Sub-processor List
1. Introduction
Lenera AI Inc. ("Lenera AI," "we," or "us") engages certain third-party service providers ("sub-processors") to process personal data on behalf of our customers in connection with the delivery of our AI video platform and related services. This document lists all current sub-processors, the categories of personal data each processes, and the applicable security certifications.
This sub-processor list forms an annex to the Lenera AI Data Processing Agreement ("DPA"). Capitalised terms not defined here have the meanings given in the DPA.
2. What is a Sub-processor?
A sub-processor is any third party that processes personal data on our behalf to provide the Service. Sub-processors do not include:
- Third-party tools accessed independently by Customers (not part of Service delivery);
- Providers used only for anonymised or aggregate data;
- Professional service providers (e.g., legal counsel) who do not access personal data in the course of their engagement; or
- Providers used purely for Lenera AI's internal business operations that do not process Customer personal data.
3. Current Sub-processor List
The table below lists all current sub-processors as of the "Last Updated" date above, organised by functional category.
Cloud Infrastructure & Hosting
Amazon Web Services (AWS)
- Purpose
- Cloud infrastructure, compute, storage, and networking
- Data Processed
- All Customer Data (encrypted at rest and in transit); system logs
- Location
- USA (us-east-1, us-west-2); EU (eu-west-1) — Customer-selectable data residency
- Security Certification
- SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, CSA STAR, FedRAMP
Vercel
- Purpose
- Front-end application hosting and edge delivery
- Data Processed
- Session tokens, request metadata; no Customer Content stored
- Location
- USA / Global CDN
- Security Certification
- SOC 2 Type II
Render
- Purpose
- Back-end API service hosting
- Data Processed
- API request/response data; Customer Data in transit only
- Location
- USA (Oregon)
- Security Certification
- SOC 2 Type II (in progress)
Supabase
- Purpose
- Database (PostgreSQL), authentication, and real-time data services
- Data Processed
- Customer account data, project metadata, platform configuration
- Location
- USA (AWS us-east-1); EU option available
- Security Certification
- SOC 2 Type II, GDPR-compliant DPA available
AI & Media Processing
Anthropic (Claude)
- Purpose
- Large language model API for script generation and content assistance
- Data Processed
- Prompts and script content submitted by users; no Customer PII transmitted without explicit user action
- Location
- USA
- Security Certification
- SOC 2 Type II; GDPR DPA available; no training on customer inputs by default
DeepSeek
- Purpose
- AI model API for supplemental language tasks
- Data Processed
- Text prompts; no Customer PII transmitted without explicit user action
- Location
- China (data processed via API; Lenera AI does not store DeepSeek outputs beyond session)
- Security Certification
- See DeepSeek Privacy Policy; customers in regulated industries should review prior to use
D-ID
- Purpose
- AI avatar rendering and video synthesis (avatar animations, talking-head generation)
- Data Processed
- Script text; uploaded reference images/video where custom avatar feature is used
- Location
- Israel / USA (AWS)
- Security Certification
- SOC 2 Type II; GDPR DPA available
Google Cloud Text-to-Speech (Google TTS)
- Purpose
- AI voice synthesis for narration generation
- Data Processed
- Script text submitted for voice rendering
- Location
- USA / Global (Google Cloud regions)
- Security Certification
- ISO 27001, SOC 2 Type II, SOC 3; GDPR DPA available
Remotion Lambda
- Purpose
- Serverless video rendering and composition (AWS Lambda-based)
- Data Processed
- Composition data, rendered frame assets; temporary processing only
- Location
- USA (AWS Lambda)
- Security Certification
- Inherits AWS security certifications; no persistent data storage
Identity & Access Management
WorkOS
- Purpose
- Enterprise SSO, Directory Sync (SAML, OIDC, SCIM), and Admin Portal
- Data Processed
- User identity data: email, name, SSO attributes, directory sync records
- Location
- USA
- Security Certification
- SOC 2 Type II, GDPR DPA available
Payments & Finance
Stripe
- Purpose
- Payment processing and subscription billing
- Data Processed
- Payment card data (PCI DSS scope; Lenera AI does not store full card numbers), billing address, transaction records
- Location
- USA / Global
- Security Certification
- PCI DSS Level 1, SOC 2 Type II
Airwallex
- Purpose
- International payment processing and currency conversion
- Data Processed
- Bank account details, payment transaction data
- Location
- Australia / Global
- Security Certification
