Sub-processors
Every third party that may process personal data on behalf of Michi customersUpdated 2026-05-24 · 18 active
Michi is operated by Nefra, Inc., a Delaware corporation (United States). For users in the European Economic Area, Sila Technologies B.V. (Antwerp, Belgium), an affiliated entity of Nefra, Inc., acts as the data controller for personal data under GDPR.
Michi uses these third-party providers to operate the service. We publish this list publicly and update it whenever a provider is added, replaced, or removed. Material changes are announced by email to all billing contacts at least 30 days in advance.
| Provider | Purpose | Data processed | Region | DPA |
|---|---|---|---|---|
| Supabase ↗ | PurposePrimary database, auth, file storage | Data processedAll customer data — encrypted at rest | RegionEU | DPAView ↗ |
| Vercel ↗ | PurposeApplication hosting, edge functions | Data processedRequest metadata, no persistent customer data | RegionEU | DPAView ↗ |
| Stripe ↗ | PurposeSubscription billing & payments | Data processedBilling email, payment method, invoices | RegionEU | DPAView ↗ |
| Anthropic ↗ | PurposeClaude LLM for transcript and email extraction | Data processedTransient prompt text only — not retained, not used for training | RegionUS | DPAView ↗ |
| Resend ↗ | PurposeTransactional email delivery | Data processedRecipient email, subject, body of system emails | RegionEU | DPAView ↗ |
| Sentry ↗ | PurposeError monitoring & performance traces | Data processedStack traces, user ID (no PII in error context) | RegionEU | DPAView ↗ |
| PostHog ↗ | PurposeProduct analytics (cookieless by default) | Data processedAnonymous events; identified events only after consent | RegionEU | DPAView ↗ |
| Google Analytics 4 ↗ | PurposeMarketing analytics & SEO attribution (marketing pages only; loaded only after consent). US transfers covered by EU SCCs. | Data processedPseudonymised page views, referrer, anonymised IP, _ga cookies | RegionUS | DPAView ↗ |
| Microsoft Clarity ↗ | PurposeSession recordings & heatmaps (marketing pages only; sensitive inputs masked; loaded only after consent). US transfers covered by EU SCCs. | Data processedAnonymised mouse movements, scroll depth, click coordinates, _clck/_clsk cookies | RegionUS | DPAView ↗ |
| Crisp ↗ | PurposeCustomer support chat widget | Data processedEmail, name, chat transcripts (only when user initiates) | RegionEU | DPAView ↗ |
| Google (Gmail API + Pub/Sub) ↗ | PurposeGmail integration & push notifications | Data processedCustomer-authorised mailbox messages (read-only) | RegionGlobal | DPAView ↗ |
| Microsoft (Graph + Outlook) ↗ | PurposeMicrosoft 365 mail integration | Data processedCustomer-authorised mailbox messages (read-only) | RegionEU | DPAView ↗ |
| Otter.ai ↗ | PurposeMeeting transcript ingestion (customer-initiated) | Data processedMeeting transcripts the customer chooses to forward | RegionUS | DPAView ↗ |
| Fireflies.ai ↗ | PurposeMeeting transcript ingestion | Data processedMeeting transcripts the customer chooses to forward | RegionUS | DPAView ↗ |
| Fathom ↗ | PurposeMeeting transcript ingestion | Data processedMeeting transcripts the customer chooses to forward | RegionUS | DPAView ↗ |
| Read.ai ↗ | PurposeMeeting transcript ingestion | Data processedMeeting transcripts the customer chooses to forward | RegionUS | DPAView ↗ |
| Granola ↗ | PurposeMeeting note ingestion via email forwarding | Data processedMeeting notes the customer chooses to forward | RegionUS | DPAView ↗ |
| GitHub ↗ | PurposeSource code repository (not customer data) | Data processedNo customer data — code only | RegionUS | DPAView ↗ |
Change notification
When we add, replace, or remove a sub-processor, we email every organisation owner at least 30 days in advance. You can object to a change by writing to dpo@michiplatform.com. If we can't resolve the objection, you have the right to terminate your subscription and receive a pro-rata refund.
Data residency
All primary storage (Supabase) and email delivery (Resend) is in the EU. Some sub-processors are US-based, and when EU customers use them, transfers rely on the EU-US Data Privacy Framework and the relevant Standard Contractual Clauses. See our DPA for details.