Skip to main content

DRAFT — Requires legal review before publication.

Sub-Processor List

Last updated: April 2026

The following third-party services process data on behalf of Nainty users as part of providing the Service. We notify customers of changes to this list via email with 30 days notice.

To request a copy of our Data Processing Agreement (DPA), contact legal@nainty.com.

ProcessorPurposeData SharedLocation
AnthropicAI features (proposals, forms, reports, workflows)PII-redacted business contextUS
StripePayment processingPayment amounts, payer emailUS/Global
PlaidBank feed connections (US/EU/UK)OAuth tokens, transaction dataUS
BasiqBank feed connections (AU/NZ)OAuth tokens, transaction dataAU
AssemblyAIMeeting transcriptionAudio recordingsUS
TwilioSMS and WhatsApp messagingPhone numbers, message contentUS
ClearbitCompany enrichmentBusiness email addressesUS
ApolloCompany enrichment (fallback)Business email addressesUS
Google (Gmail, Calendar)Email and calendar syncOAuth tokens, email metadata, calendar eventsUS/Global
Microsoft (Outlook, OneDrive)Email, calendar, file syncOAuth tokens, email metadata, filesUS/Global
Intuit (QuickBooks)Accounting syncInvoices, expenses, clients, paymentsUS
XeroAccounting syncInvoices, expenses, clients, paymentsAU/NZ
GotenbergPDF generationInvoice/contract HTML (self-hosted, no external transfer)Self-hosted

Security Measures

  • All integration tokens encrypted with AES-256-GCM before storage
  • OAuth tokens refreshed automatically; access can be revoked at any time
  • Circuit breakers on all integrations provide graceful degradation
  • Each integration is voluntary — you control which services to connect

Changes

We will notify you via email at least 30 days before adding a new sub-processor. If you object, you may terminate your account before the change takes effect.

Sub-Processor List — Nainty — Nainty