Subprocessors
Last updated: 2026-09-01
Badge-host disclosure corrected: 2026-08-29; Mate and affiliate disclosures updated: 2026-08-30; Mate provider and ZDR disclosures updated: 2026-09-01
1. About This List
A subprocessor is a third-party service provider engaged to process personal data for a processor. Depending on the data and service, Customermates may engage a provider as its processor for data it controls or as its subprocessor for data it processes on a customer's behalf.
The complete list is incorporated by reference into our Privacy Policy. Only providers expressly identified below as processing personal data on a customer's behalf are incorporated into our Data Processing Agreement as subprocessors. A controller-side processor, independent controller, or other recipient does not become a subprocessor merely because it appears on this page. We keep the list up to date and review it whenever a relevant provider is added, replaced, or removed.
This page applies only to the managed Customermates service operated by Benjamin Wagner. Providers selected or configured by an independent self-host operator, including hosting, PostgreSQL, transactional email, OAuth, monitoring, backup, and integration providers, are engaged directly by that operator and are not Customermates subprocessors. The operator is responsible for its own Art. 28 contracts, Chapter V transfer safeguards, and public disclosures.
2. Roles
The providers listed below support two different types of processing:
- For website, account, billing, security, and support data, Customermates acts as the controller. A provider listed below may process that data on our behalf or, for the categories identified in its row, act as an independent controller.
- For connected-account content and operations, including a customer's connected mailboxes, messages, contacts, calendars, social content and engagement data, profiles, relationship requests, and Sales Navigator search and list data, the customer is the controller, Customermates acts as a processor on the customer's behalf, and the relevant providers below (in particular Unipile, our hosting provider Vercel insofar as the application processes this content, and our contracted database provider Databricks insofar as it stores this content) act as subprocessors. The underlying communication platforms (Google, Microsoft, LinkedIn, Meta/WhatsApp/Instagram, Telegram) act as independent controllers for their own services.
Where a provider processes personal data on Customermates' behalf, Art. 28 GDPR requires a written data processing agreement; where it acts as a subprocessor, that agreement must also impose the obligations required by Art. 28(4) GDPR. The contractual status and known limitations for each provider are stated below and in our Privacy Policy. Disclosure and technical safeguards do not replace a required Art. 28 contract or Chapter V transfer mechanism.
3. Current Subprocessors and Other Recipients
| Provider or recipient | Service and purpose | Data location and transfer basis |
|---|---|---|
| Unipile, UNIPILE SAS, 168 rue de la Rotonde, 42153 Riorges, France (RCS Roanne 885265595) | Connected-account feature: transport for connected email, messaging, social-network, and calendar accounts and operations. Authentication runs in Unipile's hosted flow; Customermates receives neither provider passwords nor OAuth tokens. The executed supplier DPA identifies Customermates as controller and Unipile as processor. In the downstream role allocation described here, the customer is controller, Customermates is processor, and Unipile performs the supplier/subprocessor role. Its annex lists personal master data, contact data, professional data, information disclosed or contained in public directories, and IP addresses. The operational scope also includes messages, attachments, calendars, authorization data, correspondents, social-post and engagement data, person and company profiles, relationship requests, and Sales Navigator search and list data. | Unipile states that connected-account data is stored in the EU (France), on infrastructure operated by Scaleway. Its DPA permits transfers outside the EU where Chapter V safeguards apply, and its subprocessor list names a US payment provider and five proxy providers without locations. The supplier DPA names no specific Chapter V mechanism for those providers; any affected transfer remains subject to the Chapter V requirement in our DPA. |
| Vercel, Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Website and web-application hosting; cookieless Vercel Web Analytics for aggregated usage measurement on managed public content pages; and Vercel AI Gateway for routing Mate model requests and responses to the selected third-party model provider. A Gateway request may contain the prompt, recent conversation, user and route context, authorised CRM or connected-account context, tool inputs and results, approvals, generated output, and technical usage metadata described in the Privacy Policy. Customermates currently has Vercel's team-wide Zero Data Retention control enabled. Vercel states that this control applies to every Gateway request for the team, restricts routing to providers with which Vercel has a ZDR agreement, includes a prompt-training opt-out, and deletes Gateway-level prompts and outputs after inference; routing and usage metadata may still be retained. | USA. EU Standard Contractual Clauses of 2021 (Art. 46 GDPR), Modules 1 to 3, in Schedule 3 of Vercel's data processing addendum, for processing covered by that addendum. Third-party model providers available through AI Gateway are non-Vercel services governed by the applicable provider terms identified in Vercel's AI Product Terms and Notices and License Information. ZDR controls apply to the Gateway and downstream-provider request path and do not change Customermates' own storage. Vercel makes subprocessor-change notices available by subscription and gives five calendar days to object after notice, but does not promise to defer the new engagement during that period. Our DPA therefore promises prompt onward notice rather than a fixed advance period. |
| Databricks, Inc. (Neon), with the managed database operated through Neon, LLC | Contracted subprocessor for the managed PostgreSQL database: storage and processing of application data, including stored connected-account content. Customermates uses the database service only and has not selected an AI-backed Databricks service for this processing. | Primary production database configured in the AWS Frankfurt region (eu-central-1); this is a selected product setting and not a contractual data-residency guarantee. The Neon Platform Services Product Specific Schedule dated 5 August 2026 (https://neon.com/platform-terms) adds Grafana Labs in the USA to the full current Databricks subprocessor list at https://www.databricks.com/legal/databricks-subprocessors. That list includes providers and affiliates in the countries stated there and marks some cloud and AI providers as customer-selected. The Databricks Data Processing Addendum (https://www.databricks.com/legal/dpa) incorporates the EU Standard Contractual Clauses of 2021 (Art. 46 GDPR) for restricted transfers to Databricks. |
