Vendor inventory, processing purposes, locations, safeguards, and change notice process.
Last updated: May 9, 2026
The production subprocessor list must name each hosting, database, storage, email, SMS, monitoring, payment, support, identity, and security provider that may process Customer Personal Data.
For each subprocessor, the list should state purpose, data categories, processing location, and contractual or technical safeguards.
Provider should give notice of material additions or replacements through the agreed notice method and objection process unless a shorter period is required for security, availability, legal compliance, or emergency continuity.
Customer-enabled integrations with third-party systems are not Provider subprocessors unless the agreement expressly states otherwise. Customer is responsible for authorizing, configuring, reviewing, and disabling those integrations.