Data processing
Subprocessors and flows
Last updated: 28 August 2026.
Roles
For workspace data you upload through Vapi webhooks, Karim, trading as Engilane acts as processor on your instructions as agency or operator. You remain responsible to your clients. For account, billing, and service operation data, we act as controller. Gumroad is an independent controller for checkout and payment data.
Subprocessors
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Cloudflare, Inc. | Workers hosting, D1 database, Queues, Workers AI | All application data, request metadata, evaluation prompts | EU/US (Cloudflare network) |
| Brevo (Sendinblue) | Transactional email | Recipient address, message body (login codes, alerts, digests) | EU |
| Gumroad, Inc. | Merchant of record, licence verification API | Payment and account data at checkout; licence key at verification | US |
Vapi (or other voice providers you configure) sends webhooks directly to CallProof; they are your vendor, not our subprocessor, though their payload becomes workspace data once received.
Transfers
Cloudflare, Brevo, and Gumroad may process data outside the UK/EEA under their own terms and transfer mechanisms. We do not rely on subprocessors for visitor tracking or advertising profiles.
Security measures
Tenant-scoped queries, hashed session and webhook secrets, HttpOnly cookies, origin checks on mutating routes, and rate limits on auth and webhooks. Details: security.
Retention schedule: retention.