Subprocessors
For both products. Draft — not published, and not in force.
Unpublished draft
This document is a draft. It has not been reviewed by a lawyer, it has not been published, and it is not in force. Nothing on this page binds anyone, and no product links to it as a term of use.
Not written as its own document. Section 7 of the Privacy Policy is the operative list.
What applies today
The operative list is section 7 of the Privacy Policy, which names each third party that touches customer data and what it receives. That section is in force; this page is not, and nothing here adds to or removes from it.
What this document will cover
A standalone list exists so that a customer's procurement review can read it without reading a privacy policy, and so that a change to it has somewhere to be announced. None of this is in force.
- Each subprocessor, what it processes, and what for.
- Where each one runs, and which transfers leave India — the question a DPDPA review actually asks.
- Which of them are avoidable by configuring local providers, and which are not.
- The notice given before a new subprocessor is added, and how to object.
- A dated change log, so a customer can diff it.