Our AI agent can ring you back now.Get a call back
Sub-processors

Who else handles your data, and when

Running a voice or chat agent takes more than one company: someone hosts it, a model decides what to say, speech vendors hear and speak, and carriers connect the call. This page names each company that does part of that work for us, what it sees, where, and when it is involved. It is the list our Data Processing Agreement refers to.

Last updated 19 September 2026

In short
  • Two companies are always involved: Amazon Web Services, which hosts the whole platform in Frankfurt, and Google, whose Gemini models run on every workspace and are not pinned to the EU.

  • The rest are involved only when something calls for them: a phone number on an account we manage, a particular voice or language, a channel, or a model we have switched on.

  • A vendor you bring your own account for works for you, not for us, and is not our sub-processor. Bringing your own does not take ours out of the path entirely. Section 05 explains.

  • Our WhatsApp features run on a Meta app and business accounts registered to Aikolumi Software Pvt Ltd, which operates them for Mirakash. WhatsApp is not yet available to customers.

  • We give 30 days' notice before adding or replacing a sub-processor, and you can object.

  • To be told about changes, ask through the form at /contact. Every change is also dated in the changelog at the bottom of this page.

01

What a sub-processor is

When your agents talk to people, you decide what happens to what they say. For that data you are the controller, and we are your processor: we handle it only to run the Service for you, under our Data Processing Agreement.

A sub-processor is another company we engage to process that data for us. This page is the complete list of them. It covers the personal data in your workspace:

  • what callers, customers and contacts say to your agents, and what the agents say back: call audio, recordings, transcripts, chat and text messages;
  • their phone numbers and other contact details, and the records of each call and message;
  • anything your agents' tools fetch or send during a conversation;
  • the documents you add to a knowledge base, where they contain personal data;
  • the names, email addresses and sign-in records of the people who use your console.

It does not cover vendors you bring your own account for (section 05), or the vendors we use for our own website and business (section 06).

Mirakash is a brand of Naridon, Inc., a corporation incorporated in Delaware, USA, which is the party to your contract with us.

02

Always involved

These two process data for every workspace, whatever you configure.

Sub-processors that are always involved
CompanyPurposePersonal dataWhereWhen it is used
Amazon Web ServicesHosting the Service: the servers, the database, recording storage, logs, and the email the console sends (sign-in confirmations, password resets, invitations).Everything the Service stores, including recordings, transcripts, messages, call records, contact details, knowledge-base documents and your console users' details.EU: eu-central-1 (Frankfurt, Germany)Always.
Google (Gemini API)Our default AI model. On native-audio voice agents it hears the caller and speaks the reply. It also writes replies on chat and text turns, summarises and scores finished conversations, powers agent assist, and indexes knowledge bases for search, either first or as the fallback when another model fails.Call audio on native-audio agents; transcripts, chat and message text; your agents' instructions and what their tools return during a conversation; the text of knowledge-base documents when they are indexed.Not pinned to a region. May process outside the EEA.Always. Which work reaches it first depends on how your agents and our model settings are configured, and it is the fallback for voice and text when other vendors are unavailable.

03

Involved only when something calls for them

Each vendor below processes your data only when the condition in its last column is met. A text-only chat agent, for example, involves no carrier and no speech vendor at all. Some of these are wired in as options and fallbacks and rarely carry traffic. They are listed anyway, so that the list covers every vendor the platform can route your data to.

Two things move data between vendors in these tables without you choosing a new one. If a speech vendor fails during a call, the call continues on the next available vendor so the sentence is finished; and if a language model fails, the next one in line answers. Both only ever move to vendors on this page.

Calls and text messages

Carriers and messaging sub-processors
CompanyPurposePersonal dataWhereWhen it is used
PlivoPhone calls, phone numbers and SMS, and registering numbers and senders where a country requires it.Call audio as it is carried; the phone numbers at both ends; call and message records; SMS content. For registration: your business details, a named contact's name, email address, phone number and job title, and the identity and business documents the country requires.May process outside the EEA. Calls also cross the telephone networks of the countries they connect.When your calls, numbers or text messages run on a carrier account Mirakash manages for you, rather than your own.
TwilioThe same as Plivo. On calls using Twilio's ConversationRelay, Twilio also turns the caller's speech into text and the agent's text into speech.As for Plivo; on ConversationRelay calls, also call audio and the text the agent speaks.May process outside the EEA. Calls also cross the telephone networks of the countries they connect.When your calls, numbers or text messages run on a Twilio account Mirakash manages for you, rather than your own.
Meta Platforms (WhatsApp Business Platform)Sending and receiving WhatsApp messages, and Instagram and Messenger messages.Message content and media; the other person's WhatsApp number or account identifier and profile name; delivery records; your business name, number and message templates.May process outside the EEA.When you connect WhatsApp, Instagram or Messenger. Not yet available to customers: see section 04.
Aikolumi Software Pvt LtdHolds and operates, for Mirakash, the Meta business account, the WhatsApp Business Account and the Meta app that our WhatsApp features run on.The details of a WhatsApp Business Account that you give the Mirakash Meta app access to when you connect it.IndiaWhen you connect WhatsApp. Not yet available to customers: see section 04.

