Every third party, named

Subprocessors

Last updated September 18, 2026 · Version 2026-09-18
The date above is the version your account is bound by. Questions: legal@kavvim.com.

The third parties that process information to help us operate Kavvim. This is the full list, not a summary. Each is bound by a written agreement limiting it to processing on our instructions.

Always active

These providers are engaged for every studio, because the Service cannot run without them.

VendorPurposePersonal information receivedLocation
Amazon Web Services, Inc.Application and database hosting (Lightsail, us-east-1), object storage (S3), and key management (KMS)All Customer Data at rest and in processing; all uploaded files, images and exports. KMS receives no personal information, only wrapped encryption keysUnited States
Stripe, Inc.Subscription billing and client invoice payment processingCard details captured directly in the browser; billing name and email; customer and account identifiers; transaction amounts and descriptions; identity verification information collected by Stripe directly for connected accountsUnited States
Mailjet SASTransactional email deliveryRecipient email addresses; message subject and body, which may contain names, invoice numbers, amounts, and booking details; invoice PDF attachmentsEuropean Union
Functional Software, Inc. (Sentry)Error and crash monitoring, and release healthDiagnostic reports when a fault occurs: the error, stack trace, browser and operating system, user identifier, and the actions preceding it, plus a count of sessions started. Configured to exclude request contents, form values, cookies, and IP addresses. No session replay and no page contentsUnited States
Mapbox, Inc.Address autocompletePartial address strings as typed, with a session identifier. Where you have granted browser location permission, an approximate location rounded to roughly 100 meters, sent as a ranking hint only. No names or account identifiersUnited States

Active when the feature is used

These providers receive information only when someone in your studio uses the feature that depends on them.

VendorPurposePersonal information receivedLocation
Anthropic, PBCStudio assistant, and part of presentation generationYour display name; questions asked; data retrieved to answer them, which where enabled may include client names, contact details, addresses, and notesUnited States
Google LLCPresentation generation, image captioning, image editing (Gemini)Presentation content and instructions; image files, which where enabled may include photographs of client properties and interiorsUnited States
Photoroom SASBackground removal from product and project imagesThe single image submitted for processing, typically a photograph of furniture, a product, or a project interiorEuropean Union
Ship24Parcel trackingTracking number, destination country code, courier code, and an internal reference. No names, addresses, or client identifiersEuropean Union

Each AI provider is configured so that submitted content is not used to train its models. For Anthropic and Google this is a term of their commercial agreements with us. For Photoroom it is an account-level setting we have enabled and maintain.

AI providers receive only what a specific request needs, and only when someone in your studio makes that request. If you would rather no client data reached an AI provider at all, turn the relevant features off yourself in Settings → AI, or turn off AI entirely. You do not need to ask us.

Optional integrations you connect yourself

These are not engaged by Kavvim. They process information only if a studio explicitly connects the integration, and only for the bookings that use it. Disconnecting the integration stops it.

VendorPurposePersonal information receivedLocation
Zoom Communications, Inc.Meeting links for bookings, when connectedBooking title, time, and the attendee list for that bookingUnited States
Google LLC (Calendar/Meet)Google Meet links for bookings, when connectedEvent details, booking time, and attendee email addressesUnited States
8x8, Inc. (Jitsi Meet)Fallback meeting rooms where no provider is connectedA generated room name and URL only. Meeting content is handled on Jitsi’s infrastructureDepends on the instance configured

Notice of changes

We will give at least 30 days’ notice by email to the studio owner before we add or replace a subprocessor, and this page will be updated on the same day the change takes effect. You may object on reasonable data-protection grounds within 15 days. If we cannot resolve the objection, you may terminate the affected portion of the Service and receive a prorated refund of prepaid fees, as set out in Section 4 of the Data Processing Addendum.

Where a subprocessor becomes unavailable or suffers an incident, we may substitute immediately and will notify you promptly afterward.

To be added to the notification list, or to raise an objection, email privacy@kavvim.com.

Changelog

DateChange
September 18, 2026Initial published list.

Questions: privacy@kavvim.com.

Document history

2026-09-18First published version of all nine documents. (current)
Related