| Meta Platforms Ireland Ltd (WhatsApp Business Platform, Messenger Platform, Instagram Messaging API) | Delivery and receipt of messages on the channels the Customer connects | Message content and media in both directions; Contact phone numbers / platform IDs and profile names; GPS coordinates in location messages; Customer Data values the Customer interpolates into template messages; phone-book and history import under Section 4.4 | Ireland / USA | EU–US Data Privacy Framework; Meta's SCCs. Note: Meta acts as an independent controller for parts of this processing under its own terms. |
| Amazon Web Services EMEA SARL (EC2, S3) | Hosting of the application servers and the PostgreSQL database; storage of files, media, voice notes, exports and encrypted backups | All Customer Data | Ireland (eu-west-1) | Hosted in the EEA; AWS Data Processing Addendum |
| MongoDB, Inc. (Atlas) | Managed database for objects, conversations, notes, activity logs | All Customer Data except relational account records | Ireland (AWS eu-west-1) | Hosted in the EEA; MongoDB Data Processing Agreement |
| Pusher Ltd (Channels) | Real-time delivery of updates to the Customer's browser sessions | Transient: new-message notifications carrying message content and the sender's name/avatar; record-change events. Not stored beyond delivery. | Ireland (EU cluster) | Hosted in the EEA; Pusher DPA |
| Google LLC — Maps Platform | Rendering a map for a Contact's shared location | GPS coordinates of a location message, sent from the user's browser to Google when the map is opened | USA | EU–US Data Privacy Framework; Google Cloud DPA |
| Google LLC — OAuth | Optional sign-in of the Customer's users with a Google account | User email and profile — user data, Section 2.2, not Customer Data; listed for completeness | USA | as above |
| Browser push services (Google FCM, Mozilla, Apple) via Web Push | Delivering desktop notifications to the Customer's users who opted in | Transient notification payloads: Contact name and a message preview | USA | The push endpoint is chosen by the user's browser vendor; payloads are encrypted end-to-end (RFC 8291) so the service cannot read them |