Sub-processor List
Document status: Approved v1.0 (2026-07-21) Last updated: 2026-07-21
What is a sub-processor?
A sub-processor is a third party that processes Personal Information on SurveyRock’s behalf to help us deliver the Service. We engage sub-processors only where they meaningfully improve our ability to provide the Service securely and effectively.
We require each sub-processor to:
- Sign a written agreement requiring them to protect Personal Information in accordance with applicable law
- Provide a Data Processing Addendum (DPA) where Personal Information of EU/UK residents is involved
- Implement appropriate technical and organizational security measures
- Notify us of any data breach without undue delay
Notification of changes
We notify Customers of material changes to this list at least 30 days in advance by:
- Posting the updated list here
- Sending email to the primary contact on each Account
- In-app notification
Customers may object to a new sub-processor by emailing privacy@surveyrock.com within 30 days. If we cannot accommodate a reasonable objection, the Customer may terminate the affected service with a proportionate refund of prepaid fees — the full objection mechanism is in Section 4.4.3 of our DPA.
Current sub-processors
Infrastructure and hosting
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud hosting — compute, storage, networking, database | All Personal Information stored in the Service | EU (Stockholm) | https://aws.amazon.com/compliance/gdpr-center/ |
| Vercel | Marketing website and help center hosting, edge delivery | Visitor IP, request metadata, page analytics (no Customer survey data) | US (global edge) | https://vercel.com/legal/dpa |
| Cloudflare | Turnstile CAPTCHA — bot protection on signup, login, and survey-taking | IP address and browser signals of visitors completing the CAPTCHA check | Global edge | https://www.cloudflare.com/cloudflare-customer-dpa/ |
| IPlocate | IP geolocation for login-security features (new-device/location alerts, session context) | User IP addresses; derived approximate location (city, country, coordinates, timezone) | Available on request | https://www.iplocate.io/privacy |
| Mapbox | Static map images embedded in security-alert emails (visualizing the approximate location of a sign-in) | Approximate coordinates of the login location (derived from IP, embedded in the image URL); the email recipient’s IP and user agent when the mail client loads the image | US | https://www.mapbox.com/legal/dpa |
Payments and billing
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| Paddle | Merchant of Record — payment processing, tax compliance, dunning, invoicing | Billing name, email, address, payment method (not card numbers; Paddle holds those), transaction history | UK, US, EU | https://www.paddle.com/legal/dpa |
Email and communication
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| Postmark (ActiveCampaign) | Transactional email delivery, inbound email parsing | Email addresses (sender/recipient), email content for delivery | US | https://postmarkapp.com/eu-privacy |
| Telnyx | SMS delivery — survey distribution by SMS and SMS one-time passcodes for two-factor authentication | Phone numbers of message recipients (Respondents, contacts, account users), SMS message content, delivery metadata | US | https://telnyx.com/legal/data-privacy |
Customer support
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| ThriveDesk | Email-based customer support inbox | Support ticket content, names, emails of Customers requesting support | US | https://www.thrivedesk.com/our/privacy/ |
Analytics and observability
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| PostHog | Product and marketing-site analytics, feature usage measurement, session recordings (limited) | Pseudonymized user IDs, event data, page interactions, IP (truncated) | EU (PostHog Cloud EU, Frankfurt) | https://posthog.com/dpa |
| BetterStack | Status page hosting, uptime monitoring, log management | Service-level metrics, no Customer survey data | EU | https://betterstack.com/data-processing-agreement |
AI and machine learning
These sub-processors handle data only when Customers actively use AI features. AI providers receive transient data for the duration of the API call; we do not authorize them to train models on Customer Content.
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| OpenAI | LLM provider for AI features (survey generation, open-text theme and sentiment analysis, summaries, AI Query, workflow AI steps, follow-up probes) | Customer survey content and Respondent open-text responses sent when an AI feature is invoked (transient; not used for training) | US | https://openai.com/policies/data-processing-addendum |
| Portkey | LLM gateway for model routing/selection — planned integration point for any non-OpenAI model; not yet wired into the application | Same data as the underlying LLM it routes to (Portkey is a proxy); request/response metadata logged for routing and cost analysis | US | https://portkey.ai/dpa |
Source code and development
| Sub-processor | Purpose | Data processed | Location | DPA / privacy |
|---|---|---|---|---|
| Atlassian (Bitbucket) | Source code repository, CI/CD pipelines | Source code, deployment metadata, no Customer survey data | Global (US, EU options) | https://www.atlassian.com/legal/data-processing-addendum |
Sub-processors we do NOT use
For clarity with enterprise procurement teams who may ask:
- Paddle is the sole payment provider for all new subscriptions — a small number of legacy subscriptions remain on Stripe pending migration
- We do not use Intercom, HubSpot Service Hub, or Zendesk for support — ThriveDesk only
- We do not use Google Analytics or Adobe Analytics — PostHog (EU Cloud) is our only analytics tool, for both the product and the marketing site
- We do not sell, rent, or share Customer data with marketing data brokers, ad networks, or aggregators
- We do not train any AI models on Customer Content without explicit opt-in
Customer-controlled integrations
Customers can connect SurveyRock to third-party services (Zapier, HubSpot, Salesforce, custom webhooks, etc.). When Customers configure these integrations:
- The third party is not a SurveyRock sub-processor
- The Customer is responsible for the data shared with the third-party service
- The third party’s terms govern that data sharing
- SurveyRock acts as an integration point but does not control or store data on the third party’s behalf
How to verify sub-processor status
Customers can:
- Request the DPA from any listed sub-processor where they have a direct concern
- Object to a sub-processor by emailing privacy@surveyrock.com