Subprocessors
Last updated: 2026-08-07
1. About This List
A subprocessor is a third-party service provider engaged to process personal data for a processor. Depending on the data and service, Customermates may engage a provider as its processor for data it controls or as its subprocessor for data it processes on a customer's behalf.
The complete list is incorporated by reference into our Privacy Policy. Only providers expressly identified below as processing personal data on a customer's behalf are incorporated into our Data Processing Agreement as subprocessors. A controller-side processor, independent controller, or other recipient does not become a subprocessor merely because it appears on this page. We keep the list up to date and review it whenever a relevant provider is added, replaced, or removed.
This page applies only to the managed Customermates service operated by Benjamin Wagner. Providers selected or configured by an independent self-host operator, including hosting, PostgreSQL, transactional email, OAuth, monitoring, backup, and integration providers, are engaged directly by that operator and are not Customermates subprocessors. The operator is responsible for its own Art. 28 contracts, Chapter V transfer safeguards, and public disclosures.
2. Roles
The providers listed below support two different types of processing:
- For website, account, billing, security, and support data, Customermates acts as the controller. A provider listed below may process that data on our behalf or, for the categories identified in its row, act as an independent controller.
- For connected-account content and operations, including a customer's connected mailboxes, messages, contacts, calendars, social content and engagement data, profiles, relationship requests, and Sales Navigator search and list data, the customer is the controller, Customermates acts as a processor on the customer's behalf, and the relevant providers below (in particular Unipile, our hosting provider Vercel insofar as the application processes this content, and our contracted database provider Databricks insofar as it stores this content) act as subprocessors. The underlying communication platforms (Google, Microsoft, LinkedIn, Meta/WhatsApp/Instagram, Telegram) act as independent controllers for their own services.
Where a provider processes personal data on Customermates' behalf, Art. 28 GDPR requires a written data processing agreement; where it acts as a subprocessor, that agreement must also impose the obligations required by Art. 28(4) GDPR. The contractual status and known limitations for each provider are stated below and in our Privacy Policy. Disclosure and technical safeguards do not replace a required Art. 28 contract or Chapter V transfer mechanism.
3. Current Subprocessors and Other Recipients
| Provider or recipient | Service and purpose | Data location and transfer basis |
|---|---|---|
| Unipile, UNIPILE SAS, 168 rue de la Rotonde, 42153 Riorges, France (RCS Roanne 885265595) | Connected-account feature: transport for connected email, messaging, social-network, and calendar accounts and operations. Authentication runs in Unipile's hosted flow; Customermates receives neither provider passwords nor OAuth tokens. The executed supplier DPA identifies Customermates as controller and Unipile as processor. In the downstream role allocation described here, the customer is controller, Customermates is processor, and Unipile performs the supplier/subprocessor role. Its annex lists personal master data, contact data, professional data, information disclosed or contained in public directories, and IP addresses. The operational scope also includes messages, attachments, calendars, authorization data, correspondents, social-post and engagement data, person and company profiles, relationship requests, and Sales Navigator search and list data. | Unipile states that connected-account data is stored in the EU (France), on infrastructure operated by Scaleway. Its DPA permits transfers outside the EU where Chapter V safeguards apply, and its subprocessor list names a US payment provider and five proxy providers without locations. The supplier DPA names no specific Chapter V mechanism for those providers; any affected transfer remains subject to the Chapter V requirement in our DPA. |
| Vercel, Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA | Website and web-application hosting, and cookieless Vercel Web Analytics for aggregated usage measurement across the website and application. | USA. EU Standard Contractual Clauses of 2021 (Art. 46 GDPR), Modules 1 to 3, in Schedule 3 of Vercel's data processing addendum. Vercel makes subprocessor-change notices available by subscription and gives five calendar days to object after notice, but does not promise to defer the new engagement during that period. Our DPA therefore promises prompt onward notice rather than a fixed advance period. |
| Databricks, Inc. (Neon), with the managed database operated through Neon, LLC | Contracted subprocessor for the managed PostgreSQL database: storage and processing of application data, including stored connected-account content. Customermates uses the database service only and has not selected an AI-backed Databricks service for this processing. | Primary production database configured in the AWS Frankfurt region (eu-central-1); this is a selected product setting and not a contractual data-residency guarantee. The Neon Platform Services Product Specific Schedule dated 5 August 2026 (https://neon.com/platform-terms) adds Grafana Labs in the USA to the full current Databricks subprocessor list at https://www.databricks.com/legal/databricks-subprocessors. That list includes providers and affiliates in the countries stated there and marks some cloud and AI providers as customer-selected. The Databricks Data Processing Addendum (https://www.databricks.com/legal/dpa) incorporates the EU Standard Contractual Clauses of 2021 (Art. 46 GDPR) for restricted transfers to Databricks. |
