Privacy PolicyTerms of ServiceSubprocessorsCookie NoticeSMS Policy

What is a subprocessor

## A vendor that processes personal data on our behalf to help operate the service.

A subprocessor is a third party we engage to process personal data on our behalf — for example, the cloud provider that hosts our database, the payment processor that handles billing, or the email service that delivers your account verification codes. Subprocessors don't get general access to customer data. They each receive only the specific data they need to perform their function, under contracts that require confidentiality, security, and authorized use only.

Some terminology you may see in procurement reviews: under GDPR Article 28, subprocessors are sometimes called "sub-processors." Under CCPA, equivalent vendors are called "service providers" or "contractors." We treat all three categories under the same operational standard.

How we select and manage them

## The standards every subprocessor must meet.

Before engaging a subprocessor, we evaluate their security posture, privacy practices, applicable certifications (SOC 2, ISO 27001, where relevant), data handling commitments, and contractual terms. Once engaged, each subprocessor is bound by a written agreement that requires them to:

- Process data only on our documented instructions.
- Maintain confidentiality of customer data.
- Implement appropriate technical and organizational security measures.
- Notify us of personal data breaches without undue delay.
- Support our customers' data subject rights requests.
- Permit audits to the extent required by applicable law.
- Apply equivalent obligations to any of their own subprocessors.

We review the subprocessor list regularly and remove vendors we no longer need.

Current subprocessors

## The complete list of third parties that process personal data on our behalf.

| Subprocessor | Purpose | Data accessed | Location |
| --- | --- | --- | --- |
| **Supabase** | Authentication, database, file storage | Account data, customer content | United States (AWS us-east-1) |
| **Vercel** | Hosting, CDN, serverless functions | Device/log data, request metadata | United States with global edge |
| **Stripe** | Payment processing, billing | Billing data, payment metadata | United States |
| **Resend** | Transactional email (codes, resets, receipts) | Email address, message contents | United States |
| **Twilio** | SMS verification codes (opt-in only) | Phone number, verification metadata | United States |
| **Instantly** | Lead email nurture / follow-up (after form opt-in) | Email, name, website | United States |
| **Calendly** | Scheduling discovery & strategy calls | Name, email, scheduling details | United States |
| **Google (OAuth)** | Optional "Sign in with Google" | Email, name, Google account ID | United States with global edge |
| **Google (Tag Manager & Analytics 4)** | Consent-gated site analytics — GA4 loads via Google Tag Manager only after you allow Analytics cookies | Usage and device data (after Analytics consent) | United States with global edge |
| **Cloudflare** | DNS, DDoS protection, security | IP address, request metadata | Global edge |
| **NameBright** | Domain registrar | Domain ownership records | United States |

The list on your account may differ slightly depending on the features you use (e.g., Twilio applies only if you've opted into SMS recovery; Google applies only if you sign in with Google).

International transfers

## How data moves across borders, and the legal protections in place.

Most of our subprocessors are located in the United States. For customers in the EU, EEA, UK, or Switzerland whose personal data is transferred to the US, we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and equivalent mechanisms under Swiss law. The same safeguards apply to data transferred onward by our subprocessors. Full details in our Privacy Policy and Data Processing Addendum.

Notification of changes

## How we tell you before a subprocessor changes.

We notify customers at least 30 days before adding or replacing a subprocessor that processes personal data, except where shorter notice is reasonably necessary for security or legal reasons.

Notification is delivered by:

- Update to this page (with date in the changelog below).
- Email to subscribers of this page (sign up below).
- In-product notification to administrative contacts on paid plans.

If you object to a new subprocessor on reasonable data protection grounds, contact us at [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) within 15 days of the notice. We'll work with you in good faith to identify a commercially reasonable alternative. If no resolution is reached, you may terminate the affected services for convenience and receive a pro-rata refund per the Data Processing Addendum.

Get notified of changes

## Subscribe to receive email notice when this list is updated.

Prefer a feed reader? Subscribe to the [RSS feed](https://www.aisyndicate.com/subprocessors.rss).

Changelog

## A record of past additions, removals, and changes.

| Date | Change | Effective |
| --- | --- | --- |
| July 6, 2026 | Disclosure update: listed Google (Tag Manager + Google Analytics 4), already in use for consent-gated site analytics, which the list previously omitted. Also noted that the consent-gated ad pixels are accompanied by matching conversion events (Meta Conversions API, OpenAI conversion API) — like the pixels, these are advertising disclosures covered in the Privacy Policy, not data-processing subprocessors. | Immediately (correction of an omission, not a new engagement) |
| June 25, 2026 | Clarified that consent-gated advertising pixels (Meta, OpenAI) are disclosed in the Privacy Policy's How-we-share section; they are not data-processing subprocessors. | Immediately |
| May 11, 2026 | Initial publication. | Immediately |

Data Processing Addendum

## For customers who need a signed DPA.

If you process personal data of EU, UK, or California residents through AI Syndicate, we make a Data Processing Addendum available on request. The DPA incorporates the SCCs and UK IDTA, lists the same subprocessors as this page, and supplements our Terms of Service.

To request a copy, email [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) with your company name and the email address that should appear on the signature block.

Contact

## Questions about our subprocessors.

Email [privacy@aisyndicate.com](mailto:privacy@aisyndicate.com) with any question about our subprocessors, the data they process, or how to exercise your data rights. We respond within 30 days — usually much sooner.

**AI Syndicate Collective LLC** 7901 4TH ST N, STE 300 St. Petersburg, FL 33702 United States

## Need a signed DPA or have a subprocessor question?

Email us. Most procurement teams get their answer the same day.

[Email privacy@aisyndicate.com](mailto:privacy@aisyndicate.com?subject=Subprocessor%20Question)View Privacy Policy