Last updated: 24 July 2026
Status: Early access living list. Confirm production vendors before enterprise contracts.
Operator: Lazuar · Contact: [email protected]
This page lists categories of subprocessors — third parties that may process personal data on behalf of Lazuar to deliver BalasAuto. It complements our Privacy Policy and Data processing & roles.
1. How to read this list
| Column | Meaning |
|---|---|
| Category | Type of service |
| Role | Why data is processed |
| Typical data | What may be involved (not exhaustive) |
| Notes | Early-access caveats |
Exact vendor names and regions depend on how BalasAuto is deployed (Lazuar-hosted vs customer-managed). Production operators should replace placeholders with named providers and locations.
2. Current categories (early access)
| Category | Role | Typical data | Notes (MVP) |
|---|---|---|---|
| Application hosting / compute | Run the web and API | Account data, app traffic, logs | e.g. cloud VM or PaaS chosen by operator |
| Managed PostgreSQL | Primary application database | Accounts, workspaces, messages, knowledge, usage meters | Tenant-scoped app data |
| Redis / job queue | Cache and background jobs (e.g. BullMQ) | Job payloads, rate-limit keys, transient processing data | May include message IDs / short content for jobs |
| Object / file storage | Knowledge + media storage | Uploaded FAQ/docs; WhatsApp media files | Path depends on storage config |
| Payments (optional) | Card checkout | Billing email, Stripe customer/subscription ids | Stripe when STRIPE_* env configured; otherwise invoice only |
| Error tracking (optional) | Exception reports | Stack traces, request ids (redacted secrets) | e.g. Sentry when SENTRY_DSN set |
| Meta / WhatsApp Cloud API | Send/receive WhatsApp messages | Phone numbers, message content, delivery metadata | Independent platform under Meta’s terms — not a Lazuar “subprocessor” in the classic sense, but a required integration |
| AI / LLM API (optional) | Generate auto-replies when provider ≠ mock | Prompt text, retrieved knowledge snippets, model metadata | Only when you enable a non-mock AI provider and keys |
| Email / transactional mail (optional) | Account or support email if configured | Email address, message content | Not required for core WhatsApp path |
| Error / performance monitoring (optional) | Reliability | Request IDs, stack traces; avoid full chat bodies where possible | Add named vendor when enabled in production |
| Payment / invoicing (optional) | Collect BalasAuto fees when paid plans go live | Billing contact, invoice metadata | Meta conversation fees are not processed by us |
3. AI providers
When AI_PROVIDER is mock, reply generation stays offline/stubbed and does not call an external LLM.
When a real provider is configured (e.g. OpenAI-compatible API):
- customer message context and knowledge snippets may leave Lazuar infrastructure to that vendor,
- processing is solely to generate the reply you requested,
- we do not use your chats to train public foundation models (see Privacy Policy).
Name the live vendor and region in your production runbook and update this page when it changes.
4. Changes to subprocessors
For early access we may add or replace infrastructure vendors as the product hardens. Material changes for production customers should be:
- reflected on this page (bump last updated),
- communicated where contracts require notice.
5. Your own subprocessors
If you (the shop) connect tools outside BalasAuto (your CRM, sheet exports, staff devices), those are your processors/subprocessors — not listed here.
6. Questions
Related: Privacy Policy · Data processing & roles · Terms