Sub-processor List

1. Introduction

Lenera AI Inc. ("Lenera AI," "we," or "us") engages certain third-party service providers ("sub-processors") to process personal data on behalf of our customers in connection with the delivery of our AI video platform and related services. This document lists all current sub-processors, the categories of personal data each processes, and the applicable security certifications.

This sub-processor list forms an annex to the Lenera AI Data Processing Agreement ("DPA"). Capitalised terms not defined here have the meanings given in the DPA.

2. What is a Sub-processor?

A sub-processor is any third party that processes personal data on our behalf to provide the Service. Sub-processors do not include:

  • Third-party tools accessed independently by Customers (not part of Service delivery);
  • Providers used only for anonymised or aggregate data;
  • Professional service providers (e.g., legal counsel) who do not access personal data in the course of their engagement; or
  • Providers used purely for Lenera AI's internal business operations that do not process Customer personal data.

3. Current Sub-processor List

The table below lists all current sub-processors as of the "Last Updated" date above, organised by functional category.

Cloud Infrastructure & Hosting

Amazon Web Services (AWS)

Purpose
Cloud infrastructure, compute, storage, and networking
Data Processed
All Customer Data (encrypted at rest and in transit); system logs
Location
USA (us-east-1, us-west-2); EU (eu-west-1) — Customer-selectable data residency
Security Certification
SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, CSA STAR, FedRAMP

Vercel

Purpose
Front-end application hosting and edge delivery
Data Processed
Session tokens, request metadata; no Customer Content stored
Location
USA / Global CDN
Security Certification
SOC 2 Type II

Render

Purpose
Back-end API service hosting
Data Processed
API request/response data; Customer Data in transit only
Location
USA (Oregon)
Security Certification
SOC 2 Type II (in progress)

Supabase

Purpose
Database (PostgreSQL), authentication, and real-time data services
Data Processed
Customer account data, project metadata, platform configuration
Location
USA (AWS us-east-1); EU option available
Security Certification
SOC 2 Type II, GDPR-compliant DPA available

AI & Media Processing

Anthropic (Claude)

Purpose
Large language model API for script generation and content assistance
Data Processed
Prompts and script content submitted by users; no Customer PII transmitted without explicit user action
Location
USA
Security Certification
SOC 2 Type II; GDPR DPA available; no training on customer inputs by default

DeepSeek

Purpose
AI model API for supplemental language tasks
Data Processed
Text prompts; no Customer PII transmitted without explicit user action
Location
China (data processed via API; Lenera AI does not store DeepSeek outputs beyond session)
Security Certification
See DeepSeek Privacy Policy; customers in regulated industries should review prior to use

D-ID

Purpose
AI avatar rendering and video synthesis (avatar animations, talking-head generation)
Data Processed
Script text; uploaded reference images/video where custom avatar feature is used
Location
Israel / USA (AWS)
Security Certification
SOC 2 Type II; GDPR DPA available

Google Cloud Text-to-Speech (Google TTS)

Purpose
AI voice synthesis for narration generation
Data Processed
Script text submitted for voice rendering
Location
USA / Global (Google Cloud regions)
Security Certification
ISO 27001, SOC 2 Type II, SOC 3; GDPR DPA available

Remotion Lambda

Purpose
Serverless video rendering and composition (AWS Lambda-based)
Data Processed
Composition data, rendered frame assets; temporary processing only
Location
USA (AWS Lambda)
Security Certification
Inherits AWS security certifications; no persistent data storage

Identity & Access Management

WorkOS

Purpose
Enterprise SSO, Directory Sync (SAML, OIDC, SCIM), and Admin Portal
Data Processed
User identity data: email, name, SSO attributes, directory sync records
Location
USA
Security Certification
SOC 2 Type II, GDPR DPA available

Payments & Finance

Stripe

Purpose
Payment processing and subscription billing
Data Processed
Payment card data (PCI DSS scope; Lenera AI does not store full card numbers), billing address, transaction records
Location
USA / Global
Security Certification
PCI DSS Level 1, SOC 2 Type II

Airwallex

Purpose
International payment processing and currency conversion
Data Processed
Bank account details, payment transaction data
Location
Australia / Global
Security Certification
PCI DSS, SOC 1 Type II, SOC 2 Type II