| Forward Email, Forward Email, LLC, 16192 Coastal Hwy, Lewes, DE 19958, USA | Final hosted operator mailbox for Customermates' own business addresses. It processes addresses, content, attachments, headers, and delivery and security metadata. It is not used for connected customer mailboxes or ordinary CRM data, and no separate downstream mailbox provider is used. It is a limited subprocessor only where a customer includes data covered by the DPA in support or feedback correspondence. | United States. Forward Email's standard DPA is accepted electronically through its service Terms and incorporates the EU Standard Contractual Clauses for applicable transfers. |
| Sentry, Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (EU representative: Sentry Software Netherlands B.V., Amsterdam) | Error and performance monitoring across browser, server, and background workers. Sentry acts as processor for error-event and other service data and, where an event contains personal data covered by the DPA, as subprocessor for that event. It acts as an independent controller for its own account, profile, device, usage, and support data. | Error-event data stored in the EU (Frankfurt); account, authentication, integration, audit-log, and support data stored in the USA. EU-US Data Privacy Framework certification and EU Standard Contractual Clauses. |
| Lemon Squeezy, Sold through Link, LLC (formerly Lemon Squeezy LLC), 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA | Not a subprocessor for self-service purchases: it acts as Merchant of Record and independent controller under its own terms. On managed Customermates routes, its affiliate script is scheduled by the root layout. The current root layout does not suppress the script solely because APP_MODE=self-hosted is set; an independent self-host operator controls its own deployment and legal notices. When the affiliate tracker initialises, it reads document.cookie. If it finds an existing ls_aff_ref cookie or an aff parameter, it then performs pseudonymous browser fingerprinting, may set the cookie, and sends attribution data to Lemon Squeezy. Its role for that tracking has not been established. | USA. For self-service purchases, its own privacy policy governs. The contractual role and transfer mechanism for affiliate tracking and the cookie duration remain unresolved. Affiliate tracking is not strictly necessary to provide the digital service requested by the visitor; consent under § 25(1) TDDDG is therefore required before non-essential storage of or access to device information. No such consent mechanism is currently implemented. |
| Resend, Plus Five Five, Inc. (operating as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA | Controller-side transactional and account email: confirmation of the email address, password reset, invitations, notices on the trial period and on account and connected-account status, notices about updated Terms, the DPA, the Privacy Policy and subprocessors, and internal notifications to us. Where an internal support or feedback notification contains personal data covered by the DPA, Resend acts as a limited subprocessor for that fragment. No advertising and no marketing email. | USA. EU Standard Contractual Clauses and EU-US Data Privacy Framework certification. |
| OpenAI, OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (planned for EEA and Swiss customers) | Planned optional AI assistant within the CRM. The feature is not yet available and no data is currently transferred to OpenAI. Listed in advance in accordance with the notice procedure in our Data Processing Agreement. | Ireland; processing may involve transfers to the USA. Any applicable EU Standard Contractual Clauses (Art. 46 GDPR) under OpenAI's data processing addendum must be in place before the feature becomes available. |
External image hosts: flagcdn.com; uneed.best; b.sf-syn.com (SourceForge); twelve.tools; wired.business; startupfa.me; open-launch.com | Browser-loaded flags and directory badges. The browser may disclose the IP address, request time, requested image URL, HTTP or browser headers and, depending on browser policy, the referring origin. No CRM or connected-account content is intentionally transmitted. These domains are other recipients for controller-side presentation, not subprocessors for customer-controlled content. | Provider-specific infrastructure may involve processing outside the EEA. The operators' roles, processing locations, and transfer safeguards have not been contractually established by Customermates; see the Privacy Policy. |
More information about Unipile is available in its privacy policy at https://www.unipile.com/privacy-policy/, its terms of use at https://www.unipile.com/terms-of-use/, and its security and compliance information at https://www.unipile.com/security-compliance/.
4. Changes to This List
Where Customermates itself decides to engage or replace a subprocessor for processing carried out on a customer's behalf, we inform affected customers before processing begins and give them a reasonable opportunity to object. For an intended change in an existing supplier's own supply chain, we pass the supplier's notice to affected customers without undue delay and state any remaining supplier objection period; we do not promise a fixed advance period that the supplier does not guarantee. If a customer objects on reasonable data-protection grounds and we cannot accommodate the objection, the customer may terminate the affected service as set out in our Data Processing Agreement.
5. Contact
For questions about this list or about data protection generally, you can contact the controller:
Benjamin Wagner
An den Kasernen 25
68167 Mannheim
Germany
E-Mail: mail@customermates.com
Last Update: 07.08.2026