Leva·TermsPrivacyCookiesSub-Processors

Sub-Processors

Last updated: 19 May 2026

We use the following sub-processors to deliver the Leva service. All are bound by data processing agreements. We will update this page at least 30 days before adding a new sub-processor. To object to a new sub-processor, contact privacy@getleva.ai.

Sub-ProcessorPurposeData ProcessedJurisdictionTransfer Safeguard
SupabaseDatabase, authentication, file storage, and encrypted secrets vaultAll user and tenant data; OAuth tokens in encrypted vault; uploaded brand assetsEU West (Ireland)UK adequacy regulations / EU SCCs
VercelApplication hosting, CDN, edge functions, analyticsRequest logs, page views (anonymised analytics), application code executionUSA (global CDN)SCCs + UK adequacy
AnthropicLarge language model inference — all AI agent tasksBusiness data, goals, drafts, and context submitted in LLM promptsUSASCCs + Anthropic API DPA (no training on customer data)
PortkeyLLM gateway routing all Anthropic and OpenAI calls; cost observabilityAll LLM prompts and responses (same data as Anthropic/OpenAI entries above)USASCCs + Portkey DPA
OpenAIImage generation (DALL-E 3)Ad creative briefs and image generation promptsUSASCCs + OpenAI API DPA (no training on customer data)
fal.aiAI video generationVideo generation prompts and generated video outputsUSASCCs + fal.ai DPA
StripePayment processing, subscription managementPayment method details, transaction records, billing contact informationUSA / UK (Stripe Payments Europe Ltd)SCCs + UK adequacy; PCI-DSS certified
ResendTransactional email delivery (notifications, board reports, billing emails)Email addresses, email contentUSASCCs + Resend DPA
UpstashRedis rate limiting and QStash background job schedulingTenant IDs and job metadata (no personal data beyond IDs)USA (EU region option available)SCCs + Upstash DPA
ComposioOAuth aggregator for third-party integrations (Gmail, HubSpot, LinkedIn, etc.)OAuth access tokens; tool call payloads when agents act on connected servicesUSASCCs + Composio DPA; SOC 2 Type II certified
InstantlyCold email campaign sending and reply managementProspect email addresses, email content, reply dataUSASCCs + Instantly DPA
HeyReachLinkedIn outreach draft sequences (draft-only — never auto-sent)LinkedIn profile data for prospects, draft message contentUSASCCs + HeyReach DPA
CloudflareCAPTCHA and bot protection (Turnstile) on account creationIP address, browser fingerprint for bot detection (not stored by Leva)USA (global)SCCs + Cloudflare DPA

Note on third-party integrations you connect:when you connect external platforms (Gmail, HubSpot, Meta Ads, LinkedIn, etc.) via Leva's integration settings, those platforms also process your data under their own terms. They are not sub-processors of Leva — they are services you have authorised Leva to connect to on your behalf.