Trial calls to the test numbers you verify also run on Mirakash's own carrier account. Between our carrier and the person at the other end, a call or text may also cross other telephone networks, as every call does. The carriers choose those networks, not us, and they are not listed here.

Speech

Pipeline voice agents use one vendor to turn the caller's speech into text and another to speak the reply. Native-audio agents use Google for both and involve none of these.

Speech sub-processors
CompanyPurposePersonal dataWhereWhen it is used
DeepgramSpeech to text and text to speech.Call audio: the caller's voice and anything said on the call; the text the agent speaks, which can include details from the conversation.May process outside the EEA.Pipeline agents set to Deepgram, and as a fallback when another speech vendor fails.
CartesiaSpeech to text and text to speech, and making a custom voice from recordings.Call audio: the caller's voice and anything said on the call; the text the agent speaks, which can include details from the conversation; the voice recordings you upload to create a custom voice.May process outside the EEA.Agents set to Cartesia, voices you create with it, and as a fallback.
Sarvam AISpeech to text and text to speech, mainly for Indian languages.Call audio: the caller's voice and anything said on the call; the text the agent speaks, which can include details from the conversation.May process outside the EEA.Agents set to Sarvam, and as a fallback.
ElevenLabsText to speech, and making a custom voice from recordings.The text the agent speaks, which can include details from the conversation; the voice recordings you upload to create a custom voice.May process outside the EEA.Agents set to ElevenLabs, voices you create with it, and as a fallback.
AssemblyAISpeech to text.Call audio: the caller's voice and anything said on the call.May process outside the EEA.Pipeline agents set to AssemblyAI, and as a fallback.
GladiaSpeech to text.Call audio: the caller's voice and anything said on the call.May process outside the EEA.Pipeline agents set to Gladia, and as a fallback.
RimeText to speech.The text the agent speaks, which can include details from the conversation.May process outside the EEA.Pipeline agents set to Rime, and as a fallback.
LMNTText to speech.The text the agent speaks, which can include details from the conversation.May process outside the EEA.Pipeline agents set to LMNT, and as a fallback.
PlayHTText to speech.The text the agent speaks, which can include details from the conversation.May process outside the EEA.Pipeline agents set to PlayHT, and as a fallback.

Language models

These depend partly on our settings rather than yours: when we have one of them switched on, it can take text replies and analysis ahead of Google, with Google as the fallback.

Language model sub-processors
CompanyPurposePersonal dataWhereWhen it is used
AnthropicWriting agent replies on chat, text and pipeline voice turns; summarising, analysing and scoring conversations.Transcripts, chat and message text; your agents' instructions and what their tools return during a conversation.May process outside the EEA.When we have it switched on. It then runs first on this work.
OpenAIThe same work as Anthropic; text to speech for agents set to its voices; indexing knowledge bases for search.As for Anthropic; the text the agent speaks; the text of knowledge-base documents when they are indexed.May process outside the EEA.Models and indexing: when we have it switched on. Speech: agents set to OpenAI voices, and as a fallback.
Microsoft (Azure OpenAI Service)Writing replies and analysing conversations for agents set to use it.As for Anthropic.May process outside the EEA.Only for agents you set to the Azure OpenAI option.

04

WhatsApp, Meta and Aikolumi

WhatsApp on Mirakash is being set up and is not yet available to customers. It is listed now so that the list is already right on the day it goes live.

When you connect WhatsApp, you do it in Meta's own sign-up window: you choose or create your WhatsApp Business Account and number, and grant the Mirakash Meta app access to it. The account stays yours.

That Meta app, together with the Meta business account and the WhatsApp Business Account that Mirakash's own WhatsApp features run on, is registered to Aikolumi Software Pvt Ltd (India), which operates them for Mirakash.

The messages themselves travel between Meta and our servers on AWS in Frankfurt: Meta delivers incoming messages to our servers, and our servers send replies to Meta. They do not pass through any system that Aikolumi runs separately.

