Subprocessors

Last updated: May 18, 2026

This page identifies third-party providers that Unstruk Data, Inc. ("Graphlit", "we", "us", or "our") may use to provide, operate, secure, support, and improve the Graphlit platform.

Capitalized terms not defined on this page have the meanings given in the Graphlit Terms of Service or Data Processing Addendum.

1. Overview

Graphlit is a cloud-native platform that helps customers ingest, transform, index, retrieve, and use customer-controlled data in AI-powered applications, retrieval workflows, conversations, and agent context pipelines.

To provide the Service, Graphlit uses third-party providers for cloud infrastructure, storage, compute, search, authentication, billing, AI model access, monitoring, analytics, support, and related operational functions.

This page is intended to help customers understand which third-party providers may process Customer Data or Customer Personal Data on Graphlit's behalf.

2. Subprocessors vs. Customer-Connected Integrations

Graphlit supports integrations with many third-party systems. Not every integration is a Graphlit subprocessor.

A "Subprocessor" is a third-party provider engaged by Graphlit to process Customer Personal Data on behalf of Graphlit in order to provide the Service.

A "Customer-Connected Integration" is a third-party system that a customer chooses to connect to Graphlit, such as a storage system, collaboration tool, email account, calendar, CRM, developer platform, or project-management system. These systems are typically controlled by the customer and governed by the customer's own relationship with that provider.

For example, if a customer connects its own Slack workspace, Gmail account, HubSpot account, GitHub organization, Notion workspace, or Google Drive folder to Graphlit, that provider is generally a Customer-Connected Integration, not a Graphlit subprocessor.

Customer is responsible for ensuring that it has the necessary rights, permissions, notices, consents, and legal basis to connect third-party systems to Graphlit and process data from those systems.

3. Core Subprocessors

The following subprocessors may be used by Graphlit to provide, operate, secure, support, and improve the Service.

ProviderPurposeData ProcessedLocation / RegionNotes
Microsoft AzureCloud hosting, compute, storage, databases, search, indexing, monitoring, and infrastructureCustomer Data, Customer Personal Data, metadata, embeddings, indexes, files, logs, and operational dataUnited States and/or selected Azure regionsGraphlit may use Azure services such as Blob Storage, Cosmos DB, Azure AI Search, Azure Functions, monitoring, logging, and related managed infrastructure services.
ClerkAuthentication and user identityAccount information, user identity metadata, email addresses, authentication metadata, organization membership metadataUnited States and/or global infrastructureUsed for user authentication, account access, organization membership, and identity workflows.
StripeBilling and payment processingBilling contact information, payment metadata, subscription data, invoice data, tax information, payment statusUnited States and/or global infrastructureGraphlit does not store full payment card details.
VercelWeb application hosting and edge deliveryWeb application metadata, request metadata, limited account/session metadata depending on configurationUnited States and/or global infrastructureUsed where applicable for Graphlit web applications, landing pages, dashboards, or control-plane interfaces.
PostHogProduct analytics and usage analyticsProduct usage events, account or user identifiers, metadata, diagnostics, feature usage dataUnited States and/or EU depending on configurationUsed where applicable for analytics, product improvement, diagnostics, and usage analysis.
GitHubSource control, CI/CD, issue tracking, and development operationsSource code, engineering metadata, operational metadata, security and deployment metadataUnited States and/or global infrastructureUsed for Graphlit engineering operations. GitHub is not a customer data store unless a customer separately connects GitHub as a Customer-Connected Integration.

4. Conditional AI Subprocessors

The following providers may be used only when a customer configures, enables, selects, or invokes a feature that depends on that provider.

For example, Customer Data may be sent to a third-party AI model provider when a customer uses Graphlit for embeddings, summarization, extraction, classification, question answering, generation, agent responses, audio processing, video processing, or other AI-assisted workflows.

ProviderPurposeData ProcessedLocation / RegionNotes
OpenAIAI model inference, embeddings, extraction, summarization, classification, generation, and customer-configured AI workflowsPrompts, retrieved context, extracted text, generated outputs, embeddings-related input, and Customer Data submitted to configured workflowsUnited States and/or provider-operated regionsUsed only when configured or invoked for supported AI workflows.
Microsoft Azure OpenAI ServiceAI model inference, embeddings, extraction, summarization, classification, generation, and customer-configured AI workflowsPrompts, retrieved context, extracted text, generated outputs, embeddings-related input, and Customer Data submitted to configured workflowsAzure regions depending on deployment/configurationUsed only when configured or invoked for supported AI workflows.
AnthropicAI model inference, extraction, summarization, classification, generation, and customer-configured AI workflowsPrompts, retrieved context, extracted text, generated outputs, and Customer Data submitted to configured workflowsUnited States and/or provider-operated regionsUsed only when configured or invoked for supported AI workflows.
GoogleAI model inference, embeddings, extraction, summarization, classification, generation, video generation, and customer-configured AI workflowsPrompts, retrieved context, extracted text, generated outputs, embeddings-related input, reference materials, generated media, and Customer Data submitted to configured workflowsUnited States and/or provider-operated regionsUsed only when configured or invoked for supported AI workflows, including Gemini or Google media-generation services where available.
Mistral AIAI model inference, embeddings, extraction, summarization, classification, generation, and customer-configured AI workflowsPrompts, retrieved context, extracted text, generated outputs, embeddings-related input, and Customer Data submitted to configured workflowsEU, United States, and/or provider-operated regionsUsed only when configured or invoked for supported AI workflows.
CohereAI model inference, embeddings, reranking, extraction, summarization, classification, generation, and customer-configured AI workflowsPrompts, retrieved context, extracted text, generated outputs, embeddings-related input, and Customer Data submitted to configured workflowsUnited States, Canada, and/or provider-operated regionsUsed only when configured or invoked for supported AI workflows.
ElevenLabsAudio generation, transcription, speech, voice, or audio-related AI workflowsText, audio, generated audio, metadata, and Customer Data submitted to configured audio workflowsUnited States, EU, and/or provider-operated regionsUsed only when audio or voice features are configured or invoked.
TwelveLabsVideo understanding, video indexing, video search, and video AI workflowsVideo files, video metadata, transcripts, embeddings, extracted video context, and Customer Data submitted to configured video workflowsUnited States and/or provider-operated regionsUsed only when video understanding or video indexing features are configured or invoked.

