OXYGENOXYGEN

Subprocessors

Last Updated: August 15, 2026

1. Scope

OXYGEN GTM Inc. uses subprocessors to provide hosting, identity, billing, analytics, AI, integration, enrichment, observability, and support functions for OXYGEN. Actual subprocessors vary based on the integrations, workflows, providers, and done-for-you services a customer enables.

2. Current Subprocessors

ProviderPurpose
ClerkAuthentication, user identity, OAuth
NeonManaged Postgres for control and tenant databases
VercelApplication hosting, web analytics where enabled
Fly.ioBackground worker compute for table, workflow, and provider runs
Hetzner OnlineObject storage for table import files
StripeBilling and payment processing
PostHogProduct and website analytics; session recording of the signed-in application, which can capture workspace content displayed on screen; and MCP tool-call telemetry, which carries the arguments sent to a tool and the result it returned and can therefore contain workspace content
AxiomOperational logs, traces, and telemetry
Anthropic and other AI model providersAI model processing where configured or instructed
UnipileEmail, LinkedIn, and messaging integration access where configured
ComposioCRM and productivity integration access where configured
Enrichment and data providersContact, company, email, phone, and account enrichment where selected

Session recording applies to the signed-in OXYGEN application only, and only where a user has allowed optional analytics. It is excluded on authentication, credential, API-token, vault, billing, and payment screens, and a recording captures the rendered page rather than network traffic, so request and response bodies, provider payloads, and AI prompts do not appear in a recording.

MCP tool-call telemetry is a separate transmission and is not limited in the same way. When a tool on the OXYGEN MCP server is called, the arguments sent to that tool and the result it returned are transmitted to PostHog alongside the tool name, timing, and outcome, and can therefore contain workspace content such as contact records, search terms, and message content. It is processed server-side and is not governed by the cookie banner. An automated filter redacts fields named like credentials, omits a fixed set of bulk-content field names, scans remaining text for credential material such as bearer tokens and database URLs, and truncates the payload by length, breadth, and nesting depth; that filter works on field names and credential shapes, so it does not remove personal data written into free-text fields and is not a guarantee that every secret is caught. AI prompts and model outputs, server logs and stack traces, and payment card data are not transmitted to PostHog at all. Section 13 of the Privacy Policy describes both in full.

3. Provider-Specific Tools

OXYGEN also exposes customer-selected tool and enrichment providers. When Customer runs a provider tool, the provider receives the input necessary to perform that operation. Customer is responsible for selecting providers appropriate for its legal basis, jurisdictions, and data-protection obligations.

4. Notices & Objections

OXYGEN will update this page before a new subprocessor processes customer personal data, and before an existing subprocessor begins processing a materially new category of it. The August 15, 2026 update is of the second kind: PostHog already processed analytics and session recordings, and now also receives MCP tool-call arguments and results. Customers may object on reasonable data protection grounds within 30 days of the update by contacting philipp@oxygen-agent.com.