AI features (Managed and/or BYOK)Prompt text derived from customer content; generated outputUnited States
Google LLC (Gemini API)Text generation for AI features (Managed and/or BYOK)Prompt text derived from customer content; generated outputUnited States / to confirm
Self-hosted model runtime (Ollama)Text generation where the customer configures a self-hosted model endpointPrompt text; outputCustomer-controlled

2.4 Sign-in identity providers

When a user chooses to sign in with Google or GitHub, the provider authenticates the user and returns a verified email and a stable identifier (email address, name, avatar URL, and the account identifier). We treat these as independent controllers from whom we receive data.

3. Not sub-processors

  • Professional advisers (accountants, auditors, lawyers) engaged under confidentiality — disclosed only as needed and not to process customer personal data on our behalf as part of the Service.
  • Prospective acquirers in a due-diligence process — under NDA; disclosure limited.

Questions? Email legal@agily.app. Privacy requests: privacy@agily.app. Report a security issue: security@agily.app.