Subprocessors List
Last Updated: March 27, 2026
Introduction
This document is the single source of truth for all subprocessors (third-party service providers) that AckTracked uses to process customer data. This list is maintained to comply with GDPR Article 28 and other data protection requirements.
What is a Subprocessor?
A subprocessor is a third party engaged by AckTracked to process customer data on our behalf as part of providing the ACK service.
Referenced By:
- Terms of Service (Section 15.3)
- Privacy Policy (Data Sharing section)
- Website: https://www.acktracked.com/subprocessors/
Current Subprocessors
1. Amazon Web Services (AWS)
Entity: Amazon Web Services, Inc.
Purpose: Cloud infrastructure, data storage, and computing services
Data Processed:
- All tracking data (metadata, truncated message previews)
- OAuth tokens
- User IDs
- Billing and usage data
- Configuration data
Location: United States (us-east-1 region)
Compliance: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, GDPR-compliant
Website: https://aws.amazon.com
2. Stripe, Inc.
Entity: Stripe, Inc.
Purpose: Payment processing
Data Processed:
- Payment card information (we never store card data; Stripe handles directly)
- Workspace IDs (for billing association)
- Purchase history
- Email addresses for receipts
Location: United States
Compliance: PCI DSS Level 1, SOC 2 Type II, GDPR-compliant
Website: https://stripe.com
3. Google Workspace
Entity: Google LLC
Purpose: Email and business productivity (support communications)
Data Processed:
- Email communications with customers (support requests)
- May include customer data if shared by customers in support emails
- Contact information
Location: United States
Compliance: SOC 2 Type II, ISO 27001, GDPR-compliant
Website: https://www.google.com/workspace
Note: Customer data in support emails is deleted after resolution (typically 2 years for records retention).
4. Cursor (Anysphere, Inc.)
Entity: Anysphere, Inc. (Cursor)
Purpose: Development and operations tool
Data Processed:
- May access customer data during development, debugging, or support activities
- Code that may reference customer scenarios
- System logs during troubleshooting
Location: United States
Compliance: SOC 2 (in progress), GDPR-aware
Website: https://www.cursor.com
Note: Used for development and operations; customer data access is incidental and minimized.
5. OpenAI, LP
Entity: OpenAI, LP
Purpose: Business intelligence, content generation, and operational assistance
Data Processed:
- Anonymized or aggregated usage metrics
- Customer information for business analysis (not real-time service data)
- May process support queries or documentation content
Location: United States
Compliance: SOC 2 Type II
Website: https://www.openai.com
Important:
- We do not send real-time tracking data or message content to OpenAI
- Usage is limited to business operations, analytics, and content generation
- Customer data is anonymized or aggregated before processing where possible
6. Anthropic PBC
Entity: Anthropic PBC
Purpose: Business intelligence, content generation, and operational assistance
Data Processed:
- Anonymized or aggregated usage metrics
- Customer information for business analysis (not real-time service data)
- May process support queries or documentation content
Location: United States
Compliance: SOC 2 Type II
Website: https://anthropic.com
Important:
- We do not send real-time tracking data or message content to Anthropic
- Usage is limited to business operations, analytics, and content generation
- Customer data is anonymized or aggregated before processing where possible
Services NOT Listed (Do Not Process Customer Data)
The following services we use do NOT process customer data and are therefore not subprocessors:
- GitHub - Code repository only; no customer data stored
- Internal development tools - Do not access customer data
Data Processing Safeguards
All subprocessors are required to:
- Maintain appropriate security measures
- Comply with GDPR and applicable data protection laws
- Process data only as instructed by AckTracked
- Notify us of data breaches
- Support us in fulfilling data subject rights (access, deletion, etc.)
- Not use customer data for their own purposes
Subprocessor changes
We may add, remove, or change subprocessors as needed to provide and improve the Service. The current list is always reflected in this document; we update the list and version history when subprocessors change. For questions, contact privacy@acktracked.com or legal@acktracked.com.
We do not commit here to a specific advance-notice period, objection process, or notification channel for future changes—those mechanics are governed by your agreement with us (including the DPA, if applicable) and applicable law.
Data Transfers
International Data Transfers:
Most subprocessors are located in the United States. For customers in the EEA, UK, or Switzerland, we rely on:
- AWS: EU-US Data Privacy Framework, Standard Contractual Clauses
- Stripe: EU-US Data Privacy Framework, Standard Contractual Clauses
- Google: EU-US Data Privacy Framework, Standard Contractual Clauses
- Others: Standard Contractual Clauses where applicable
Auditing and compliance
- We review subprocessor relationships on a periodic basis
- We review vendor security and compliance materials (for example published reports and questionnaires) as part of vendor management
- We assess data processing agreements where appropriate
- We monitor for security incidents affecting our service
Contact
Questions about subprocessors:
Email: legal@acktracked.com
To request current subprocessor agreements or certifications:
Email: legal@acktracked.com
Legal Framework
This subprocessors list is maintained in accordance with:
- GDPR Article 28 (Processor)
- CCPA Service Provider requirements (where applicable)
This list is updated when subprocessors are added, changed, or removed. For questions, contact privacy@acktracked.com.