MerdialMerdialerdial

Sub-processors

Every vendor that touches your data. · Last updated 6 September 2026

Merdial engages the third parties below to deliver the Service. Each is bound by a written contract to process personal data only on Merdial’s instructions, with protections no less strict than those in our Data Processing Agreement. Merdial remains fully liable to its customers for their performance.

Get told before the list changes

We give at least 30 days’ notice before a new sub-processor begins processing customer data. To subscribe to those notices, email team@merdial.com with the address that should receive them. Customers may object on reasonable data-protection grounds; see DPA §6.

Infrastructure and platform

Sub-processorWhat it doesData it touchesLocation
SupabasePrimary database, authentication, file storage, realtime and serverless functions. The system of record.All Customer Data; account identity; authentication and transactional email.United States / European Union (per project region)
VercelHosting, edge delivery and DNS for the web application and marketing site.Request metadata and IP address. No call content is stored here.United States, with global edge network
CloudflareDNS resolution used when verifying customer custom domains.Hostnames only. No personal data.United States, global

Speech

Sub-processorWhat it doesData it touchesLocation
DeepgramReal-time and post-call speech-to-text.Call audio and the transcript returned from it.United States

AI model providers

Sub-processorWhat it doesData it touchesLocation
OpenAILanguage model for the realtime lane — the coaching prompt an agent sees mid-call — and as fallback on the analysis lane.Redacted transcript excerpts and the configuration context a task needs.United States
DeepSeekLanguage model for the heavy lane — post-call scoring, playbook extraction, list organisation, long-context analysis.Redacted transcripts and the rubric or criteria being applied.People’s Republic of China

Where the model calls go, stated plainly

DeepSeek is operated from the People’s Republic of China, and requests to it are an international transfer. It receives redacted transcript text and the rubric being applied — never call audio, credentials, contact databases or payment data — under contractual terms that prohibit training on, or retaining, the content we send. Customers whose own obligations forbid processing in China can have their organisation pinned to the US-only model lane; ask team@merdial.com before onboarding.

Before any transcript reaches a model provider, payment-card patterns are stripped by the redaction layer described in the Security Overview. Both providers are contracted on no-training terms for the content we send them — neither may use it to develop its own models. Merdial does improve its own models on de-identified transcripts; what that means, and how to opt out, is in Privacy §5.

Business operations

Sub-processorWhat it doesData it touchesLocation
Polar Software, Inc.Merchant of record. Takes payment, issues invoices, handles sales tax and refunds.Billing contact, company details, payment instrument, transaction records. Card numbers never reach Merdial.United States (Delaware)
ipifyReturns the device’s own public IP address at sign-in, so brute-force protection and IP blocking can work.IP address. Nothing else, and no account identifier is sent with the lookup.United States

What is not on this list

There is no advertising network, no data broker, no session-replay vendor and no third-party analytics on the product surfaces. Transactional email is sent through Supabase rather than a separate email platform. If a vendor is not named above, it does not process customer personal data.

Questions

Sub-processor objections, region-pinning requests and vendor due-diligence packs: team@merdial.com. This list is current as of 6 September 2026.