Vistaly
English Español Deutsch Français 日本語 Português
ログイン (V1) ワークスペースへ
English Español Deutsch Français 日本語 Português
ログイン (V1) ワークスペースへ

AI Subprocessors & Data Processing

Last updated: May 2026

This page details the third-party subprocessors involved in AI-powered features within the Vistaly platform. It describes what data is processed, where it is processed and stored, and the safeguards in place. For a complete list of all Vistaly subprocessors (including non-AI services), see our Sub-Processors page.

If you have questions about AI data processing, please contact us at dpo@vistaly.com.

Overview

Vistaly uses AI to help product teams synthesize customer conversations into structured opportunity spaces. The core AI capabilities include:

  • Call and interview processing — transcribing and analyzing customer interviews to extract key insights
  • Opportunity space generation — automatically organizing insights into structured opportunity trees
  • Text analysis and summarization — summarizing interview content and identifying patterns across conversations

All AI processing is performed via Anthropic's Claude API. Vistaly does not use OpenAI or any other large language model provider at this time. Anthropic's commercial API terms explicitly state that customer data submitted via the API is not used for model training.

AI Subprocessor Details

Subprocessor Purpose Data Processed Processing Region DPF Data Retention Links
Anthropic PBC Primary AI provider. Anthropic's Claude API powers core AI-driven features within the Vistaly platform, including call processing, interview transcript analysis, insight extraction, summarization, and opportunity space generation. Interview transcripts, call recordings (text), user-provided content submitted to AI features. United States No Anthropic does not use customer data submitted via the API to train its models, per Anthropic Commercial Terms §B. Prompt and completion data may be retained by Anthropic for up to 30 days for abuse monitoring before automatic deletion.
Homepage DPA Commercial Terms Privacy Policy Security
Amazon Web Services, Inc. Infrastructure and data storage. AWS hosts the entire Vistaly application infrastructure, including all databases, file storage, and backups. Customer data at rest — including data used as input to or output from AI features — is stored on AWS in the customer's selected region. Note: authentication (AWS Cognito), payment processing (Stripe), and the account directory always operate in the United States regardless of data residency selection. All customer data, including interview transcripts, AI-generated insights, opportunity spaces, and user account data. Your selected region (US or EU). Authentication, payment, and account directory services always US. Yes Data is retained in accordance with Vistaly's data retention policies and the customer's chosen data residency region. Backups follow the same regional constraints. AWS does not access customer content; model training is not applicable — AWS is an infrastructure provider, not an AI model provider.
Homepage Compliance DPA GDPR Privacy Policy
AssemblyAI, Inc. Speech-to-text transcription. Used in Vistaly's beta product for converting audio and video recordings of customer interviews into text transcripts for further AI analysis. Audio and video recordings of customer interviews submitted for transcription. Your selected region (US or EU) Yes Audio data is processed by AssemblyAI for transcription. Vistaly is enrolled in AssemblyAI's opt-out from the Model Improvement Program; customer audio and transcripts are not used to train AssemblyAI's models.
Homepage DPA GDPR Privacy Policy Security
Product Talk LLC Licensed AI feature provider with platform access. Product Talk licenses AI-powered features integrated into Vistaly, including the Interview Snapshot Generator and OST (Opportunity Solution Tree) Update features. Product Talk does not perform AI inference itself — inference is performed by Anthropic — but has platform access to customer data within Vistaly for product research, service improvement, and quality assurance of the licensed features. Platform access to customer data relevant to the licensed AI features, including interview transcripts and AI-generated insights and opportunity spaces. Data remains within Vistaly's infrastructure; Product Talk does not store or export customer data. Your selected region (US or EU) — access only, data remains in Vistaly's infrastructure No Product Talk does not retain customer data. All data remains within Vistaly's infrastructure and is subject to Vistaly's data retention policies.
Homepage DPA

Data Flow

The following describes how data flows through AI features in Vistaly:

  1. Input: Customer interview recordings or transcripts are uploaded by the user to Vistaly and stored on AWS in the customer's selected data residency region (US or EU).
  2. Transcription (if applicable): Audio/video recordings are sent to AssemblyAI for speech-to-text conversion. The resulting transcript is stored on AWS.
  3. AI Processing: Transcript text is sent to Anthropic's Claude API for analysis, insight extraction, and opportunity space generation. This processing currently occurs in the United States.
  4. Storage: AI-generated outputs (insights, opportunity spaces, summaries) are stored on AWS in the customer's selected data residency region.

Data Residency & Regional Processing

Vistaly offers a choice of data residency region — United States or European Union — which customers select during account creation. All customer data at rest (databases, file storage, and backups) is hosted in the selected region on AWS.

AI processing via Anthropic’s Claude API currently occurs in the United States regardless of the customer’s selected data residency region. For EU-resident customers, interview transcript content is transmitted to the United States for AI processing and the results are returned and stored in the EU region.

In addition to AI processing, certain platform services always operate in the United States regardless of the customer’s chosen data residency region:

  • Authentication services (AWS Cognito) — hosted in the United States for all customers. Processes login credentials, authentication tokens, and email addresses.
  • Payment processing (Stripe) — all payment data is processed in the United States by Stripe, a PCI Service Provider Level I. Vistaly does not handle payment information directly.
  • Account directory — a minimal set of account identifiers (account IDs and URL slugs) is replicated globally to ensure service availability and prevent conflicts across regions. This directory does not contain customer content or personal data beyond account identifiers.

For a complete list of all subprocessors and their data processing regions, see our Sub-Processors page.

Safeguards for Cross-Border Transfers

For all transfers of personal data to subprocessors located outside the customer's chosen region, Vistaly relies on appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) — incorporated into data processing agreements with subprocessors
  • Data Processing Agreements (DPAs) — in place with all AI subprocessors
  • EU-U.S. Data Privacy Framework — relied upon where the subprocessor is certified (AWS is DPF-certified; Anthropic is not currently certified)
  • Encryption in transit — all data transmitted to AI subprocessors uses TLS encryption
  • No model training on customer data — Anthropic's commercial API terms prohibit use of customer data for model training

AI Output Handling

AI-generated content within Vistaly is treated as untrusted text and rendered with the following safeguards:

  • Sanitized rendering — AI outputs are displayed exclusively in sanitized React contexts, never as raw HTML or executable markdown. Outputs cannot trigger code execution, script injection, or cross-site scripting in the user’s browser.
  • No automated side effects — AI outputs are confined to display within the user’s own workspace. They do not initiate outbound network calls, automation, or actions on the user’s behalf without explicit confirmation.
  • Model-level safety controls — Vistaly relies on Anthropic’s built-in safety classifiers (per Anthropic’s Commercial Terms) for harmful-content moderation at the model layer.
  • User reporting — users can flag any AI output for review by contacting dpo@vistaly.com.

For more information, see our Sub-Processors, Privacy Policy, GDPR Compliance Statement, EU AI Act Compliance, and Security Policy.

Vistaly

プロダクトチームのための継続的ディスカバリープラットフォーム。戦略、ディスカバリー、デリバリーをビジュアルにつなぎます。

プロダクト

  • ステータス
  • V1ドキュメント

ログイン

  • ログイン (V1)

法務・セキュリティ

  • セキュリティ
  • トラストセンター
  • プライバシーポリシー
  • 利用規約
  • Cookieポリシー
  • GDPRコンプライアンス

© 2026 Vistaly, Inc. All rights reserved.