AgentAssist legal
Subprocessors
Review the policies that govern AgentAssist data, AI assistance, organization billing, security, and support workflows.
Last updated: June 28, 2026
AgentAssist uses third-party providers to operate infrastructure, storage, email, AI, payments, monitoring, and support workflows.
Current provider categories
| Provider | Purpose | Data processed | Notes |
|---|---|---|---|
| Dokploy and hosting infrastructure | Run AgentAssist web, SaaS, worker, storage, and deployment infrastructure | Account, organization, technical, log, and operational data needed to serve the application | Dev and production infrastructure may use separate environments |
| PostgreSQL with pgvector | Store application records and vector-search indexes | Organizations, users, documents, chunks, conversations, billing state, audit logs, and metadata | Primary application database |
| MinIO-compatible object storage | Store uploaded documents, avatars, exports, and support attachments | PDFs, document objects, image assets, generated files, and related metadata | Objects remain private unless signed access is intentionally generated |
| Better Auth | Provide login, sessions, passkeys, password reset, and organization access controls | Identity, account, session, device, invitation, and security metadata | Authentication framework used by AgentAssist |
| Cohere, PageIndex, Groq, OpenAI, or configured AI providers | Support embeddings, OCR/PageIndex fallback, chat, voice, and AI-assisted workflows | Prompts, retrieved document excerpts, structured output instructions, and generated text where enabled | Provider use depends on environment configuration and enabled features |
| Razorpay | Process organization subscriptions, checkout, invoices, payment status, and webhooks | Payment identifiers, billing contact data, subscription state, transaction metadata, and webhook payloads | Used for organization-level billing where configured |
| Resend or configured mail provider | Send transactional email | Email addresses, message content, delivery metadata, and communication preferences | Used when email delivery is configured |
Access limitations
Subprocessor access is limited by purpose and environment. Provider configuration can vary by deployment environment and customer agreement.
Data minimization
AgentAssist aims to send providers only the information required for the relevant workflow. For AI requests, context should be limited to the user's prompt, selected organization scope, and retrieved document excerpts needed to answer.
Change notices
Provider categories may change as the platform evolves. Material provider changes for production customers may be communicated according to the applicable agreement or product notice process.
Enterprise review
Enterprise customers can request a current subprocessor list, region review, and data-flow summary through support.