Every third party that can receive data through CoreLayerEngine is listed below, with what it is for, what it gets and where it processes. The list is derived from the outbound calls in our source code rather than from memory, and adding a new outbound call requires updating this page in the same change.
CoreLayerEngine is operated by Ektasi Technology (OPC) Private Limited, India. Our commitments to customers about these parties are in the Data Processing Agreement; how we handle personal data generally is in the Privacy Policy.
How to read this
- Always engaged for every workspace — the product does not run without it.
- If configured engaged only when the operator sets that key. A deployment without it never contacts the party.
- If you enable it engaged only when you connect that channel or switch that feature on. If you never connect Instagram, we never send Meta anything about you.
"Region" is where that party states it processes data — not where your workspace lives. Your own residency is described in Trust & Security.
Core infrastructure
| Party | Purpose | Data | Region | When |
|---|---|---|---|---|
| Hosting & database operator (self-managed PostgreSQL and application containers) | Runs the application; holds your workspace's primary datastore | All customer data | India — the only region we operate | Always |
| Cloudflare, Inc. | DNS, TLS, CDN, DDoS and WAF in front of the website and the product | IP address, request metadata | Global edge | Always |
| Object storage for backups (S3-compatible, chosen per region) | Stores encrypted database backups | Encrypted database dumps | Same region as the data | Always |
| Google LLC (Analytics 4 & Tag Manager) | Counts visits and page reads on this marketing website only — never loaded by the product at app.corelayerengine.com | Visitor IP address (truncated by Google), user-agent, page URL, referrer, and a first-party _ga cookie id. No advertising signal is sent: every Google advertising consent category is denied before the tag loads, and analytics storage is denied outright in the EEA, UK and Switzerland. | Global edge; Google processes in the US | Always for website visitors |
AI model providers
One text and image provider is active at a time. With none configured, generation runs locally and no prompt leaves our infrastructure.
| Party | Purpose | Data | Region | When |
|---|---|---|---|---|
| OpenRouter, Inc. | Text and image generation, brokered onward to a downstream model provider | Prompts (brand profile, briefs, content you ask it to write) and generated output | US / global | If configured |
| Anthropic PBC | Text generation | As above | US | If configured |
| OpenAI, L.L.C. | Text generation, image generation, audio transcription | As above, plus audio you submit | US | If configured |
| Groq, Inc. | Vision / image understanding — OCR and captioning of images you upload | The uploaded image itself, which may contain identifiable faces, plus the prompt and the extracted text or caption | US | Default vision endpoint |
We do not train models on your data, and there is no training or fine-tuning pipeline in the product. Where Anthropic or OpenAI is used directly, their API terms state inputs are not used to train their models. Where OpenRouter is used, requests are brokered to a downstream provider and we cannot give one no-training guarantee across every model reachable that way — ask us and we will pin your workspace to a direct provider.
Optional AI media features
| Party | Purpose | Data | Region | When |
|---|---|---|---|---|
| HeyGen | Presenter / avatar video | Script text and a synthetic avatar identifier. A photograph of a real person is sent only if the operator has deliberately enabled that path — off by default | US | If you enable it |
| D-ID | Presenter / avatar video (alternative) | Script text and a source image. Same default-off restriction on real-person photographs | US / Israel | If you enable it |
| remove.bg | Background removal on uploaded images | The uploaded image | EU (Germany) | If configured |
Publishing channels
Engaged only for the channels you connect, and only with the permissions you grant.
| Party | Covers | Data | Region | When |
|---|---|---|---|---|
| Meta Platforms, Inc. | Facebook Pages, Instagram, Threads | Post content and media; your page identifiers; comments on your posts; WhatsApp recipient numbers and message bodies | Global | If you enable it |
| LinkedIn Corporation | Post content and media; organisation identifiers | Global | If you enable it | |
| TikTok Ltd. | TikTok | Video content; account identifiers | Global | If you enable it |
| Pinterest, Inc. | Pin content and media; board identifiers | Global | If you enable it | |
| X Corp. | X | Post content and media; account identifiers | Global | If you enable it |
| Google LLC | YouTube, Google Business Profile | Video and local-post content; channel and location identifiers | Global | If you enable it |
Social listening
Off unless switched on. Listening collects public content written by people who are not our customers, which is why we keep raw mentions for only 180 days by default — and only 30 days for anything retrieved from the YouTube API, which is the maximum YouTube's API Services Terms allow.
| Party | Purpose | Data | Region | When |
|---|---|---|---|---|
| X Corp. | Public posts mentioning your brand | Public post text, author handle, reach | Global | If configured |
| Reddit, Inc. | Public Reddit mentions | Public post text and author handle | US | If configured |
| The GDELT Project | News-article mentions | Outbound query only — your brand name. No personal data is sent | US | If configured |
| Google LLC (YouTube Data API) | YouTube video and comment mentions | Public comment text and commenter display names | Global | If configured |
| Meta Platforms, Inc. | Comment listening on your own posts | Commenter handles and comment text | Global | If configured |
Payments
Checkout happens on the provider's own page. Card numbers never reach our servers; we receive payment metadata only.
| Party | Purpose | Data | Region | When |
|---|---|---|---|---|
| Stripe, Inc. | Subscription checkout and billing | Billing email, customer and subscription identifiers, plan, status | US / global | If configured |
| Razorpay Software Pvt Ltd | Subscription checkout (India) | As above | India | If configured |
| Cashfree Payments India Pvt Ltd | Payment links (India) | Billing email, phone, amount, plan | India | If configured |
| Paddle.com Market Ltd | Merchant-of-record checkout | Billing email, transaction identifiers | UK / EU | If configured |
| Lemon Squeezy LLC | Merchant-of-record checkout | Billing email, transaction identifiers | US | If configured |
Messaging, identity and operations
| Party | Purpose | Data | Region | When |
|---|---|---|---|---|
| Amazon Web Services, Inc. (Amazon SES) | Transactional email and email broadcasts you send | Recipient email address, subject, body | Configured AWS region (ap-south-1, Mumbai) | If configured |
| SMS gateway (operator-chosen) | SMS reminders and broadcasts | Recipient phone number, message body | Depends on the gateway | If configured |
| Google, Meta, LinkedIn, X, Discord | Optional social sign-in to our console | Your name and email from the identity provider | Global | If you enable it |
| Alerting destination (e.g. PagerDuty, Opsgenie) | Operational alerts to our on-call engineer | Operational metadata only — alert key, severity, workspace identifier. No content, no contact data | Depends on the destination | If configured |
Outbound webhooks you configure deliver to your endpoint — you control that destination, so it is not a sub-processor of ours.
What we deliberately do not use
No third-party product analytics (no Google Analytics, Segment, Mixpanel, Amplitude, PostHog, Plausible). No third-party error tracking (no Sentry, Bugsnag, Rollbar). No advertising or marketing pixels. No session-replay tooling. No customer-support SaaS holding your data — the in-product help assistant runs on our own knowledge base.
Change notice
We give 30 days' written notice — by email to the workspace owner and by updating this page and its date — before adding or replacing a sub-processor that processes customer personal data. Within that period you may object on reasonable data-protection grounds; if we cannot offer a workaround, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees. Emergency replacements, where a provider fails or is terminated for cause, may be made immediately with notice as soon as practicable.
To subscribe to change notices, or to ask about any entry here, email legal@ektasi.io.