Last updated: July 24, 2026
When your organization uses Vogata, the chain of responsibility over data is simple and declared: your organization is the controller of its people's work content, Vogata acts as processor (we process that data following its instructions, never for our own purposes), and behind Vogata there is a short, public list of subprocessors that make the service possible. This page shows who they are and the safeguards each one operates under, with their data processing agreements (DPAs) one click away.
Vogata's data processing agreement
Vogata's Data Processing Agreement (DPA) with your organization is incorporated by reference into our Terms of Service. It governs the subject matter and purpose of processing, security measures, incident notification, assistance with data subject rights, and deletion or return of data when the service ends. If your organization's legal team needs a copy for review, write to [email protected] and we will send it the same day.
Our clouds
Vogata's infrastructure and AI models run on the three major clouds. Their data processing agreements are automatically incorporated into our agreements with them and carry the international transfer safeguards; you can read or download them from their official source, always the current version:
| Cloud | What it does for Vogata | Safeguards |
|---|---|---|
| Amazon Web Services | Core infrastructure: database, compute, email, and authentication (us-east-2, Ohio) | AWS Data Processing Addendum (PDF) · Customer Agreement |
| Google Cloud | Notetaker infrastructure and AI inference (Gemini); Google Calendar and Meet only if you connect your account | Cloud Data Processing Addendum |
| Microsoft Azure | Microsoft sign-in and Outlook/Teams calendar only if you connect your account; AI inference (Azure OpenAI) | Microsoft Products and Services DPA |
We keep dated, archived copies of each of these documents as compliance evidence; they are available on request for audits.
Other providers
| Provider | What it does for Vogata | Safeguards |
|---|---|---|
| Anthropic PBC | AI inference (Claude) | Commercial Terms (no training on customer data) |
| xAI | AI inference (Grok) | xAI legal & privacy |
| Cloudflare | CDN and site protection | Cloudflare Customer DPA |
| PayPal | Subscription payment processing | PayPal privacy statement (handles payment data as its own controller) |
Our commitments on this list
Every AI provider operates through its paid business tier, with the contractual commitment not to use your data to train its models. We never sell data to third parties. And if this list changes (we add, remove, or replace a provider), we will give reasonable advance notice, because your organization has the right to know the full chain that processes its people's data.
The detail of what data each provider processes, where, and for how long lives in our Privacy Policy. Questions from your legal team? [email protected].