Sub-processors
Policy text reviewed: July 16, 2026
This page lists the third parties that may process Customer Personal Data on behalf of SalesSynq under the Data Processing Agreement. We notify Customers of any intended addition or replacement of an active Sub-processor at least 30 days in advance, by email to the Customer's administrative contact and by updating this page. To subscribe to change notifications, email [email protected].
How to read this page.
- Active means listed for the standard service configuration; exact tenant usage can vary and should be confirmed contractually.
- Conditional sub-processors run only on the marketing site and only after cookie consent.
- Available but not enabled by default are integrated in code as alternatives but are NOT engaged for production tenants. They will be moved to the Active list (with notice) before any production engagement.
This registry is maintained policy content, not real-time telemetry, legal advice, or a SalesSynq certification. Provider-assurance entries summarize provider-published materials and are not independent verification.
Active Sub-processors
1. Infrastructure
Hosting, compute, storage and core platform services. Personal Data is stored at rest in this layer.
| Sub-processor | Purpose | Location of processing | Category of data | Provider assurance (not SalesSynq certification) |
|---|---|---|---|---|
| Hetzner Online GmbH | Compute, block storage and networking for the SalesSynq application; self-managed PostgreSQL runs on Hetzner volumes. Hetzner Cloud volumes are encrypted at rest by Hetzner. | Hetzner Cloud, Helsinki (HEL1) by default for EEA tenants; alternative Hetzner locations (Falkenstein FSN1, Nuremberg NBG1) available on request. | All Customer Data at rest. | Provider-reported: ISO/IEC 27001; ISAE 3402 Type II for parts of the operation; EU Cloud Code of Conduct adherence. |
| Let's Encrypt (Internet Security Research Group) | Issuance and renewal of public TLS certificates. | United States (issuance authority); certificates are public artefacts. | No Customer Personal Data is transferred. | — |
2. AI / LLM inference
Configured LLM providers may process free-text for supported enrichment paths. Those paths can apply common-pattern redaction and pseudonymous tenant metadata before provider egress, but coverage varies by integration and policy. Pattern redaction can miss personal data and is not anonymisation. SalesSynq contractually commits not to train models on Customer Data; provider handling depends on the enabled provider contract and configuration.
| Sub-processor | Purpose | Location of processing | Category of data | Provider assurance (not SalesSynq certification) |
|---|---|---|---|---|
| OpenAI, L.L.C. | Available LLM provider for supported semantic-enrichment paths. An OpenAI Zero-Data-Retention request has been submitted, but approval is not claimed; deployment-specific provider settings must be confirmed. | United States, via api.openai.com. | Free-text from messages and CRM activities on enabled paths; common-pattern redaction is path-specific and not guaranteed complete. | Provider-reported: SOC 2 Type 2; ISO/IEC 27001. These are not SalesSynq certifications. |
| Microsoft Ireland Operations Limited | Azure OpenAI Service. Engaged only when LLM_REGION=eu is configured for an EU-pinned deployment. Azure OpenAI is operated by Microsoft, not by OpenAI; Customer Data does not pass to OpenAI when this path is in use. | EU regions (Sweden Central or France Central) when configured. | Same input categories as the OpenAI entry, subject to the enabled path and its redaction configuration. | Provider-reported: SOC 1/2/3; ISO/IEC 27001/27017/27018; HDS; C5; EU Data Boundary commitment. |
3. Operational and observability
Services used to operate the Service securely, bill Customers, and respond to incidents.
| Sub-processor | Purpose | Location of processing | Category of data | Provider assurance (not SalesSynq certification) |
|---|---|---|---|---|
| Sentry (Functional Software, Inc.) | Error and exception tracking for the application. | United States (sentry.io). PII filtering enabled in our SDK configuration; "Send Default PII" is OFF. | Stack traces, request metadata and error fingerprints. SDK filtering is configured to reduce PII, but diagnostic payloads still require minimisation and review. | Provider-reported: SOC 2 Type 2; ISO/IEC 27001. |
| Stripe, Inc. | Billing, subscription management and payment processing. | United States and Ireland (Stripe Payments Europe Ltd. for EEA Customers). | Customer billing-contact identifiers and payment metadata. Card numbers do not transit SalesSynq. | Provider-reported: PCI DSS Service Provider Level 1; SOC 1/2; ISO/IEC 27001. |
Conditional Sub-processors
4. Marketing-site analytics (cookie-consent gated)
These services run only on the public marketing site and only after the visitor has accepted analytics cookies via the consent banner. They are not loaded inside the authenticated Service.
| Sub-processor | Purpose | Location of processing | Category of data | Provider assurance (not SalesSynq certification) |
|---|---|---|---|---|
| Google Tag Manager / Google Analytics 4 (Google LLC) | Aggregate marketing-site visitor analytics on salesynq.com. | United States; Google LLC is a EU-US DPF participant. | Web visitor data: IP address (truncated), device and browser metadata, page views. Not Customer Data. | Provider-reported: ISO/IEC 27001/27017/27018; SOC 2/3. |
Not engaged by default
5. Available but not enabled by default
These providers have code-level integrations but are not listed as enabled by default. This page is not real-time deployment telemetry; contract-specific configuration must be confirmed before use and the active registry updated when applicable.
| Sub-processor | Purpose | Location of processing | Category of data | Provider assurance (not SalesSynq certification) |
|---|---|---|---|---|
| Anthropic, PBC | Alternative LLM provider for semantic enrichment. | United States, via api.anthropic.com. EU-region access available through AWS Bedrock if Bedrock is enabled (would require AWS Inc. / AWS EMEA SARL to be added as additional sub-processors at that point). | Potentially the same input categories as OpenAI; actual use and redaction policy depend on deployment configuration. | Provider-reported: SOC 2 Type 2; ISO/IEC 27001. |
| Mistral AI | Alternative LLM provider; EU-native. | France (Paris). | Potentially the same input categories as OpenAI; not represented as active. | Vendor assurance materials must be reviewed before activation; no SalesSynq legal-status claim. |
| Cohere Inc. | Alternative LLM provider; embeddings. | Canada / United States. | Potentially free-text or embedding input; actual use and redaction policy depend on deployment configuration. | Provider-reported: SOC 2 Type 2. |
| OpenRouter (TheVintageGarageInc) | LLM provider proxy used during development. | United States. | Forwarded to whichever upstream model is selected. | — |
| DeepSeek | Alternative LLM provider integrated in code; not enabled for production tenants. | China (PRC). Not listed as enabled by default; any proposed activation would require a separate legal, security and sub-processor review. | No active processing represented by this registry. | — |
The Customer's own integrations (HubSpot, Zoho, Outlook, Gmail, WhatsApp, Slack, Telegram and similar) are not Sub-processors of SalesSynq. They are upstream sources from which Customer authorises SalesSynq to read data on Customer's behalf, and they remain governed by Customer's direct relationship with each provider.
See also: Data Processing Agreement, Privacy Policy, Security, AI Disclosure.