5. AI Provider Use

Graphlit does not train, fine-tune, host, or deploy its own AI foundation models.

Graphlit does not use Customer Data to train or fine-tune Graphlit-owned AI foundation models.

Graphlit does not sell Customer Data.

Graphlit does not share Customer Data for unrelated third-party use.

Third-party AI model providers are used only where required to provide customer-configured functionality or where a customer chooses to use features that depend on those providers.

Third-party AI model provider handling is governed by the applicable provider terms, customer configuration, and Graphlit's agreements with those providers where applicable.

Customers are responsible for selecting model providers, model configurations, prompts, workflows, guardrails, and downstream applications appropriate for their data, risk profile, and legal obligations.

6. Customer-Connected Integrations

Graphlit may allow customers to connect third-party systems to ingest, retrieve, index, enrich, or act on Customer Data.

These integrations are generally customer-selected systems and are not necessarily Graphlit subprocessors. The customer controls whether to connect them, what permissions to grant, what data to ingest, and how to use the resulting data.

Graphlit may support integrations with systems such as the following.

Collaboration and Knowledge Systems

  • Slack
  • Microsoft Teams
  • Discord
  • Notion
  • Confluence
  • Evernote

File Storage and Cloud Storage

  • Google Drive
  • Microsoft OneDrive
  • Microsoft SharePoint
  • Dropbox
  • Box
  • Amazon S3
  • Azure Blob Storage
  • Cloudflare R2
  • Wasabi
  • Backblaze B2
  • DigitalOcean Spaces
  • S3-compatible storage endpoints

Email, Calendar, and Contacts

  • Gmail
  • Google Calendar
  • Google Contacts
  • Microsoft Outlook
  • Microsoft Calendar
  • Microsoft Contacts

Meeting and Transcript Systems

  • Zoom
  • Fathom
  • Fireflies
  • Other meeting transcript or recording sources supported by Graphlit

CRM and Customer Systems

  • HubSpot
  • Salesforce
  • Attio
  • Productlane
  • Intercom
  • Zendesk

Project Management and Work Tracking

  • Jira
  • Linear
  • Trello
  • Asana

Developer Systems

  • GitHub
  • GitLab

Other Sources

  • Public web pages
  • RSS feeds
  • Website crawls
  • APIs
  • Uploaded files
  • Customer-provided URLs
  • Customer-built integrations using the Graphlit API

The availability of a specific integration may vary by plan, feature, customer configuration, API availability, provider permissions, or product roadmap.

7. Data Processed by Subprocessors

Depending on the provider and customer configuration, subprocessors may process:

  • Account information
  • User identity metadata
  • Authentication metadata
  • Billing metadata
  • Customer-ingested files
  • Extracted text
  • Metadata
  • Embeddings
  • Search indexes
  • Conversation history
  • Prompts
  • Retrieved context
  • AI-generated outputs
  • Audio, image, or video inputs and outputs where configured
  • Logs and diagnostic information
  • Usage and product analytics events
  • Support and operational metadata

Graphlit limits subprocessor access to the data reasonably necessary for the provider to perform the applicable service.

8. Updates to This Page

Graphlit may update this Subprocessor page from time to time as providers are added, removed, replaced, or reclassified.

Where required by applicable law or commercially reasonable under the circumstances, Graphlit will provide notice of material subprocessor changes through the Graphlit website, email, product notice, or another reasonable method.

Customers may object to a new subprocessor on reasonable data protection grounds by contacting legal@graphlit.com within 30 days after notice of the new subprocessor.

Graphlit will use commercially reasonable efforts to address the objection. If the parties cannot resolve the objection, Customer may stop using the affected Service feature or terminate the affected Service subscription.

9. Contact

For questions about Graphlit subprocessors, contact:

Unstruk Data, Inc.
Legal: legal@graphlit.com
Security: security@graphlit.com
Website: https://www.graphlit.com