Skip to content
CoreLayerEngine
ProductPlatformsSolutionsResourcesPricing
Transparency

Sub-processors

Last updated: 10 August 2026

Every third party that can receive data through CoreLayerEngine is listed below, with what it is for, what it gets and where it processes. The list is derived from the outbound calls in our source code rather than from memory, and adding a new outbound call requires updating this page in the same change.

CoreLayerEngine is operated by Ektasi Technology (OPC) Private Limited, India. Our commitments to customers about these parties are in the Data Processing Agreement; how we handle personal data generally is in the Privacy Policy.

How to read this

  • Always engaged for every workspace — the product does not run without it.
  • If configured engaged only when the operator sets that key. A deployment without it never contacts the party.
  • If you enable it engaged only when you connect that channel or switch that feature on. If you never connect Instagram, we never send Meta anything about you.

"Region" is where that party states it processes data — not where your workspace lives. Your own residency is described in Trust & Security.

Core infrastructure

PartyPurposeDataRegionWhen
Hosting & database operator (self-managed PostgreSQL and application containers)Runs the application; holds your workspace's primary datastoreAll customer dataIndia — the only region we operateAlways
Cloudflare, Inc.DNS, TLS, CDN, DDoS and WAF in front of the website and the productIP address, request metadataGlobal edgeAlways
Object storage for backups (S3-compatible, chosen per region)Stores encrypted database backupsEncrypted database dumpsSame region as the dataAlways
Google LLC (Analytics 4 & Tag Manager)Counts visits and page reads on this marketing website only — never loaded by the product at app.corelayerengine.comVisitor IP address (truncated by Google), user-agent, page URL, referrer, and a first-party _ga cookie id. No advertising signal is sent: every Google advertising consent category is denied before the tag loads, and analytics storage is denied outright in the EEA, UK and Switzerland.Global edge; Google processes in the USAlways for website visitors

AI model providers

One text and image provider is active at a time. With none configured, generation runs locally and no prompt leaves our infrastructure.

PartyPurposeDataRegionWhen
OpenRouter, Inc.Text and image generation, brokered onward to a downstream model providerPrompts (brand profile, briefs, content you ask it to write) and generated outputUS / globalIf configured
Anthropic PBCText generationAs aboveUSIf configured
OpenAI, L.L.C.Text generation, image generation, audio transcriptionAs above, plus audio you submitUSIf configured
Groq, Inc.Vision / image understanding — OCR and captioning of images you uploadThe uploaded image itself, which may contain identifiable faces, plus the prompt and the extracted text or captionUSDefault vision endpoint

We do not train models on your data, and there is no training or fine-tuning pipeline in the product. Where Anthropic or OpenAI is used directly, their API terms state inputs are not used to train their models. Where OpenRouter is used, requests are brokered to a downstream provider and we cannot give one no-training guarantee across every model reachable that way — ask us and we will pin your workspace to a direct provider.

Optional AI media features

PartyPurposeDataRegionWhen
HeyGenPresenter / avatar videoScript text and a synthetic avatar identifier. A photograph of a real person is sent only if the operator has deliberately enabled that path — off by defaultUSIf you enable it
D-IDPresenter / avatar video (alternative)Script text and a source image. Same default-off restriction on real-person photographsUS / IsraelIf you enable it
remove.bgBackground removal on uploaded imagesThe uploaded imageEU (Germany)If configured

Publishing channels

Engaged only for the channels you connect, and only with the permissions you grant.

PartyCoversDataRegionWhen
Meta Platforms, Inc.Facebook Pages, Instagram, ThreadsPost content and media; your page identifiers; comments on your posts; WhatsApp recipient numbers and message bodiesGlobalIf you enable it
LinkedIn CorporationLinkedInPost content and media; organisation identifiersGlobalIf you enable it
TikTok Ltd.TikTokVideo content; account identifiersGlobalIf you enable it
Pinterest, Inc.PinterestPin content and media; board identifiersGlobalIf you enable it
X Corp.XPost content and media; account identifiersGlobalIf you enable it
Google LLCYouTube, Google Business ProfileVideo and local-post content; channel and location identifiersGlobalIf you enable it

Social listening

Off unless switched on. Listening collects public content written by people who are not our customers, which is why we keep raw mentions for only 180 days by default — and only 30 days for anything retrieved from the YouTube API, which is the maximum YouTube's API Services Terms allow.

PartyPurposeDataRegionWhen
X Corp.Public posts mentioning your brandPublic post text, author handle, reachGlobalIf configured
Reddit, Inc.Public Reddit mentionsPublic post text and author handleUSIf configured
The GDELT ProjectNews-article mentionsOutbound query only — your brand name. No personal data is sentUSIf configured
Google LLC (YouTube Data API)YouTube video and comment mentionsPublic comment text and commenter display namesGlobalIf configured
Meta Platforms, Inc.Comment listening on your own postsCommenter handles and comment textGlobalIf configured

Payments

Checkout happens on the provider's own page. Card numbers never reach our servers; we receive payment metadata only.

PartyPurposeDataRegionWhen
Stripe, Inc.Subscription checkout and billingBilling email, customer and subscription identifiers, plan, statusUS / globalIf configured
Razorpay Software Pvt LtdSubscription checkout (India)As aboveIndiaIf configured
Cashfree Payments India Pvt LtdPayment links (India)Billing email, phone, amount, planIndiaIf configured
Paddle.com Market LtdMerchant-of-record checkoutBilling email, transaction identifiersUK / EUIf configured
Lemon Squeezy LLCMerchant-of-record checkoutBilling email, transaction identifiersUSIf configured

Messaging, identity and operations

PartyPurposeDataRegionWhen
Amazon Web Services, Inc. (Amazon SES)Transactional email and email broadcasts you sendRecipient email address, subject, bodyConfigured AWS region (ap-south-1, Mumbai)If configured
SMS gateway (operator-chosen)SMS reminders and broadcastsRecipient phone number, message bodyDepends on the gatewayIf configured
Google, Meta, LinkedIn, X, DiscordOptional social sign-in to our consoleYour name and email from the identity providerGlobalIf you enable it
Alerting destination (e.g. PagerDuty, Opsgenie)Operational alerts to our on-call engineerOperational metadata only — alert key, severity, workspace identifier. No content, no contact dataDepends on the destinationIf configured

Outbound webhooks you configure deliver to your endpoint — you control that destination, so it is not a sub-processor of ours.

What we deliberately do not use

No third-party product analytics (no Google Analytics, Segment, Mixpanel, Amplitude, PostHog, Plausible). No third-party error tracking (no Sentry, Bugsnag, Rollbar). No advertising or marketing pixels. No session-replay tooling. No customer-support SaaS holding your data — the in-product help assistant runs on our own knowledge base.

Change notice

We give 30 days' written notice — by email to the workspace owner and by updating this page and its date — before adding or replacing a sub-processor that processes customer personal data. Within that period you may object on reasonable data-protection grounds; if we cannot offer a workaround, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees. Emergency replacements, where a provider fails or is terminated for cause, may be made immediately with notice as soon as practicable.

To subscribe to change notices, or to ask about any entry here, email legal@ektasi.io.