Sub-processors

Last updated 27 August 2026

The companies that process data on Woise's behalf, what each one does, and whether it applies to every account or only to accounts that enable it.

Woise is assembled from specialist services. Some handle every account; most are chosen per agent, so the set that actually touches your data depends on how you have configured Woise. Both cases are marked below, because a flat list would name vendors that most customers never enable.

Notice of changes

Before a new sub-processor starts processing customer data we will give account holders […notice period, typically 30 days…] notice by email, and update this page. If you object within that period we will work with you on an alternative, and if none is workable you may terminate the affected service without penalty.

[…This notice mechanism is not yet wired up.…] Transactional email is not currently configured on this deployment, so the commitment above cannot be honoured automatically today. Until it is, check this page, whose date changes whenever the list does.

Current sub-processors

Infrastructure

ProviderPurposeApplies to
Amazon Web ServicesHosting, databases and object storage for the platform and for stored call artefacts.All accounts

Identity

ProviderPurposeApplies to
Stack AuthAccount authentication and session management.All accounts

Payments

ProviderPurposeApplies to
StripeSubscription and usage billing. Card details go to Stripe directly and are never stored by Woise.All accounts

Error monitoring

ProviderPurposeApplies to
SentryCrash and error reports so faults can be diagnosed. Technical context only, not call content.All accounts

Product analytics

ProviderPurposeApplies to
PostHogWhich pages and features get used in the dashboard. Runs only where the visitor has accepted analytics cookies.With consent

Telephony

ProviderPurposeApplies to
TwilioCarrying calls to and from the public telephone network.If configured
TelnyxCarrier for managed numbers and call delivery.If configured
PlivoCarrier for call delivery in some regions.If configured

Speech to text

ProviderPurposeApplies to
DeepgramTranscribing call audio in real time.If configured
Sarvam, CartesiaAlternative transcription engines, used where an agent selects one.If configured

Text to speech

ProviderPurposeApplies to
CartesiaGenerating the agent’s voice.If configured
ElevenLabs, Rime, CambAlternative voice engines, used where an agent selects one.If configured

Language models

ProviderPurposeApplies to
OpenAIGenerating the agent’s replies, where an agent is configured to use it.If configured
Google, Groq, AWS Bedrock, OpenRouter, AzureAlternative model providers, used where an agent selects one.If configured

Integrations

ProviderPurposeApplies to
ComposioHolds the authorisation for third-party tools you connect, such as a CRM or calendar, so Woise never stores those credentials itself.If configured

Where they are

[…Name the processing locations for each sub-processor, and the transfer mechanism relied on for each one that processes outside the UK, EEA or India. This is the section a customer's data protection officer reads first, and a vague answer here is what stalls a procurement review.…]

Related documents

The Privacy Policy explains what is processed and why. The Data Processing Addendum is the contract that governs it.