Skip to content
shuffl

Version 1.4 · Effective

Subprocessors

A subprocessor is a company Shuffl relies on that may process personal information from an employer’s workspace to provide its part of the service. This page lists them, as the Data Processing Addendum describes.

Current subprocessors

Shuffl uses these subprocessors today. Each one processes information only to provide its service to Shuffl, under Shuffl’s instructions and a written agreement with Shuffl.

  • VercelApplication runtime: United States (Northern California). AI gateway: processing region is not restricted.

    Hosting and application delivery, which processes every request to the service, and the AI gateway that routes questions to a model provider, knowledge text to an embedding provider, and messages and chat excerpts to a decision model to classify questions, handle corrections and find related chats.

  • SupabaseUnited States (Northern California)

    The managed PostgreSQL database that holds each workspace’s records.

  • AnthropicAI inference region is not restricted by Shuffl.

    The model provider currently configured behind the gateway, which composes an answer from the question and the knowledge retrieved for it.

  • Microsoft AzureAI inference region is not restricted by Shuffl.

    Hosts the OpenAI text-embedding-3-small model reached through the Vercel AI Gateway with zero-data-retention routing. It creates search embeddings from published Knowledge text and questions so knowledge can be found by meaning as well as by wording.

  • xAIAI inference region is not restricted by Shuffl.

    The image model (Grok Imagine), reached through the Vercel AI Gateway, which draws pictures people ask for with “Create with Mello” from the supplied name, description and optional idea. Each request asks the gateway to select a provider with a no-retention agreement; that request does not establish the deletion of every copy held by Shuffl or its service providers.

  • TypeSafe AIAI inference region is not restricted by Shuffl.

    The decision model (Jev), reached through the Vercel AI Gateway, which classifies the latest message of a question, including whether it is sensitive or an attempt to manipulate the assistant. It also compares an earlier and a new Slack message to decide whether the new one changes direction, and receives search text with the titles and short opening-message excerpts of chats the person can access to find related chats. Each request asks the gateway to select a provider with a no-retention agreement.

  • ResendUnited States (Northern Virginia)

    Email delivery for invitations, verification, notifications, Shuffl’s replies to support conversations, and sales inquiries from the contact sales form to Shuffl’s sales mailbox.

  • Google WorkspaceUnited States and other Google data centers

    Email hosting for Shuffl’s own mailboxes, including the sales mailbox where contact sales inquiries arrive and are answered, and the mailboxes where Shuffl staff receive notice of new support conversations.

  • SlackUnited States

    Where a workspace has connected it: the assistant, HR delivery and directory synchronisation.

  • StripeUnited States

    Payment processing where fees apply. It receives billing identifiers and never workspace content.

  • PostHogUnited States

    Product analytics: content-free product events tied to an account and workspace id, browser analytics subject to the browser’s choice, workspace-level counts of how the Slack app is used, and content-free server error reports.

Where they process it

The application runtime and database run in Northern California, and email delivery is configured in Northern Virginia. The AI gateway’s processing region is not restricted, and Shuffl does not restrict AI inference to a particular region. AI requests may therefore be processed outside the United States; the provider table distinguishes those routes from the application and database.

Where information comes from outside the United States, Shuffl relies on the Standard Contractual Clauses, as the Data Processing Addendum describes, and requires the same of these providers.

How Shuffl chooses them

Shuffl uses a provider only where the service needs it, gives it only the information its part of the service needs, and binds it to data-protection obligations that protect workspace information at least as well as the Data Processing Addendum. Shuffl remains responsible to the employer for what its subprocessors do.

Notice of changes

Before a new subprocessor starts processing workspace information, Shuffl updates this page and tells workspace administrators by email at least 30 days in advance, unless a change has to be immediate to keep the service safe or lawful. The date at the top of this page says when the list last changed.

Objecting to a change

An employer may object to a new subprocessor on reasonable data-protection grounds by writing to Shuffl within the notice period. What happens next is set out under “Subprocessors” in the Data Processing Addendum.

Contact

Questions about this list go to privacy@shuffl.ai.