1. Scope
A subprocessor is a provider engaged to process Customer Personal Data on LumiTalk’s behalf. A website vendor, independent controller, telecommunications carrier, customer-selected integration, and subprocessor are not automatically the same legal role.
2. Verified public-website providers
| Provider | Public-site purpose | Status |
|---|---|---|
| Google Analytics | Optional site measurement after consent | Analytics provider |
| Cloudflare Turnstile | Contact-form abuse prevention | Security provider |
| Resend | Contact-form email delivery | Communications provider |
| Google Calendar and Google Meet | Demo availability, invitations, and meeting links | Scheduling provider / independent services may apply |
3. Customer-service subprocessors
The complete production subprocessor register cannot be represented accurately from the public website code alone. A binding DPA must identify the providers actually used for the customer’s deployment, processing purpose, location where required, and update process before Customer relies on the list.
4. Customer-selected integrations
A CRM, calendar, help desk, commerce platform, communications carrier, or other system selected and authorized by Customer may receive Customer Data directly under Customer’s account and the provider’s terms. The signed agreement should state whether LumiTalk acts as Customer’s processor when transmitting that data and who contracts with the integration provider.
5. Changes and objections
Where required by an executed DPA, LumiTalk will provide notice before adding or replacing a subprocessor and a reasonable process for data-protection objections. The DPA must state the resolution and termination options if an objection cannot be resolved.
6. Contractual safeguards
Authorized subprocessors should be bound to protect Customer Personal Data to a standard materially consistent with the executed DPA for the processing they perform. LumiTalk remains responsible to Customer as stated in that agreement.
7. Request the deployment list
Customers should request the current deployment-specific list during contracting. LumiTalk should not provide credentials, network diagrams, or security-sensitive architecture through the public contact form.