- PCI DSS, SOC 1 Type II, SOC 2 Type II
Customer Communications & Marketing
ActiveCampaign
- Purpose
- Email marketing, CRM, and marketing automation
- Data Processed
- Customer contact data: name, email, marketing preferences, email engagement metrics
- Location
- USA
- Security Certification
- SOC 2 Type II, GDPR DPA available
Calendly
- Purpose
- Meeting scheduling and calendar integration
- Data Processed
- Contact name, email, calendar availability data
- Location
- USA
- Security Certification
- SOC 2 Type II, GDPR DPA available
Analytics & Monitoring
Contentsquare
- Purpose
- Digital experience analytics (session replay, heatmaps, journey analysis) — Website only
- Data Processed
- Anonymised/pseudonymised interaction data (mouse movements, clicks, scroll depth); no Customer Content
- Location
- France / USA
- Security Certification
- ISO 27001, SOC 2 Type II, GDPR DPA available
Google Analytics 4 (GA4)
- Purpose
- Website traffic analytics and user behaviour — Website only, not in-Service application
- Data Processed
- Anonymised device/browser data, page views, session data; IP anonymisation enabled
- Location
- USA / Global
- Security Certification
- ISO 27001; GDPR DPA available; no advertising features enabled
Sales & Customer Support
Pipedrive
- Purpose
- Sales CRM and pipeline management
- Data Processed
- Prospect and Customer contact data: name, email, company, deal details
- Location
- Estonia / USA
- Security Certification
- ISO 27001, SOC 2 Type II, GDPR DPA available
Pylon
- Purpose
- Customer support and in-app messaging
- Data Processed
- Support ticket data: name, email, conversation content
- Location
- USA
- Security Certification
- SOC 2 Type II (in progress)
Slack
- Purpose
- Internal team communication (Lenera AI staff only; not used for Customer data processing)
- Data Processed
- Internal operational communications; Customer data shared only in exceptional support escalations with Customer consent
- Location
- USA
- Security Certification
- SOC 2 Type II, ISO 27001, GDPR DPA available
Document & E-Signature
SignEasy (Glide)
- Purpose
- Electronic signature and document execution
- Data Processed
- Signer name, email, IP address, signature image; signed document content
- Location
- USA
- Security Certification
- SOC 2 Type II, GDPR DPA available
4. Sub-processor Updates and Notifications
Lenera AI periodically reviews and updates its sub-processor list as our services and infrastructure evolve. We are committed to transparency and will:
- Provide at least thirty (30) days' prior written notice (by email to the Customer's registered contact address, or via the in-platform notification centre) before adding a new sub-processor or making a material change to an existing sub-processor's role or data processing scope;
- Maintain an up-to-date version of this sub-processor list at lenera.ai/legal/subprocessors;
- Log the effective date of each change in the version history; and
- Promptly notify Customers if a sub-processor suffers a material security incident affecting Customer personal data.
5. Objection Process
If a Customer reasonably objects to Lenera AI's use of a new or changed sub-processor on grounds that the change materially impairs the Customer's ability to comply with applicable data protection law, the Customer must:
- Submit a written objection to support@lenera.ai within thirty (30) days of receiving the notice;
- Identify the specific sub-processor and the legal or compliance concern; and
- Engage in good faith discussions with Lenera AI to explore alternative arrangements.
If Lenera AI cannot reasonably accommodate the objection within thirty (30) days of receiving it (e.g., by using an alternative sub-processor or modifying processing), the Customer may, as its sole and exclusive remedy, terminate the affected Service upon written notice, and Lenera AI will refund any prepaid, unused fees on a pro-rata basis.
6. International Data Transfers
Where a sub-processor processes personal data outside the European Economic Area, the United Kingdom, or other jurisdictions with adequacy decisions, Lenera AI ensures appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) adopted by the European Commission (Module 3: Processor-to-Processor);
- The UK International Data Transfer Addendum (UK IDTA) for UK data;
- Swiss-specific transfer mechanisms where applicable; and
- Sub-processor adherence to the EU-U.S. Data Privacy Framework (DPF) where certified.
Specific transfer mechanisms in place for each sub-processor are available upon written request to support@lenera.ai.
7. Contact
For questions about this sub-processor list or to submit an objection, please contact:
Privacy Team — Lenera AI Inc.
support@lenera.ai
28 Geary St STE 650 Suite #620, San Francisco, California 94108, United States
Last updated: June 2026