Sub-processors & data handling
These are the third parties that process data on Notewell's behalf, what each one touches, and where the processing happens. We keep this honest and current — including the steps that run outside India — so you can tell your own client or compliance team exactly who is in the chain.
The honest bit on residency. Storage is India-hosted, and audio transcription can be pinned to an India region (Sarvam). But the AI summary step today uses a model that runs in the United States, under a contractual no-training / no-retention term. We will not claim your matter “stays in India” end-to-end, because it doesn't yet. If end-to-end India processing is a hard requirement for you, tell us before you sign up.
| Sub-processor | Purpose | Region | Data touched |
|---|---|---|---|
| Hostinger (VPS, Mumbai) | Application + database + audio storage | India | Account, meetings, transcripts, summaries, audio |
| Sarvam AI | Speech-to-text (Indic / code-mix) — India-region STT option | India | Meeting audio (transcription only) |
| Groq | Speech-to-text (Whisper) and/or LLM summarisation | United States | Meeting audio and/or transcript text |
| Deepgram | Speech-to-text (optional provider) | United States | Meeting audio (transcription only) |
| Anthropic | LLM summarisation (optional provider) | United States | Transcript text (to produce the summary) |
| OpenAI | Embeddings for Ask-AI semantic search (optional) | United States | Transcript chunks (to build the search index) |
| Resend | Transactional + summary email delivery | United States | Recipient email, summary content |
| WhatsApp delivery (KanavuWA) | Branded WhatsApp summary + reminder delivery | India | Recipient phone, summary content |
| Recall.ai | Companion meeting bot capture (optional) | United States | Meeting audio/video (when a bot is sent) |
| Razorpay | Payments (Pro/Team subscriptions) | India | Billing name, email, payment reference |
Data Processing Agreement (DPA)
For firms, in-house teams and anyone with a confidentiality policy, we offer a signable DPA that names these sub-processors, binds the no-training / no-retention terms above, and covers DPDP Act 2023 obligations (consent, data export, erasure, 72-hour breach notification). Audio can be set to purge on transcript-ready, and retention is configurable.
Request our DPASee also our Privacy Policy and Terms.