01What a subprocessor is, and what it is not
Under Article 28 of the GDPR and comparable provisions of US state privacy law, a processor that engages another processor must do so under a written contract imposing equivalent obligations, and must tell the controller who those parties are.
In our case: you are the controller of Customer Data, Nead, LLC is the processor, and the parties listed below are subprocessors.
Not every vendor we use is a subprocessor. A vendor that never receives Customer Data — our accounting software, for instance, or the tool we use to write documentation — is not listed here, because listing it would pad the page without telling you anything about where your data goes.
02Infrastructure subprocessors
These parties host or transmit Customer Data as part of running the service.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Primary compute, database, object storage, and backup | All Customer Data, encrypted at rest and in transit | United States (us-east-1, us-west-2) |
| Cloudflare, Inc. | DNS, TLS termination, CDN, DDoS protection, WAF | Request metadata and content in transit; no persistent storage of Customer Data | Global edge network |
| Twilio SendGrid | Transactional and notification email delivery | Recipient name and address, message content of notifications | United States |
03AI model subprocessors
These parties receive content in order to generate an output for a feature you have enabled. They are listed separately because the questions customers ask about them differ from the questions they ask about hosting.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic, PBC | Language model inference for agents and copilot features | Content submitted to those features — typically document text, transaction detail, and relevant context | United States |
Contractual position with model providers
- No training. Our agreement prohibits the use of content submitted through our service to train or fine-tune the provider’s models.
- Zero or limited retention. Content is retained only as required for abuse monitoring under the terms of our enterprise agreement, and is not used for any other purpose.
- No onward sharing. The provider may not disclose content to third parties except as required by law.
If you would rather no Customer Data reached an AI model provider, agent and copilot features can be disabled at the tenant level. The rest of the service continues to function without them.
04Business operations subprocessors
These parties may incidentally process personal data relating to your personnel — such as the name and email address of an account contact — in the course of supporting the commercial relationship. They do not receive Customer Data from the service.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Google LLC | Business email, calendaring, document storage | Correspondence and business records | United States |
| Stripe, Inc. | Payment processing | Billing contact and transaction detail; card data handled by Stripe, never by us | United States |
05How we assess a subprocessor
Before engaging any subprocessor that will handle Customer Data, we assess:
- its security posture, including available certifications and audit reports;
- the terms it offers on data use, retention, and onward transfer, and whether they can be improved by negotiation;
- the jurisdictions in which it will process data, and whether an appropriate transfer mechanism is available;
- its incident notification commitments and how quickly it has performed against them historically; and
- whether the function could reasonably be performed without introducing a third party at all.
The last question is the one we ask first. Every subprocessor is an additional party with access to something, and the smallest defensible list is better than a comprehensive one.
Each subprocessor is engaged under a written agreement imposing data protection obligations at least as protective as those we owe you, and — where the GDPR applies — meeting the requirements of Article 28(3).
06Notification of changes and your right to object
We will give customers at least 30 days’ advance notice before adding a new subprocessor or materially expanding the role of an existing one. Notice is given by email to the account contact and by updating this page with a revised date.
To subscribe to change notifications, write to [email protected]with “Subprocessor notifications” in the subject line and the address you want notified.
Objecting
If you have a reasonable, good-faith objection to a proposed subprocessor on data protection grounds, tell us within the notice period. We will work with you to find an alternative, which may include configuring your tenant so the subprocessor is not used where that is technically feasible.
Where no reasonable alternative exists, you may terminate the affected Services without penalty and receive a pro-rata refund of prepaid unused fees. We would rather lose the subscription than move your data somewhere you have told us you do not want it.
We may engage a replacement subprocessor without advance notice in an emergency — for example where an existing provider fails and continuity is at risk — and will notify you as soon as practicable afterwards, with an explanation.
07Questions and requests
For a copy of our Data Processing Addendum, the Standard Contractual Clauses we rely on for international transfers, or a subprocessor’s current security documentation where we are permitted to share it, write to [email protected].
Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States.