Subprocessor Disclosure
The third-party service providers SDRCloud uses to deliver, secure, and support the Platform.
Overview
SDRCloud uses carefully selected third-party service providers ("Subprocessors") to help deliver, secure, support, and improve the SDRCloud Platform.
A Subprocessor is a third-party organization that may process Customer Data or Customer Personal Data on SDRCloud's behalf in connection with providing the Platform.
SDRCloud evaluates subprocessors based on security, privacy, reliability, compliance, and operational requirements.
Where Customer Personal Data is processed by a Subprocessor, SDRCloud seeks to maintain contractual protections designed to protect Customer Data and comply with applicable privacy laws, including GDPR, UK GDPR, and California privacy laws where applicable.
SDRCloud Privacy Commitments
- •Customer Data remains owned by the Customer.
- •SDRCloud does not sell Customer Personal Data.
- •SDRCloud does not share Customer Personal Data for cross-context behavioral advertising.
- •SDRCloud does not use Customer Personal Data to train foundation AI models shared across customers.
- •SDRCloud does not use one customer's data to train models for another customer.
- •SDRCloud does not identify natural persons solely from IP addresses.
- •SDRCloud does not reverse engineer individual identity from IP address information.
- •SDRCloud remains responsible for managing Subprocessor relationships.
Current Subprocessors
Providers currently engaged to support the SDRCloud Platform.
| Subprocessor | Purpose |
|---|---|
| Google Cloud Platform (GCP) | Hosting, infrastructure, storage, networking, security |
| Convex | Application database and real-time backend services |
| Nylas | Email synchronization and inbox connectivity |
| Resend | Transactional and system email delivery |
| Stripe | Payment processing and subscription management |
| OpenAI | AI-assisted content generation and reasoning services |
| Anthropic | AI-assisted content generation and reasoning services |
International Transfers
Where required by applicable law, SDRCloud relies on appropriate transfer mechanisms including SCCs, the UK International Data Transfer Addendum, Adequacy Decisions, and other lawful mechanisms.
Security Expectations
SDRCloud seeks to engage subprocessors that maintain appropriate security controls including encryption, access controls, authentication, logging, monitoring, incident response, privacy protections, and vendor security programs.
Subprocessor Changes
SDRCloud may add, replace, or retire subprocessors as the Platform evolves. Where required by law or contract, SDRCloud will provide notice of material changes.
Customer Objections
Customers may submit reasonable subprocessor objections to privacy@sdrcloud.ai.