Sub-processors
Effective 2026-07-28 · Version 1.0 · Last updated 2026-08-09This page lists the third parties ("sub-processors") that Vista del Lago Software LLC engages to Process personal data on behalf of our customers in connection with Lonzo. It is incorporated by reference into our Data Processing Addendum (DPA) and satisfies the general written authorization requirement under GDPR Art. 28 and equivalent US state-law flow-down requirements.
We deliberately keep our sub-processor footprint small. Every sub-processor below is engaged only to the extent necessary to provide the Service, is bound by written data-protection terms at least as protective as our DPA, and Processes only the categories of data described in its row.
How we notify you of changes
We publish the current sub-processor list on this page with a "last updated" date. This page is the notice mechanism: the authoritative way to see our current sub-processors and any pending changes is to check this page, where changes are posted with an updated date. You can also subscribe to change notifications by emailing privacy@lonzo.ai with the subject "Subscribe: sub-processor changes", and we will notify you at that address whenever we post a change.
Before we add or replace a sub-processor that will Process customer personal data, we post at least thirty (30) days' advance notice on this page and notify subscribers to the change-notification subscription above. A customer subject to our DPA may object on reasonable data-protection grounds within thirty (30) days of that notice by writing to privacy@lonzo.ai. If no objection is received within that window, the change is deemed accepted. If a customer objects and we cannot resolve the objection, the customer may terminate the portion of the Service that cannot be provided without the objected-to sub-processor, without penalty, as its sole remedy.
Data location
All of our sub-processors Process data in United States regions (AWS us-*, Google US). This keeps our transfer story simple — a single US destination — while requiring the Standard Contractual Clauses / Data Privacy Framework apparatus in our DPA for personal data originating in the EEA, the United Kingdom, or Switzerland.
Current sub-processors
Infrastructure and core services
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| Google (Gmail, Calendar, Contacts, Tasks APIs) | Authoritative source of the user's email, calendar, contacts, and tasks. Vista del Lago Software LLC holds caches only; Google remains the system of record. In the MVP, all outbound email is sent through the user's own Gmail — Vista del Lago Software LLC sends no email from its own identity. | Email content and metadata, calendar events, contacts, tasks | USA |
| AWS (compute & storage — data hosting) | Hosts the Lonzo application, compute, and primary data store. The encrypted caches of Gmail message bodies (held as Pins) and the derived assistant memory are hosted here, encrypted under per-actor keys. | Encrypted Gmail body caches, derived assistant memory, encrypted account data | USA |
| AWS Simple Storage Service (S3) | Stores the encrypted audit trail. | Encrypted audit records | USA |
Artificial intelligence / inference
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| AWS Bedrock (models: Nova, Claude, Titan) | Large-language-model inference and embeddings that power the assistant. Model content is Processed within Bedrock; the underlying model providers are not engaged by Vista del Lago Software LLC directly. | Email, calendar, and task content submitted as inference prompts, and the outputs generated from them | USA |
Inference is a core, always-on part of Lonzo; it is not an optional toggle.
Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum (which incorporates the EU Standard Contractual Clauses); Amazon Bedrock is also a HIPAA-eligible service under BAA and is in scope for AWS SOC and ISO 27001/27017/27018 reports.
Payments and billing
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| Google Play (Billing) | The sole payment channel. All purchase and subscription billing. Google holds the payment method directly; Vista del Lago Software LLC receives no card data. | Purchase tokens, subscription identifiers | USA |
Security services
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| Have I Been Pwned (HIBP) | Checks whether a chosen password appears in known breach corpora, using k-anonymity: only a partial SHA-1 hash prefix (first 5 characters) ever leaves our system. | Partial password hash prefix only — no full credential, no email address, no other personal data | USA / UK service |
Because only a 5-character hash prefix is transmitted, HIBP arguably does not Process personal data at all. We list it here for transparency rather than because disclosure is required.
Third-party functional asset providers (no user data)
These content-delivery networks serve static front-end assets (fonts and rendering libraries) to the browser. They receive only the requesting browser's IP address as an inherent part of an HTTP request; they receive no user account data, email, calendar, or other personal content, set no cookies we control, and perform no tracking. They are listed for transparency.
| Provider | Purpose | Data categories processed | Location |
|---|---|---|---|
| Google Fonts (fonts.googleapis.com / fonts.gstatic.com) | Delivers the Inter web font to the browser. | IP address only (no user data) | USA |
| jsDelivr / Cloudflare CDN | Delivers the KaTeX, highlight.js, and Mermaid rendering libraries to the browser. | IP address only (no user data) | Global CDN |
We intend to self-host the Inter font and vendor the KaTeX/highlight.js/Mermaid assets to eliminate these third-party calls; until then, we disclose them here.
What we do not use
Vista del Lago Software LLC uses no third-party product-analytics, error-tracking, crash-reporting, customer-support-desk, or CRM sub-processors. We do not embed analytics or tracking SDKs, and no such vendor touches your data. Keeping this footprint deliberately small is a privacy design choice, not an omission from this list.
Not active — reserved for a coordination feature we do not currently offer
The sub-processors below would support a coordination feature that sends outbound email or SMS from Lonzo's own identity. That feature is not offered and none of these data flows are active. Lonzo is Gmail-only: it sends no email or SMS from an identity of its own. They are listed for transparency, and we will update this page — with the notice period described above — before any of them becomes active.
| Sub-processor | Purpose | Data categories processed | Location |
|---|---|---|---|
| AWS Simple Email Service (SES) | Would send and receive email as a Lonzo assistant identity, distinct from acting on your own Gmail. Not active. | Email headers and bodies sent or received by the assistant identity | USA |
| AWS End User Messaging | Would provide SMS delivery. Not active. | Phone numbers, message content | USA |
Affiliate sub-processors
Vista del Lago Software LLC engages no affiliate or subsidiary sub-processors. No Vista del Lago Software LLC affiliate or contractor Processes customer personal data.
The complete active set. The sub-processors that Process customer personal data are: Google, AWS (compute and storage), AWS S3 (audit trail), AWS Bedrock (inference), and Google Play (the sole payment channel). HIBP receives only a k-anonymized hash prefix, and the functional CDNs (Google Fonts, jsDelivr/Cloudflare) receive only an IP address. There are no others. Any additional sub-processor — including any future payment processor, product-analytics, error-tracking, support-desk, or CRM vendor — will be added to this page, with the notice period described above, before it Processes customer personal data.