Legal · Effective July 6, 2026

Subprocessors for AI Syndicate.

We rely on a small set of vendors ("subprocessors") to operate the AI Syndicate platform. Each subprocessor is bound by a written data processing agreement, processes data only on documented instructions, and is restricted to the data categories listed below. We choose subprocessors with strong security and privacy postures and review them periodically.

Legal entity
AI Syndicate Collective LLC, a Florida LLC
Effective date
July 6, 2026
Notice of changes
At least 30 days before adding or replacing a subprocessor. Subscribe below.
No sale of data
Subprocessors process data on our behalf only. We don't sell your data; ad-related sharing is limited to consent-gated pixels and conversion events (see Privacy Policy).
What is a subprocessor

A vendor that processes personal data on our behalf to help operate the service.

A subprocessor is a third party we engage to process personal data on our behalf — for example, the cloud provider that hosts our database, the payment processor that handles billing, or the email service that delivers your account verification codes. Subprocessors don't get general access to customer data. They each receive only the specific data they need to perform their function, under contracts that require confidentiality, security, and authorized use only.

Some terminology you may see in procurement reviews: under GDPR Article 28, subprocessors are sometimes called "sub-processors." Under CCPA, equivalent vendors are called "service providers" or "contractors." We treat all three categories under the same operational standard.

How we select and manage them

The standards every subprocessor must meet.

Before engaging a subprocessor, we evaluate their security posture, privacy practices, applicable certifications (SOC 2, ISO 27001, where relevant), data handling commitments, and contractual terms. Once engaged, each subprocessor is bound by a written agreement that requires them to:

  • Process data only on our documented instructions.
  • Maintain confidentiality of customer data.
  • Implement appropriate technical and organizational security measures.
  • Notify us of personal data breaches without undue delay.
  • Support our customers' data subject rights requests.
  • Permit audits to the extent required by applicable law.
  • Apply equivalent obligations to any of their own subprocessors.

We review the subprocessor list regularly and remove vendors we no longer need.

Current subprocessors

The complete list of third parties that process personal data on our behalf.

SubprocessorPurposeData accessedLocation
SupabaseAuthentication, database, file storageAccount data, customer contentUnited States (AWS us-east-1)
VercelHosting, CDN, serverless functionsDevice/log data, request metadataUnited States with global edge
StripePayment processing, billingBilling data, payment metadataUnited States
ResendTransactional email (codes, resets, receipts)Email address, message contentsUnited States
TwilioSMS verification codes (opt-in only)Phone number, verification metadataUnited States
InstantlyLead email nurture / follow-up (after form opt-in)Email, name, websiteUnited States
CalendlyScheduling discovery & strategy callsName, email, scheduling detailsUnited States
Google (OAuth)Optional "Sign in with Google"Email, name, Google account IDUnited States with global edge
Google (Tag Manager & Analytics 4)Consent-gated site analytics — GA4 loads via Google Tag Manager only after you allow Analytics cookiesUsage and device data (after Analytics consent)United States with global edge
CloudflareDNS, DDoS protection, securityIP address, request metadataGlobal edge
NameBrightDomain registrarDomain ownership recordsUnited States

The list on your account may differ slightly depending on the features you use (e.g., Twilio applies only if you've opted into SMS recovery; Google applies only if you sign in with Google).

International transfers

How data moves across borders, and the legal protections in place.

Most of our subprocessors are located in the United States. For customers in the EU, EEA, UK, or Switzerland whose personal data is transferred to the US, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and equivalent mechanisms under Swiss law. The same safeguards apply to data transferred onward by our subprocessors. Full details in our Privacy Policy and Data Processing Addendum.

Notification of changes

How we tell you before a subprocessor changes.

We notify customers at least 30 days before adding or replacing a subprocessor that processes personal data, except where shorter notice is reasonably necessary for security or legal reasons.

Notification is delivered by:

  • Update to this page (with date in the changelog below).
  • Email to subscribers of this page (sign up below).
  • In-product notification to administrative contacts on paid plans.

If you object to a new subprocessor on reasonable data protection grounds, contact us at privacy@aisyndicate.com within 15 days of the notice. We'll work with you in good faith to identify a commercially reasonable alternative. If no resolution is reached, you may terminate the affected services for convenience and receive a pro-rata refund per the Data Processing Addendum.

Get notified of changes

Subscribe to receive email notice when this list is updated.

We'll only email you about subprocessor changes. Unsubscribe any time.

Prefer a feed reader? Subscribe to the RSS feed.

Changelog

A record of past additions, removals, and changes.

DateChangeEffective
July 6, 2026Disclosure update: listed Google (Tag Manager + Google Analytics 4), already in use for consent-gated site analytics, which the list previously omitted. Also noted that the consent-gated ad pixels are accompanied by matching conversion events (Meta Conversions API, OpenAI conversion API) — like the pixels, these are advertising disclosures covered in the Privacy Policy, not data-processing subprocessors.Immediately (correction of an omission, not a new engagement)
June 25, 2026Clarified that consent-gated advertising pixels (Meta, OpenAI) are disclosed in the Privacy Policy's How-we-share section; they are not data-processing subprocessors.Immediately
May 11, 2026Initial publication.Immediately
Data Processing Addendum

For customers who need a signed DPA.

If you process personal data of EU, UK, or California residents through AI Syndicate, we make a Data Processing Addendum available on request. The DPA incorporates the SCCs and UK IDTA, lists the same subprocessors as this page, and supplements our Terms of Service.

To request a copy, email privacy@aisyndicate.com with your company name and the email address that should appear on the signature block.

Contact

Questions about our subprocessors.

Email privacy@aisyndicate.com with any question about our subprocessors, the data they process, or how to exercise your data rights. We respond within 30 days — usually much sooner.

AI Syndicate Collective LLC
7901 4TH ST N, STE 300
St. Petersburg, FL 33702
United States

Need a signed DPA or have a subprocessor question?

Email us. Most procurement teams get their answer the same day.

Email privacy@aisyndicate.comView Privacy Policy