ManifestoPricing
Sign inJoin the waitlist
LegalLast updated June 26, 2026

Capable — Sub-processors

Last updated: 2026-06-26

This page lists the third-party sub-processors that Capable Agents AB (organisationsnummer 559504-0444, VAT SE559504044401) ("Capable") engages to process Customer Data in providing the Services. It supplements our Data Processing Agreement (Annex III) and Privacy Policy.

Change notification

We may add or replace a sub-processor as the Services evolve. When we do, we update this page and, where a customer has subscribed to sub-processor notifications, we give notice (by email or in-product). Customers then have a reasonable period — at least thirty (30) days unless a shorter period is required for security or legal reasons — to object on reasonable data-protection grounds, as described in Section 6.3 of the DPA. To subscribe to notifications or to raise an objection, email hello@capable.run.


Current sub-processors

Sub-processorPurposeData processedLocation / region
SupabasePrimary data store, authentication, file storage, backups (PITR)All Customer Data; Authorized User identityEuropean Union (eu-west-3, Paris)
VercelApplication + MCP server hosting, edge, deployment, logsCustomer Data in transit; request/operational logsEU (Paris / cdg1) / global edge
GoogleIdentity provider (Google Sign-In) and, on the customer's authorisation, the source of Gmail data and Calendar event metadataAuthorized User identity; email header metadata (stored); email message content (stored encrypted at rest, access-controlled, never sent to an AI model, purged on deletion); calendar event metadata + the event description (meeting agenda) stored on the activity (scrubbed of obvious join credentials, encrypted at rest, never sent to an AI model, purged on deletion; never calendar locations/attachments)United States / global
Recall.aiMeeting-recorder bots that join and record video calls (where enabled)Meeting audio/video, transcripts, recording links, participant metadataEuropean Union (eu-central-1, Frankfurt) — configured via RECALL_REGION=eu-central-1
DeepgramSpeech-to-text transcription of recordings, routed through Recall.ai (BYO provider)Meeting audio for transcriptionEuropean Union (routed through Recall.ai's EU deployment)
InngestBackground-job orchestration (inbox import, signal ingestion, scheduled report digests, recorder routing)Customer Data referenced by background jobs (event metadata, identifiers)US / global
ResendTransactional email delivery (scheduled report digests; account/operational email)Recipient email address; email content of digests/notificationsUS / global
SentryApplication error and performance monitoringError/diagnostic metadata (configured not to send personal data by default)US / global
PostHogProduct analytics (cookieless, metadata-minimized)Metadata-minimized usage signals (tool/kind/latency/error class); Authorized User identifierEuropean Union (EU-hosted)
UpstashRate limiting and caching (Redis)Short-lived cache keys (e.g. workspace settings, domain facts); rate-limit countersUS / global (graceful no-op when unconfigured)
BrandfetchCompany-level (domain) firmographic factsCompany domain and public company facts (not individual personal data)US / global
Logo.devCompany logos by domainCompany domain (not individual personal data)US / global
Stripe (planned)Payments, invoicing, customer portalBilling contact and payment metadata (card data handled by Stripe, not stored by Capable)US / global

Status note. Vendors marked (planned) are not yet engaged in the production Service. Stripe is integrated in the product plan but not yet wired in code; we will engage it before processing payments and will reflect that here.


Why Anthropic is not listed as a sub-processor

Capable is an AI-native CRM, but we do not make server-side calls to any large language model and we do not transmit Customer Data to a model. The AI assistant is Anthropic's Claude, connected by the Authorized User under that user's own agreement with Anthropic. When an Authorized User instructs Claude, our MCP server returns the requested Customer Data into that user's own Claude session, where Anthropic processes it under the user's own Anthropic terms — not on Capable's behalf.

Because Anthropic does not process Customer Data on Capable's behalf, it is not a sub-processor of Capable, and is deliberately not listed above. Anthropic is the environment in which Authorized Users operate the Services, governed by each user's own agreement with Anthropic. This treatment is consistent across our Terms of Service (Sections 6–7), Privacy Policy (Section 4.4), and DPA (Section 12).


Questions: hello@capable.run

The AI-native customer backbone: clean relationship data, a clear web UI for your team, one MCP endpoint for supported clients.

Join the waitlist
Product
  • How it works
  • Pricing
  • All capabilities
Company
  • Manifesto
  • Use cases
  • Contact
Resources
  • Join the waitlist
  • Security
  • FAQ
  • Developers
  • Sign in
Legal
  • Privacy
  • Terms
  • DPA
  • Sub-processors
© 2026 Capable. All rights reserved.All systems operational