Sub-processors
The third parties that help us run Agily, and how we notify you of changes.
Last updated: 2026-09-12 · Effective: 2026-09-12
We are finalizing our legal documentation ahead of general availability. These pages describe our current practices; contact legal@agily.app with any questions.
Agily engages the third parties below to help provide the Service. Each is bound by a written contract with data-protection terms consistent with our Data Processing Agreement. We remain responsible for their performance.
How to get change notifications
Customers can subscribe to sub-processor change notifications by emailing legal@agily.app with the subject “subscribe: sub-processors”. Before a new sub-processor begins processing customer personal data, we will post it here and notify subscribers with at least 30 days’ notice. Customers may object on reasonable data-protection grounds as described in the DPA.
1. Core infrastructure sub-processors (used for every customer)
| Sub-processor | Function | Data processed | Location |
|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud hosting and compute; object storage (Amazon S3) for uploaded files, avatars, and organization logos; malware scanning of uploads (Amazon GuardDuty) | Customer data and account data at rest and in transit within our infrastructure; uploaded file bytes | [AWS region — to confirm] |
| [frontend host — e.g. Vercel] | Hosting and delivery of the web frontend | Serves the application shell to browsers; may process request metadata (IP, user-agent) at the edge | To confirm |
| [transactional email provider] | Sending transactional email (verification, password reset, invitations, notifications) | Recipient email address and name; email content | To confirm |
| Managed Redis provider | Queueing and read-model for standup dispatch and inbound chat-event ingestion; distributed rate limiting | Transient job payloads and inbound provider event payloads (may include message text and user identifiers) | To confirm |
| Error-monitoring / log-aggregation provider | Application error tracking, log aggregation, and alerting | Application logs and error events, configured to minimize personal data | To confirm |
| Paddle.com Market Ltd | Payment processing, mandate setup, and automatic debit for paid subscriptions, in all billing currencies. Acts as merchant of record: calculates, collects, and remits applicable tax (for example, GST for transactions billed in India) on our behalf. | Billing contact details; payment instrument (held by the processor; we receive only a token and a display hint); transaction data | United Kingdom |
| Razorpay Software Private Limited | Payment processing, e-mandate setup, and automatic debit for paid subscriptions billed in INR that started before we moved to Paddle. Not used for new subscriptions. | Billing contact details; payment instrument (held by the processor; we receive only a token and a display hint); transaction data | India |
2. Feature-triggered sub-processors (only when a customer enables the feature)
2.1 Chat / messaging integrations
Enabled per organization by a customer administrator.
| Sub-processor | Function | Data processed |
|---|---|---|
| Slack Technologies, LLC (Salesforce) | Deliver messages to and receive events from a connected Slack workspace | Message content; Slack user IDs and usernames of linked members; the workspace’s OAuth token |
| Microsoft Corporation (Microsoft Teams) | Deliver messages to a connected Teams environment | Message content; Teams/Azure user identifiers |
| Telegram Messenger | Deliver DMs/prompts and receive replies via a Telegram bot | Message content; Telegram user IDs and usernames |
| Discord Inc. | Deliver channel messages and receive DM replies via a Discord bot | Message content; Discord user IDs and usernames |
2.2 Data import integrations
Connected by a customer administrator to import an existing Jira project or Confluence space into the Service at the Customer’s explicit request. Unlike the chat integrations above, this is a one-time import, not an ongoing sync — we do not continue exchanging data with Atlassian after an import completes. The connection is authenticated with an API token the Customer generates and supplies (not OAuth), stored encrypted at rest, and can be permanently deleted by an administrator at any time from Settings → Integrations, which immediately and irrecoverably removes the stored token from our database.
| Sub-processor | Function | Data processed |
|---|---|---|
| Atlassian Pty Ltd (Jira & Confluence Cloud) | Read a connected Jira project’s issues, or a Confluence space’s pages, for one-time import | Issue/page titles, descriptions, comments, and attachments; Jira assignee/comment-author email addresses used for best-effort matching to existing members; the Customer-supplied Atlassian API token |
2.3 AI providers
Used by AI-assisted features (standup summarization; editor writing assistant). In “Managed” mode the provider is one we select from the list below; in “bring-your-own-key” mode it is the provider whose API key the customer supplies. These providers are contractually prohibited from using the data to train models.
| Sub-processor | Function | Data processed | Location |
|---|---|---|---|
| OpenAI, L.L.C. | Text generation for AI features (Managed and/or BYOK) | Prompt text derived from customer content; generated output | United States |
| Anthropic, PBC | Text generation for AI features (Managed and/or BYOK) | Prompt text derived from customer content; generated output | United States |
| Google LLC (Gemini API) | Text generation for AI features (Managed and/or BYOK) | Prompt text derived from customer content; generated output | United States / to confirm |
| Self-hosted model runtime (Ollama) | Text generation where the customer configures a self-hosted model endpoint | Prompt text; output | Customer-controlled |
2.4 Sign-in identity providers
When a user chooses to sign in with Google or GitHub, the provider authenticates the user and returns a verified email and a stable identifier (email address, name, avatar URL, and the account identifier). We treat these as independent controllers from whom we receive data.
3. Not sub-processors
- Professional advisers (accountants, auditors, lawyers) engaged under confidentiality — disclosed only as needed and not to process customer personal data on our behalf as part of the Service.
- Prospective acquirers in a due-diligence process — under NDA; disclosure limited.
Questions? Email legal@agily.app. Privacy requests: privacy@agily.app. Report a security issue: security@agily.app.