Theona

Sub-Processors

Third-party services we use to deliver Theona, with full transparency on data processing

Last updated: 23 September 2026

This page lists all third-party sub-processors that Theona, Inc. uses to provide the Services. We require all sub-processors to comply with applicable data protection laws, including GDPR and CCPA, through Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs).

Infrastructure & Hosting

Supabase

View DPA →

Database hosting, authentication, backend infrastructure

Data Processed:All user data, authentication credentials, application data📍 United States

Application hosting and Redis infrastructure

Data Processed:Application runtime data, job queues, caching📍 United States

Cloudflare

View DPA →

Content delivery network, DDoS/WAF protection, DNS and TLS termination

Data Processed:IP address, request metadata📍 United States

Google Workspace

View DPA →

Identity provider for Theona staff accounts, support mailbox, and document storage

Data Processed:Email addresses, support correspondence, contract documents📍 United States

AI & Large Language Model Providers

AI chat, content generation, task automation

Data Processed:User prompts, chat messages, context data (zero-retention API)📍 United States

Anthropic

View DPA →

Claude LLM for advanced reasoning and conversational AI

Data Processed:User prompts, chat messages, context data (not used for training)📍 United States

Google AI (Gemini)

View DPA →

Conversation summarization and compression

Data Processed:Chat history for summarization (not retained by Google)📍 United States

OpenRouter

View DPA →

Routes requests to various LLM providers for model flexibility and fallback

Data Processed:User prompts, context data (not used for model training)📍 United States

Payment Processing

Payment processing, subscription management, billing

Data Processed:Email, user ID, payment methods, transaction history📍 United States

Analytics & Monitoring

Google Analytics (GA4)

View DPA →

Website traffic analysis (marketing website only)

Data Processed:Anonymized page views, visitor behavior, traffic sources (no PII)📍 United States

Product analytics (application only)

Data Processed:User ID, email, usage events, session data (partially masked)📍 United States

Error monitoring and performance tracking

Data Processed:Sanitized error logs (no PII, no request bodies)📍 United States

Langfuse

View DPA →

LLM observability and tracing for debugging and quality monitoring

Data Processed:Prompts, completions, metadata from AI interactions📍 United States

LinkedIn

View DPA →

Insight Tag for campaign measurement, loaded only after analytics consent is given

Data Processed:IP address, page views, browser metadata📍 United States

Integration Framework

Third-party integration management, OAuth connections

Data Processed:User ID, tool execution arguments (no raw user content)📍 United States

Microsoft (Bot Framework)

View DPA →

Message delivery for the Theona bot in Microsoft Teams

Data Processed:Message content, conversation and participant identifiers📍 United States

Data Extraction

Web scraping and content extraction

Data Processed:URLs and extracted web page content (as requested by user)📍 United States

LinkedIn data extraction and web automation

Data Processed:Public profile data, search results (as requested by user)📍 EU (Czech Republic)

People and company enrichment, run on a Theona-managed account rather than your own connection

Data Processed:Names, work email addresses and employment data of the people being enriched (as requested by user)📍 United States

Email

Transactional email delivery

Data Processed:Email address, email content (notifications, account alerts)📍 United States

Marketing Communications

Mailchimp

View DPA →

Marketing email communications to opted-in users

Data Processed:Email address📍 United States

Internal Communications

Theona staff communication, and operational alerts about account events and agent quality

Data Processed:User ID, organisation and agent names, evaluation summaries (email addresses and phone numbers removed before sending), and customer details discussed by staff in support and engineering conversations📍 United States

Meeting Recording

Meeting recording and transcription

Data Processed:Meeting audio, transcripts, participant metadata (as authorized by user)📍 United States

Wallet Passes

Google Wallet

View DPA →

Adding a generated pass to Google Wallet, when you choose to save one

Data Processed:The contents of the pass, sent to Google by your browser when you save it📍 United States

Apple Wallet passes are built and signed by Theona and delivered to your device directly. Apple receives nothing from us, so it is not listed above.

User-Authorized Integrations

When you connect third-party services to your Theona account, data flows between Theona and those services subject to their respective privacy policies. Theona supports 60+ integrations across the following categories:

Communication: Slack, Microsoft Teams, Discord, Telegram, WhatsApp Business
Project Management: Linear, Asana, Jira, Notion, Trello, Monday, Todoist
CRM: HubSpot, Salesforce, Pipedrive, Apollo, Attio
Google Workspace: Gmail, Calendar, Drive, Docs, Sheets
Microsoft 365: Outlook, OneDrive, Teams
Development: GitHub, Bitbucket
Design: Figma, Webflow
HR: BambooHR, Lever, Recruitee, Talantix
Support: HelpScout, Zendesk, Intercom
Social & Content: LinkedIn, YouTube, Reddit
Storage: Dropbox, Google Drive, OneDrive
Other: Shopify, Looker, Confluence, YouTrack

For a complete and up-to-date list of supported integrations, visit theona.ai/integration. Each integration accesses only the data you explicitly authorize.

Data Protection Measures

All sub-processors are required to:

  • •Implement appropriate technical and organizational security measures
  • •Process data only as instructed by Theona
  • •Maintain confidentiality of personal data
  • •Comply with GDPR, CCPA, and other applicable data protection laws
  • •Execute Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) where required
  • •Notify Theona of any data breaches without undue delay

International Data Transfers

When sub-processors are located outside the European Economic Area (EEA) or United Kingdom, we implement appropriate safeguards including:

  • •Standard Contractual Clauses (SCCs) approved by the European Commission
  • •Adequacy decisions for countries deemed to have adequate data protection
  • •Additional safeguards such as encryption in transit and at rest

Updates to This List

We maintain this page to reflect our current sub-processors. Where practicable, we will notify users of material changes at least 30 days in advance via email. Emergency changes required for security, legal compliance, or service continuity may be implemented with shorter notice. You can also subscribe to updates via our changelog.

Contact Us

If you have questions about our sub-processors or data processing practices, contact us:

Theona, Inc.

Email: [email protected]

For more information, see our Privacy Policyand Terms of Service.