Skip to main content
Setor AI uses the following third-party subprocessors to provide the service. As our customer, you authorise us to use these processors under the terms of our Data Processing Agreement. We provide at least 14 days’ advance notice before adding or replacing any subprocessor, and you may object on documented data-protection grounds within that notice period.
This list reflects the current named subprocessors. The authoritative versioned list is always published at https://setor.ai/subprocessors. To object to a subprocessor change, email [email protected].

AI Models

Setor AI uses multiple AI providers to analyse messages, understand intent, generate responses, transcribe voice notes, synthesise voice, and process images and video content. Data processed: DM message content, voice note audio, image metadata. Processing is transient — data is not retained by AI sub-processors after session completion, except for limited abuse-prevention logging (typically 30 days, auto-deleted). No AI sub-processor uses your data to train its own general models. Transfer mechanism: SCC (EU 2021/914) or EU-US DPF where applicable. Transfer Impact Assessments conducted for all US processors.

Hosting and Infrastructure

Data processed: All customer and end-user data as required to operate the platform. The primary database is located within the EEA (Germany). Cloudflare processes network-layer data for routing, security, and performance. Retention: Data is retained for the periods specified in the Privacy Policy and Data Processing Agreement.

Payments

Data processed: Billing name and address, last four digits of payment card, transaction identifiers, subscription status. Stripe is PCI-DSS Level 1 certified — full card details are collected and stored exclusively by Stripe and never touch Setor AI servers.

Email and Communication

Data processed: Email address, notification content. Message channel data (Instagram DMs) is processed via Meta under the Meta Platform Terms.

Analytics and Session Recording

Data processed: Usage events, page views, interaction patterns, session recordings. Analytics and session recording scripts load only after your prior active consent — they are not loaded on page load by default. Microsoft Clarity: All text input fields are masked by default — no form content or personal text is captured in session recordings. PostHog: First-party data only; EU data residency (Frankfurt); not used for PostHog’s own advertising; data not shared with third parties for advertising purposes. Retention: Up to 36 months, then deletion or anonymisation.

Marketing Attribution

Data processed (consent required): Hashed identifiers (SHA-256 hashed email, phone, first name, last name, external ID), conversion events, browsing behaviour on setor.ai. Raw IP addresses are never stored in analytics systems. An ip_hash pseudonym may be used solely to link events from the same lead across devices — it is never used as an identity key. US transfers for Meta are covered by the EU-US Data Privacy Framework (DPF), with SCC (2021/914) as automatic fallback.

CRM and Scheduling

Data processed: Contact records, meeting booking data, support ticket content as necessary for the respective function. Scheduling integrations process calendar availability and meeting metadata.

Public Data Verification

Data processed: Publicly available Instagram profile data only (follower count, business category, account activity). Used solely to verify eligibility of accounts submitted in onboarding forms — not for monitoring or surveillance of end users.

Video and Content

Data processed: Video view events, playback progress. Used to deliver and measure engagement with embedded video content on setor.ai pages.

Sub-processor Change Notification

Setor AI follows a formal procedure for all sub-processor additions and changes:
1

Advance notice

Setor AI sends you at least 14 days’ advance notice by email of any planned addition or replacement of a sub-processor. Notices are also reflected in the versioned list at setor.ai/subprocessors.
2

Object if needed

You may object to a proposed change on documented, justified data-protection grounds specific to that sub-processor. Objections must be submitted to [email protected] within the 14-day notice period.
3

Resolution

Upon a valid objection, Setor AI and you will negotiate in good faith to find a solution. If no agreement is reached, your sole remedy is to terminate the affected portion of the service. An objection does not constitute a veto over Setor AI’s operations.
4

Acceptance

Silence after the 14-day notice period is treated as acceptance. By continuing to use the service after the notice period expires, you accept the new or changed sub-processor.
For the full named and versioned subprocessor list, visit https://setor.ai/subprocessors. To object to a subprocessor change, email [email protected].