Subprocessors List

Last Updated: March 27, 2026

Introduction

This document is the single source of truth for all subprocessors (third-party service providers) that AckTracked uses to process customer data. This list is maintained to comply with GDPR Article 28 and other data protection requirements.

What is a Subprocessor?
A subprocessor is a third party engaged by AckTracked to process customer data on our behalf as part of providing the ACK service.

Referenced By:


Current Subprocessors

1. Amazon Web Services (AWS)

Entity: Amazon Web Services, Inc.
Purpose: Cloud infrastructure, data storage, and computing services
Data Processed:

  • All tracking data (metadata, truncated message previews)
  • OAuth tokens
  • User IDs
  • Billing and usage data
  • Configuration data

Location: United States (us-east-1 region)
Compliance: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, GDPR-compliant
Website: https://aws.amazon.com


2. Stripe, Inc.

Entity: Stripe, Inc.
Purpose: Payment processing
Data Processed:

  • Payment card information (we never store card data; Stripe handles directly)
  • Workspace IDs (for billing association)
  • Purchase history
  • Email addresses for receipts

Location: United States
Compliance: PCI DSS Level 1, SOC 2 Type II, GDPR-compliant
Website: https://stripe.com


3. Google Workspace

Entity: Google LLC
Purpose: Email and business productivity (support communications)
Data Processed:

  • Email communications with customers (support requests)
  • May include customer data if shared by customers in support emails
  • Contact information

Location: United States
Compliance: SOC 2 Type II, ISO 27001, GDPR-compliant
Website: https://www.google.com/workspace

Note: Customer data in support emails is deleted after resolution (typically 2 years for records retention).


4. Cursor (Anysphere, Inc.)

Entity: Anysphere, Inc. (Cursor)
Purpose: Development and operations tool
Data Processed:

  • May access customer data during development, debugging, or support activities
  • Code that may reference customer scenarios
  • System logs during troubleshooting

Location: United States
Compliance: SOC 2 (in progress), GDPR-aware
Website: https://www.cursor.com

Note: Used for development and operations; customer data access is incidental and minimized.


5. OpenAI, LP

Entity: OpenAI, LP
Purpose: Business intelligence, content generation, and operational assistance
Data Processed:

  • Anonymized or aggregated usage metrics
  • Customer information for business analysis (not real-time service data)
  • May process support queries or documentation content

Location: United States
Compliance: SOC 2 Type II
Website: https://www.openai.com

Important:

  • We do not send real-time tracking data or message content to OpenAI
  • Usage is limited to business operations, analytics, and content generation
  • Customer data is anonymized or aggregated before processing where possible

6. Anthropic PBC

Entity: Anthropic PBC
Purpose: Business intelligence, content generation, and operational assistance
Data Processed:

  • Anonymized or aggregated usage metrics
  • Customer information for business analysis (not real-time service data)
  • May process support queries or documentation content

Location: United States
Compliance: SOC 2 Type II
Website: https://anthropic.com

Important:

  • We do not send real-time tracking data or message content to Anthropic
  • Usage is limited to business operations, analytics, and content generation
  • Customer data is anonymized or aggregated before processing where possible

Services NOT Listed (Do Not Process Customer Data)

The following services we use do NOT process customer data and are therefore not subprocessors:

  • GitHub - Code repository only; no customer data stored
  • Internal development tools - Do not access customer data

Data Processing Safeguards

All subprocessors are required to:

  • Maintain appropriate security measures
  • Comply with GDPR and applicable data protection laws
  • Process data only as instructed by AckTracked
  • Notify us of data breaches
  • Support us in fulfilling data subject rights (access, deletion, etc.)
  • Not use customer data for their own purposes

Subprocessor changes

We may add, remove, or change subprocessors as needed to provide and improve the Service. The current list is always reflected in this document; we update the list and version history when subprocessors change. For questions, contact privacy@acktracked.com or legal@acktracked.com.

We do not commit here to a specific advance-notice period, objection process, or notification channel for future changes—those mechanics are governed by your agreement with us (including the DPA, if applicable) and applicable law.


Data Transfers

International Data Transfers:

Most subprocessors are located in the United States. For customers in the EEA, UK, or Switzerland, we rely on:

  • AWS: EU-US Data Privacy Framework, Standard Contractual Clauses
  • Stripe: EU-US Data Privacy Framework, Standard Contractual Clauses
  • Google: EU-US Data Privacy Framework, Standard Contractual Clauses
  • Others: Standard Contractual Clauses where applicable

Auditing and compliance

  • We review subprocessor relationships on a periodic basis
  • We review vendor security and compliance materials (for example published reports and questionnaires) as part of vendor management
  • We assess data processing agreements where appropriate
  • We monitor for security incidents affecting our service

Contact

Questions about subprocessors:
Email: legal@acktracked.com

To request current subprocessor agreements or certifications:
Email: legal@acktracked.com


Legal Framework

This subprocessors list is maintained in accordance with:

  • GDPR Article 28 (Processor)
  • CCPA Service Provider requirements (where applicable)

This list is updated when subprocessors are added, changed, or removed. For questions, contact privacy@acktracked.com.