Customer Communications & Marketing

ActiveCampaign

Purpose
Email marketing, CRM, and marketing automation
Data Processed
Customer contact data: name, email, marketing preferences, email engagement metrics
Location
USA
Security Certification
SOC 2 Type II, GDPR DPA available

Calendly

Purpose
Meeting scheduling and calendar integration
Data Processed
Contact name, email, calendar availability data
Location
USA
Security Certification
SOC 2 Type II, GDPR DPA available

Analytics & Monitoring

Contentsquare

Purpose
Digital experience analytics (session replay, heatmaps, journey analysis) — Website only
Data Processed
Anonymised/pseudonymised interaction data (mouse movements, clicks, scroll depth); no Customer Content
Location
France / USA
Security Certification
ISO 27001, SOC 2 Type II, GDPR DPA available

Google Analytics 4 (GA4)

Purpose
Website traffic analytics and user behaviour — Website only, not in-Service application
Data Processed
Anonymised device/browser data, page views, session data; IP anonymisation enabled
Location
USA / Global
Security Certification
ISO 27001; GDPR DPA available; no advertising features enabled

Sales & Customer Support

Pipedrive

Purpose
Sales CRM and pipeline management
Data Processed
Prospect and Customer contact data: name, email, company, deal details
Location
Estonia / USA
Security Certification
ISO 27001, SOC 2 Type II, GDPR DPA available

Pylon

Purpose
Customer support and in-app messaging
Data Processed
Support ticket data: name, email, conversation content
Location
USA
Security Certification
SOC 2 Type II (in progress)

Slack

Purpose
Internal team communication (Lenera AI staff only; not used for Customer data processing)
Data Processed
Internal operational communications; Customer data shared only in exceptional support escalations with Customer consent
Location
USA
Security Certification
SOC 2 Type II, ISO 27001, GDPR DPA available

Document & E-Signature

SignEasy (Glide)

Purpose
Electronic signature and document execution
Data Processed
Signer name, email, IP address, signature image; signed document content
Location
USA
Security Certification
SOC 2 Type II, GDPR DPA available

4. Sub-processor Updates and Notifications

Lenera AI periodically reviews and updates its sub-processor list as our services and infrastructure evolve. We are committed to transparency and will:

  • Provide at least thirty (30) days' prior written notice (by email to the Customer's registered contact address, or via the in-platform notification centre) before adding a new sub-processor or making a material change to an existing sub-processor's role or data processing scope;
  • Maintain an up-to-date version of this sub-processor list at lenera.ai/legal/subprocessors;
  • Log the effective date of each change in the version history; and
  • Promptly notify Customers if a sub-processor suffers a material security incident affecting Customer personal data.

5. Objection Process

If a Customer reasonably objects to Lenera AI's use of a new or changed sub-processor on grounds that the change materially impairs the Customer's ability to comply with applicable data protection law, the Customer must:

  • Submit a written objection to support@lenera.ai within thirty (30) days of receiving the notice;
  • Identify the specific sub-processor and the legal or compliance concern; and
  • Engage in good faith discussions with Lenera AI to explore alternative arrangements.

If Lenera AI cannot reasonably accommodate the objection within thirty (30) days of receiving it (e.g., by using an alternative sub-processor or modifying processing), the Customer may, as its sole and exclusive remedy, terminate the affected Service upon written notice, and Lenera AI will refund any prepaid, unused fees on a pro-rata basis.

6. International Data Transfers

Where a sub-processor processes personal data outside the European Economic Area, the United Kingdom, or other jurisdictions with adequacy decisions, Lenera AI ensures appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission (Module 3: Processor-to-Processor);
  • The UK International Data Transfer Addendum (UK IDTA) for UK data;
  • Swiss-specific transfer mechanisms where applicable; and
  • Sub-processor adherence to the EU-U.S. Data Privacy Framework (DPF) where certified.

Specific transfer mechanisms in place for each sub-processor are available upon written request to support@lenera.ai.

7. Contact

For questions about this sub-processor list or to submit an objection, please contact:

Privacy Team — Lenera AI Inc.
support@lenera.ai
28 Geary St STE 650 Suite #620, San Francisco, California 94108, United States

Last updated: June 2026