05

Vendors you bring are not our sub-processors

You can run parts of the Service on your own accounts with other vendors. When you do, that vendor works for you under your own contract with it. It is your processor, not our sub-processor, and it is not on this list. That includes:

  • your own model, speech, knowledge-base indexing or avatar vendor accounts, connected in the console's settings;
  • your own Twilio or Plivo account, SIP trunk or SIM gateway for calls and numbers;
  • messaging accounts you connect yourself, such as Telegram, Slack, Microsoft Teams or Discord, or your own Meta, Twilio or Plivo credentials;
  • the systems your agents' tools, webhooks, connectors and MCP servers call;
  • your own storage bucket for recordings, if you set one;
  • the security tool you stream your audit log to.

We send those vendors what your configuration tells us to send, and nothing else. You choose them and you are responsible for your arrangement with them.

Bringing your own account moves one leg, not the whole call. If you bring your own speech-to-text account, the model and the voice still run on the vendors above. And it is not a hard fence:

  • if your speech vendor fails during a call, the call can continue on a speech vendor listed above, on our account;
  • if we cannot fetch your key when a call starts, that call runs on our accounts;
  • if your own knowledge-base indexing account fails, search falls back to ours.

There is no setting today that switches those fallbacks off for a workspace. If you need that, tell us through /contact before you rely on it.

06

Our own website and business

Some vendors process personal data for Mirakash's own purposes rather than for you. For that data we are the controller, so those vendors are not your sub-processors. Our privacy policy covers them:

  • Google Analytics, on mirakash.com, and only if a visitor accepts analytics cookies;
  • Amazon Web Services, which serves mirakash.com and keeps its access logs;
  • the Mirakash Guide assistant and the public demo call on mirakash.com, which run on this same platform and the vendors above, for our own purposes;
  • Stripe, when we take payment through it: it receives your billing contact and payment details, and none of your conversations.

07

How we choose and bind them

Before a vendor handles customer data, we look at what it does with the data, where it processes it, and how it secures it. We use the protective settings a vendor offers where we have them wired in: every request we send to Deepgram, for example, carries its opt-out from its model-improvement programme.

Each sub-processor is bound by a written contract with data-protection terms that protect your data at least as well as our Data Processing Agreement requires of us, and we remain responsible to you for its work.

The Where column in each table says which vendors may process your data outside the European Economic Area.

We have no business associate agreement (BAA) with any vendor on this list, and we do not sign BAAs with customers today. Protected health information must not be processed on Mirakash.

08

How we tell you about changes

We give at least 30 days' notice before a new sub-processor starts processing your data, or before we replace one. The notice goes on this page, with a dated entry in the changelog below, and to every customer who has asked to be told.

To be told: use the form at /contact(the topic “Notify me of sub-processor changes” is chosen for you) and give your company name. We will send each notice to the email address you give.

Moving your traffic between vendors already on this page, for example when a call fails over to the next speech vendor, is not a change to the list.

09

Objecting to a change

If you have a reasonable objection, on data-protection grounds, to a new or replacement sub-processor, tell us through /contact within the notice period. Say which vendor and why.

We will work through it with you. There is often a way round: many rows on this page apply only if you choose that vendor, voice, language or channel, and you can move a leg onto your own vendor account (section 05). There is no switch today that removes one listed vendor from the fallback paths for a single workspace, so an objection is handled by talking to us.

If we cannot resolve it, you may end the part of the Service that depends on the new sub-processor, as set out in the Data Processing Agreement.

10

Emergency replacements

If a sub-processor fails, stops providing its service, or becomes a risk to the security of your data, we may need to replace it sooner than 30 days allow. When that happens we will tell you as soon as we reasonably can, and you keep the same right to object.

11

Affiliates

You contract with Naridon, Inc. The one other company that operates part of Mirakash is Aikolumi Software Pvt Ltd (India), which holds the Meta accounts behind our WhatsApp features for Mirakash (section 04), and is in the table in section 03 for that reason.

WhatsApp messages do not pass through any system that Aikolumi runs separately; they travel between Meta and our servers on AWS.

12

See it for your own workspace

Signed in to the console, Settings, HIPAA & PCI scope has a Subprocessors panel for your own workspace. It lists the model vendors named on your finished conversations, the speech vendors your agents are set to use, and the carriers behind your phone numbers.

It is narrower than this page. For speech it shows what your agents are set to use, not a vendor a call failed over to, and it does not show which vendor indexed your knowledge base. This page is the full list.

13

Changelog

  • 19 September 2026: initial publication.