Subprocessor Notice
Categories of third-party providers expected to support hosting, security, AI, billing, and deletion verification.
- Effective
- July 28, 2026
- Updated
- July 28, 2026
- Owner
- [Your LLC Legal Name]
Attorney-review draft
This notice identifies expected provider categories. It must be replaced with the final production subprocessor table before launch, including provider legal names, processing purposes, locations, safeguards, and notice dates.
Do not treat this page as a complete production subprocessor list until every live provider has been configured, reviewed, and accepted.
Expected categories
Hosting and deployment; database and authentication; object storage; payment processing; AI model processing; malware scanning; KMS/HSM or key broker; transactional email; security monitoring; error monitoring; rate limiting; queue or worker infrastructure; independent deletion verification; customer support tooling.
Provider categories must remain server-side where secrets or sensitive processing are involved and must produce metadata-only evidence where the architecture requires it.
Current named integrations in the codebase
The current build references Supabase for database/auth patterns, Stripe for billing, OpenAI-compatible server-side AI processing, hosting/deployment manifests, malware scanner adapters, managed KMS/HSM broker contracts, Redis-style rate limiting, private-network/VPN provider contracts, cloud-compute provider contracts, and independent verifier adapters.
Some integrations are contractual or adapter-level until live provider evidence is supplied. A provider should not be described as production active until configured in the deployment environment and accepted in launch evidence.
Change notice
Before adding a new material subprocessor, the provider should update this notice, give customer notice where required, and allow objection or termination rights if required by contract or law.
Questions about subprocessors may be sent to privacy@example.com.