The complete processing chain: what each vendor does, which region it runs in, and what data reaches it. If a name is not on this list, it does not process Customer Data.
Each one is bound by a written agreement imposing obligations no less protective than our own Data Processing Addendum, and we remain liable for their performance.
Adding a vendor to the processing chain is a decision you get to react to, not discover.
Workspace administrators are emailed at least 30 days before we add or replace a subprocessor that processes Customer Data. This page is updated at the same time, with a new revision number.
Raise a reasonable data protection objection inside the notice window and we will work on an alternative. If none exists, you may terminate the affected service and take a prorated refund.
Every vendor is assessed for security posture, processing location, transfer mechanism and breach commitments before onboarding, then re-reviewed each year.
Where you supply your own model provider key, that provider is your processor, not ours, and its terms govern the content you send. Providers you connect through outbound MCP credentials sit in the same category.
Read the DPA →Workspace administrators are notified automatically. Anyone else evaluating us can subscribe to the same notice.