This is a starting template. It describes how the platform actually works, but it has not been reviewed by a lawyer for your jurisdiction. Have it checked before you rely on it.
Who we rely on
These are the third parties that may process customer data on our behalf. Each is bound by a written agreement no less protective than our own commitments.
Complete this table with your actual vendors before publishing. An inaccurate sub-processor list is worse than none, customers rely on it, and a missing name is a breach of your own DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hosting provider | Application and database hosting | To be confirmed |
| Object storage | File and attachment storage | To be confirmed |
| Stripe | Payment processing | To be confirmed |
| Email delivery | Transactional and campaign email | To be confirmed |
| AI provider | Optional AI features, where enabled | To be confirmed |
Changes
We notify customers before adding a sub-processor. To be told, email privacy@example.com and ask to be added to the notification list.