Sub-processors
Effective 2026-08-18 · Version 2.6 · Last updated 2026-08-18This page lists the third parties ("sub-processors") that Vista del Lago Software LLC engages to Process personal data on behalf of our customers in connection with Lonzo. It is incorporated by reference into our Data Processing Addendum (DPA) and satisfies the general written authorization requirement under GDPR Art. 28 and equivalent US state-law flow-down requirements.
We deliberately keep our sub-processor footprint small. Every sub-processor below is engaged only to the extent necessary to provide the Service, is bound by written data-protection terms at least as protective as our DPA, and Processes only the categories of data described in its row.
How we notify you of changes
We publish the current sub-processor list on this page with an effective date and a version. This page is the notice mechanism, and it is the only one: the authoritative way to see our current sub-processors, and any pending change, is to check this page.
We are not offering an email subscription, and we want to say why rather than let you assume the option exists. A page that invites you to subscribe to notifications has made a promise that only a maintained mailing list can keep, and we do not operate one. Rather than accept subscriptions into a list that might not be there when a change is posted, we have made the page itself the commitment: the advance-notice period below runs from the date posted here, and it is long enough that checking this page before you rely on it is a real option. If your organization needs to be told directly when a change is posted, write to privacy@lonzo.ai and we will agree that in writing with you under the Data Processing Addendum — an individually agreed obligation we can actually honor, in place of a general one we cannot.
Before we add or replace a sub-processor that will Process customer personal data, we post at least thirty (30) days' advance notice on this page, and we notify any customer with whom we have separately agreed in writing to give direct notice. A customer subject to our DPA may object on reasonable data-protection grounds within thirty (30) days of that notice by writing to privacy@lonzo.ai. If no objection is received within that window, the change is deemed accepted. If a customer objects and we cannot resolve the objection, the customer may terminate the portion of the Service that cannot be provided without the objected-to sub-processor, without penalty, as its sole remedy.
Data location
All of our sub-processors Process data in United States regions (AWS us-*, Google US). This keeps our transfer story simple — a single US destination — while requiring the Standard Contractual Clauses / Data Privacy Framework apparatus in our DPA for personal data originating in the EEA, the United Kingdom, or Switzerland.
Current sub-processors
Infrastructure and core services
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| Google (Gmail, Calendar, Contacts, Tasks APIs) | Authoritative source of the user's email, calendar, contacts, and tasks. Vista del Lago Software LLC holds a fifteen-minute in-process cache of a message body it fetches, and keeps the text of a conversation the assistant is asked to work on for as long as the account exists; Google remains the system of record. All email the Service sends on the user's behalf is sent through the user's own Gmail account, from the user — both replies and messages to the people they correspond with, and every coordination message the Service originates to a third-party participant at their direction. | Email content and metadata (including the coordination messages sent to participants and the participants' replies), calendar events, contacts, tasks | USA |
| AWS (compute & storage — data hosting) | Hosts the Lonzo application, compute, and primary data store. The encrypted caches of Gmail message bodies (held as Pins) and the derived assistant memory are hosted here, encrypted under per-actor keys. | Encrypted Gmail body caches, derived assistant memory, encrypted account data | USA |
| AWS Simple Storage Service (S3) | Stores the encrypted audit trail. | Encrypted audit records | USA |
| AWS Simple Email Service (SES) | Sends and receives mail from our own addresses on lonzo.ai. Two uses: service and account mail to the address on the user's account (address verification, password reset, and similar); and inbound mail addressed to our published role addresses (support@, privacy@, legal@, security@, abuse@) and to the per-message unsubscribe+<token>@lonzo.ai opt-out address, which is received here. It does not carry coordination messages to participants — those are sent through the user's own Gmail account, from the user, and appear on the Google row above. Mail to privacy@, legal@, security@ and abuse@ is forwarded to an operator mailbox and read by a person. Mail to support@ is answered automatically by the assistant from our published help pages, and reaches a person when the assistant cannot answer it, when you ask for a person, or when it concerns privacy, legal, security, abuse, or account deletion — those we always route to a person, never to an automatic reply. SES also returns bounce and complaint feedback for the mail we send, which we record so we can stop mailing an address that bounces or complains. | The account email address; headers and bodies of account and service mail; headers and bodies of mail sent to a role address or to an opt-out address; bounce and complaint reports, including the affected recipient address | USA |
Artificial intelligence / inference
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| AWS Bedrock (models: Nova, Claude, Titan) | Large-language-model inference and embeddings that power the assistant. This includes answering mail sent to support@: the subject and body of your message are submitted as an inference prompt so the assistant can answer it from our published help pages. Model content is Processed within Bedrock; the underlying model providers are not engaged by Vista del Lago Software LLC directly. | Email, calendar, and task content submitted as inference prompts, including the subject and body of a message sent to support@, and the outputs generated from them | USA |
Inference is a core, always-on part of Lonzo; it is not an optional toggle.
Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum (which incorporates the EU Standard Contractual Clauses), and Amazon Bedrock is in scope for AWS SOC and ISO 27001/27017/27018 reports. Bedrock is additionally a HIPAA-eligible AWS service, but that eligibility is AWS's and does not extend to us: we hold no Business Associate Agreement with AWS or with any customer, we offer none, and the Service must not be used to process protected health information. See Consumer Health Data Privacy Policy, Section 11.
Payments and billing
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| Google Play (Billing) | The sole payment channel. All purchase and subscription billing. Google holds the payment method directly; Vista del Lago Software LLC receives no card data. | Purchase tokens, subscription identifiers | USA |
Security services
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| Have I Been Pwned (HIBP) | Checks whether a chosen password appears in known breach corpora, using k-anonymity: only a partial SHA-1 hash prefix (first 5 characters) ever leaves our system. | Partial password hash prefix only — no full credential, no email address, no other personal data | USA / UK service |
Because only a 5-character hash prefix is transmitted, HIBP arguably does not Process personal data at all. We list it here for transparency rather than because disclosure is required.
Third-party functional asset providers (none)
This section is now empty, and that is the whole of it. Every front-end asset the browser loads — code, styles, icons, and the typeface the interface is set in — is served from our own storage. No third party receives your IP address when you use the web app. That statement is about two things, not one: which servers the browser is asked to contact, and who operates the server it does contact. No content-delivery network, WAF, or other shared cache stands in front of our origin — requests for lonzo.ai reach machines we run. A cache placed in front of us would receive the address of every visitor to every page while every asset remained self-hosted, so it would be a sub-processor addition under the notice section above, and it would appear in this section before it carried a request.
Two providers used to be listed here. Both were removed, in the order they were removed, because a page that promises thirty days' notice before a sub-processor is added means nothing if the list is not maintained downward as well. Removing a sub-processor needs no advance notice under the section above, which governs adding or replacing one; we record both here so the change is visible in this page's history instead of only in its absence.
- The jsDelivr / Cloudflare CDN — removed 2026-08-15. It delivered the KaTeX, highlight.js, and Mermaid rendering libraries to the browser. Those are now committed copies served from our own origin. We removed it for security rather than privacy — a script loaded from another origin into the page that holds your live session is a compromise of that origin waiting to happen — but the privacy effect is the one this section is about: one fewer third party ever sees your IP address.
- Google Fonts — removed 2026-08-17. It delivered the Inter web font to the browser and received the requesting browser's IP address every time someone opened the web app, including a visit that ended at the sign-in screen — so before there was an account or any agreement in place. (These published pages are plain documents and request nothing from a third party.) Earlier versions of this page said we intended to self-host the font, "which would leave this section empty". The font files are now served from our own storage, and this section is empty.
What we do not use
Vista del Lago Software LLC uses no third-party product-analytics, error-tracking, crash-reporting, customer-support-desk, or CRM sub-processors. We do not embed analytics or tracking SDKs, and no such vendor touches your data. Keeping this footprint deliberately small is a privacy design choice, not an omission from this list.
Not active — reserved for SMS, which we do not currently send
The Service sends no SMS or text messages. The sub-processor below would provide that channel if we add it; that data flow is not active, and we will update this page — with the notice period described above — before it becomes active.
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| AWS End User Messaging | Would provide SMS delivery. Not active. | Phone numbers, message content | USA |
Affiliate sub-processors
Vista del Lago Software LLC engages no affiliate or subsidiary sub-processors. No Vista del Lago Software LLC affiliate or contractor Processes customer personal data.
The complete active set. The sub-processors that Process customer personal data are: Google, AWS (compute and storage), AWS S3 (audit trail), AWS SES (mail sent from and received at our own Lonzo addresses), AWS Bedrock (inference), and Google Play (the sole payment channel). HIBP receives only a k-anonymized hash prefix, and there is no longer any functional asset provider at all — every front-end asset is served from our own storage. There are no others. Any additional sub-processor — including any future payment processor, product-analytics, error-tracking, support-desk, or CRM vendor, and including any content-delivery network, WAF, or other shared cache placed in front of our origin — will be added to this page, with the notice period described above, before it Processes customer personal data. The content-delivery network is named explicitly because our server software already contains the integration for one and it is switched on by configuration rather than by code, which makes it the addition least likely to announce itself; a check on our source refuses that configuration change unless this page and the Cookie & Local Storage Notice have been changed first.