SurveyRock
BlogResourcesSupportPricingLog inStart free

Sub-processor List

Document status: Approved v1.0 (2026-07-21) Last updated: 2026-07-21


What is a sub-processor?

A sub-processor is a third party that processes Personal Information on SurveyRock’s behalf to help us deliver the Service. We engage sub-processors only where they meaningfully improve our ability to provide the Service securely and effectively.

We require each sub-processor to:

  • Sign a written agreement requiring them to protect Personal Information in accordance with applicable law
  • Provide a Data Processing Addendum (DPA) where Personal Information of EU/UK residents is involved
  • Implement appropriate technical and organizational security measures
  • Notify us of any data breach without undue delay

Notification of changes

We notify Customers of material changes to this list at least 30 days in advance by:

  • Posting the updated list here
  • Sending email to the primary contact on each Account
  • In-app notification

Customers may object to a new sub-processor by emailing privacy@surveyrock.com within 30 days. If we cannot accommodate a reasonable objection, the Customer may terminate the affected service with a proportionate refund of prepaid fees — the full objection mechanism is in Section 4.4.3 of our DPA.


Current sub-processors

Infrastructure and hosting

Sub-processor Purpose Data processed Location DPA / privacy
Amazon Web Services (AWS) Primary cloud hosting — compute, storage, networking, database All Personal Information stored in the Service EU (Stockholm) https://aws.amazon.com/compliance/gdpr-center/
Vercel Marketing website and help center hosting, edge delivery Visitor IP, request metadata, page analytics (no Customer survey data) US (global edge) https://vercel.com/legal/dpa
Cloudflare Turnstile CAPTCHA — bot protection on signup, login, and survey-taking IP address and browser signals of visitors completing the CAPTCHA check Global edge https://www.cloudflare.com/cloudflare-customer-dpa/
IPlocate IP geolocation for login-security features (new-device/location alerts, session context) User IP addresses; derived approximate location (city, country, coordinates, timezone) Available on request https://www.iplocate.io/privacy
Mapbox Static map images embedded in security-alert emails (visualizing the approximate location of a sign-in) Approximate coordinates of the login location (derived from IP, embedded in the image URL); the email recipient’s IP and user agent when the mail client loads the image US https://www.mapbox.com/legal/dpa

Payments and billing

Sub-processor Purpose Data processed Location DPA / privacy
Paddle Merchant of Record — payment processing, tax compliance, dunning, invoicing Billing name, email, address, payment method (not card numbers; Paddle holds those), transaction history UK, US, EU https://www.paddle.com/legal/dpa

Email and communication

Sub-processor Purpose Data processed Location DPA / privacy
Postmark (ActiveCampaign) Transactional email delivery, inbound email parsing Email addresses (sender/recipient), email content for delivery US https://postmarkapp.com/eu-privacy
Telnyx SMS delivery — survey distribution by SMS and SMS one-time passcodes for two-factor authentication Phone numbers of message recipients (Respondents, contacts, account users), SMS message content, delivery metadata US https://telnyx.com/legal/data-privacy

Customer support

Sub-processor Purpose Data processed Location DPA / privacy
ThriveDesk Email-based customer support inbox Support ticket content, names, emails of Customers requesting support US https://www.thrivedesk.com/our/privacy/

Analytics and observability

Sub-processor Purpose Data processed Location DPA / privacy
PostHog Product and marketing-site analytics, feature usage measurement, session recordings (limited) Pseudonymized user IDs, event data, page interactions, IP (truncated) EU (PostHog Cloud EU, Frankfurt) https://posthog.com/dpa
BetterStack Status page hosting, uptime monitoring, log management Service-level metrics, no Customer survey data EU https://betterstack.com/data-processing-agreement

AI and machine learning

These sub-processors handle data only when Customers actively use AI features. AI providers receive transient data for the duration of the API call; we do not authorize them to train models on Customer Content.

Sub-processor Purpose Data processed Location DPA / privacy
OpenAI LLM provider for AI features (survey generation, open-text theme and sentiment analysis, summaries, AI Query, workflow AI steps, follow-up probes) Customer survey content and Respondent open-text responses sent when an AI feature is invoked (transient; not used for training) US https://openai.com/policies/data-processing-addendum
Portkey LLM gateway for model routing/selection — planned integration point for any non-OpenAI model; not yet wired into the application Same data as the underlying LLM it routes to (Portkey is a proxy); request/response metadata logged for routing and cost analysis US https://portkey.ai/dpa

Source code and development

Sub-processor Purpose Data processed Location DPA / privacy
Atlassian (Bitbucket) Source code repository, CI/CD pipelines Source code, deployment metadata, no Customer survey data Global (US, EU options) https://www.atlassian.com/legal/data-processing-addendum

Sub-processors we do NOT use

For clarity with enterprise procurement teams who may ask:

  • Paddle is the sole payment provider for all new subscriptions — a small number of legacy subscriptions remain on Stripe pending migration
  • We do not use Intercom, HubSpot Service Hub, or Zendesk for support — ThriveDesk only
  • We do not use Google Analytics or Adobe Analytics — PostHog (EU Cloud) is our only analytics tool, for both the product and the marketing site
  • We do not sell, rent, or share Customer data with marketing data brokers, ad networks, or aggregators
  • We do not train any AI models on Customer Content without explicit opt-in

Customer-controlled integrations

Customers can connect SurveyRock to third-party services (Zapier, HubSpot, Salesforce, custom webhooks, etc.). When Customers configure these integrations:

  • The third party is not a SurveyRock sub-processor
  • The Customer is responsible for the data shared with the third-party service
  • The third party’s terms govern that data sharing
  • SurveyRock acts as an integration point but does not control or store data on the third party’s behalf

How to verify sub-processor status

Customers can:

  • Request the DPA from any listed sub-processor where they have a direct concern
  • Object to a sub-processor by emailing privacy@surveyrock.com
SurveyRock

Surveys that turn answers into decisions. Operating since 2012.

Product

PricingTemplatesFree toolsEnterprise

Company

Our storyBlogBrand & pressContact

Resources

Resource hubGlossaryHelp center

Trust & legal

Trust centerGDPRAI & data governance

Compare

vs SurveyMonkeyvs Typeformvs Jotformvs Google Formsvs SurveySparrow

© 2026 SurveyRock

PrivacyTermsCookiesAcceptable UseDPASub-processorsAccessibility