| Forward Email, Forward Email, LLC, 16192 Coastal Hwy, Lewes, DE 19958, USA | Final hosted operator mailbox for Customermates' own business addresses. It processes addresses, content, attachments, headers, and delivery and security metadata. It is not used for connected customer mailboxes or ordinary CRM data, and no separate downstream mailbox provider is used. It is a limited subprocessor only where a customer includes data covered by the DPA in support or feedback correspondence. | United States. Forward Email's standard DPA is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers. |
| Sentry, Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (EU representative: Sentry Software Netherlands B.V., Amsterdam) | Error and performance monitoring across browser, server, and background workers. Sentry acts as processor for error-event and other service data and, where an event contains personal data covered by the DPA, as subprocessor for that event. It acts as an independent controller for its own account, profile, device, usage, and support data. | Error-event data stored in the EU (Frankfurt); account, authentication, integration, audit-log, and support data stored in the USA. EU-US Data Privacy Framework certification and EU Standard Contractual Clauses. |
| Lemon Squeezy, Sold through Link, LLC (formerly Lemon Squeezy LLC), 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA | Not a subprocessor for self-service purchases: it acts as Merchant of Record and independent controller under its own terms. Its standard affiliate script is loaded only on managed-cloud public content pages to attribute referred visits and purchases, allocate commission, administer the programme, and prevent incorrect attribution. Every visit to such a page requests the script from lmsqueezy.com, disclosing ordinary network-request data even without an affiliate code. On referred visits it additionally receives the landing URL, referrer, referral reference, and a browser-derived visitor identifier, and stores the ls_aff_ref referral cookie. The script is not gated by a separate Customermates consent mechanism. Authenticated, authentication, invitation, demo, and upstream self-hosted routes do not load it. Affiliate-registration links open Lemon Squeezy's hosted website. | USA. Lemon Squeezy's own privacy policy governs self-service purchases, affiliate tracking, and visits to its hosted website. Its contractual role and transfer basis for affiliate tracking have not been established by Customermates. Disclosure and Art. 6(1)(f) GDPR for subsequent personal-data processing do not replace consent where § 25(1) TDDDG requires it for device storage or access. |
| Resend, Plus Five Five, Inc. (operating as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA | Controller-side transactional and account email: confirmation of the email address, password reset, invitations, notices on the trial period and on account and connected-account status, notices about updated Terms, the DPA, the Privacy Policy and subprocessors, and internal notifications to us. Where an internal support or feedback notification contains personal data covered by the DPA, Resend acts as a limited subprocessor for that fragment. No advertising and no marketing email. | USA. EU Standard Contractual Clauses and EU-US Data Privacy Framework certification. |
| Microsoft Azure, a Microsoft service | Active downstream inference provider for Mate through Vercel AI Gateway. Azure serves the selected OpenAI-created models and receives the parts of a model request necessary to generate the response, which can include prompts or saved instructions, recent conversation text, authorised CRM or connected-account context, tool inputs and results, approvals, generated output, and technical metadata. Where Routines are offered, this can also include trigger event and record references and a saved instruction submitted for loop-risk analysis before execution. Microsoft states that prompts and outputs processed by Azure-hosted models are not available to OpenAI. The customer determines which authorised data is included and remains responsible for necessity, an applicable legal basis, and safeguards appropriate to the risk. | Vercel's current Notices and License Information identifies Microsoft Azure and applies Microsoft's Terms of Use. Vercel's public Trust Center identifies Microsoft in the United States for hosting, storage, and generative-AI services, but does not identify the exact Microsoft legal entity or the regional inference location for this route. The live Gateway endpoint metadata for both selected models identifies Azure and reports ZDR and no prompt training. Provider and subprocessor processing may nevertheless involve the USA and other countries. Every required Art. 28 GDPR contract and Chapter V transfer safeguard must apply; this public listing and the ZDR setting do not by themselves establish those safeguards or change Customermates' application-level storage. |
External image hosts: flagcdn.com; uneed.best; b.sf-syn.com (SourceForge); twelve.tools; wired.business; startupfa.me; open-launch.com | Browser-loaded flags and directory badges. The browser may disclose the IP address, request time, requested image URL, HTTP or browser headers and, depending on browser policy, the referring origin. No CRM or connected-account content is intentionally transmitted. These domains are other recipients for controller-side presentation, not subprocessors for customer-controlled content. | Provider-specific infrastructure may involve processing outside the EEA. The operators' roles, processing locations, and transfer safeguards have not been contractually established by Customermates; see the Privacy Policy. |
More information about Unipile is available in its privacy policy at https://www.unipile.com/privacy-policy/, its terms of use at https://www.unipile.com/terms-of-use/, and its security and compliance information at https://www.unipile.com/security-compliance/.
4. Changes to This List
Where Customermates itself decides to engage or replace a subprocessor for processing carried out on a customer's behalf, we inform affected customers before processing begins and give them a reasonable opportunity to object. For an intended change in an existing supplier's own supply chain, we pass the supplier's notice to affected customers without undue delay and state any remaining supplier objection period; we do not promise a fixed advance period that the supplier does not guarantee. If a customer objects on reasonable data-protection grounds and we cannot accommodate the objection, the customer may terminate the affected service as set out in our Data Processing Agreement.
5. Contact
For questions about this list or about data protection generally, you can contact the controller:
Benjamin Wagner
An den Kasernen 25
68167 Mannheim
Germany
E-Mail: mail@customermates.com
Last Update: 01.09.2026; badge-host disclosure corrected: 29.08.2026; Mate provider and ZDR disclosures updated: 01.09.2026