Current public list

Virali Subprocessors

Virali provides at least 30 days' notice before a new subprocessor begins processing Customer Personal Data. Customers may submit a reasonable data-protection objection within 15 days. Provider certifications are not Virali certifications.

Active production providers

ProviderPurposeData categoriesStatus
StripePayment processing and recurring subscription management when paid billing is enabledBilling contacts, customer/subscription identifiers, payment and consent metadataActive for paid billing; card data is handled by Stripe rather than stored by Virali
RenderApplication hosting and service runtimeWorkspace account data, logs, configuration metadataLocation/certifications pending vendor review
SupabasePostgres database, Auth, storage, backupsApplication data, Auth data, files, logsLocation/certifications pending vendor review
Resend / configured SMTP providerProduction transactional emailEmail address and email delivery metadataLocation/certifications pending vendor review
Bright DataApproved creator/content analytics workflowsPublic social content URLs and provider job metadataLocation/certifications pending vendor review
Google APIs / GmailUser-authorized email outreach sending and reply synchronizationConnected mailbox identity, email message/thread metadata, message content needed for outreach workflows, OAuth tokens encrypted server-sideActive when a workspace user connects Gmail
OpenAI APIAI-assisted outreach drafting, reply classification, pricing suggestions, and workflow decisionsCreator, campaign, prospect, Outreach conversation context, and relevant Gmail reply content for known Outreach conversations when AI Outreach is enabledActive only when AI Outreach is enabled; Google Workspace API data is not authorized for model training
GitHubSource control and supplemental synthetic health workflowOperational metadata and issue/PR evidenceLocation/certifications pending vendor review

Deferred providers