Legal
Subprocessors and Service Providers
The subprocessors AccountMade uses to provide the service, and how customer data is handled.
Effective: May 10, 2026
Summary
This page lists third-party providers that help operate AccountMade. Some are subprocessors for Customer Personal Data under the DPA. Others, such as Paddle and customer-selected CRMs, may act as independent controllers or customer-controlled providers.
We provide at least 30 days' notice before adding or replacing a DPA subprocessor, unless urgent security, legal, or continuity needs require a shorter period. Customers may object on reasonable data-protection grounds within 14 days after notice.
DPA subprocessors
| Provider | Purpose | Data categories | Processing location | Notes |
|---|---|---|---|---|
| Vercel Inc. | Application hosting, serverless functions, edge delivery | Customer Content, request metadata, IP addresses, headers, logs | United States and global edge | Hosting and edge infrastructure |
| Supabase Inc. | Database, authentication, storage | Account Data, Customer Content, Customer Personal Data, workspace data, integration metadata | United States | Database, auth, and storage infrastructure |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, bot protection, custom-domain routing | IP addresses, request headers, access logs, shared-deck delivery metadata, cached content where applicable | Global | Security and content delivery |
| OpenAI, L.L.C. | AI generation, ingestion/extraction, answerability judging, and text embeddings | Prompts, approved source documents, brand context, personas, selected CRM fields, questionnaire/RFP questions, generated outputs | United States | Accessed via OpenAI's commercial API (Platform). Customer Content submitted through the API is not used to train OpenAI's models under its API data-usage terms. |
| Google LLC (Gemini API) | AI generation, ingestion/extraction, answerability judging, and text embeddings (cross-provider fallback / independence) | Prompts, approved source documents, brand context, personas, selected CRM fields, questionnaire/RFP questions, generated outputs | United States | Accessed via Google's paid Gemini API. Customer Content submitted through the paid API is not used to train Google's models under its paid-tier API data-usage terms. |
| Upstash, Inc. | Redis caching, queues, rate limiting | Pseudonymous identifiers, usage counters, job state, temporary processing metadata | United States | Cache and rate-limit infrastructure |
| Resend, Inc. | Transactional email | Names, email addresses, workspace/account metadata, message content and delivery metadata | United States | Service, security, billing, and notification email |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Error events, stack traces, device/browser metadata, IP addresses, limited Customer Content where included in errors | United States | Error tracking and incident diagnostics |
| PostHog, Inc. | Product analytics | Usage events, device/browser metadata, page/activity events, pseudonymous identifiers | United States | Product analytics |
| TrueClara | Aggregate behavioral and revenue telemetry | Pathnames without query strings, aggregate pageview timing, workspace/revenue event identifiers and product-event metadata | United States | Cookieless aggregate telemetry; invite and share routes use a closed egress policy |
| Channel Corp. (Channel.io) | Customer support chat | Names, email addresses, chat messages, support context, device/browser metadata | Republic of Korea | Support interactions initiated by users |
Not every subprocessor processes every data category in every use of the Service. Some subprocessors process only Account Data or Service Data, while others may process Customer Personal Data depending on the features used.
Independent controllers and payment providers
| Provider | Purpose | Data categories | Processing location | Role |
|---|---|---|---|---|
| Paddle.com Market Limited and affiliates | Merchant of record, checkout, payments, subscriptions, tax, invoicing, refund administration, fraud screening | Billing contact details, payment method details, transaction records, tax location, subscription metadata | United Kingdom, Ireland, and global processing locations | Independent controller for payment transactions |
Paddle is not a DPA subprocessor for Customer Personal Data merely because it processes payment transactions. AccountMade receives limited payment metadata from Paddle and processes that metadata as described in the Privacy Policy.
Customer-selected integrations
| Provider | Purpose | Role |
|---|---|---|
| HubSpot | CRM data sync and field mapping when connected by Customer | Usually Customer's own vendor or independent provider. AccountMade accesses data through Customer-authorized OAuth scopes |
| Salesforce | CRM data sync and field mapping when connected by Customer | Usually Customer's own vendor or independent provider. AccountMade accesses data through Customer-authorized OAuth scopes |
| Google Drive (Google LLC) | Sync selected documents and files into Customer's claim library | Customer-selected provider accessed through Customer-authorized OAuth scopes |
| Notion Labs, Inc. | Sync selected pages and databases into Customer's claim library | Customer-selected provider accessed through Customer-authorized OAuth scopes |
| Atlassian, Inc. (Confluence) | Sync selected spaces and pages into Customer's claim library | Customer-selected provider accessed through Customer-authorized OAuth scopes |
| Microsoft Corporation (Microsoft 365, OneDrive, and SharePoint) | Sync selected files into Customer's claim library | Customer-selected provider accessed through Customer-authorized OAuth scopes |
| Drata, Inc. | Sync Customer-selected compliance controls, tests, evidence, and framework metadata | Customer-selected provider accessed with Customer-provided API credentials |
| Secureframe, Inc. | Sync Customer-selected controls, tests, and framework metadata | Customer-selected provider accessed with Customer-provided API credentials |
| Slack Technologies, LLC | Deliver workspace notifications to a Customer-selected Slack workspace | Customer-selected provider accessed through Customer-authorized OAuth or webhook configuration |
Customer-selected integrations are not automatically AccountMade subprocessors. If AccountMade uses a provider through an AccountMade-managed account to process Customer Personal Data, the provider will be listed in the DPA subprocessors table.
The Vanta connector exists as dormant code but is not currently offered in the product because its OAuth application is not provisioned. It is not described as a live Customer integration here; this list will be updated before that connector is enabled.
AI provider note
AccountMade does not use Customer Content or Customer Personal Data to train AI models, and Customer Content submitted to our AI subprocessors through their commercial APIs is not used to train their models under those providers' API data-usage terms. Provider retention and abuse-monitoring controls depend on the provider, product, and configured account terms; material changes to our AI-provider arrangements are reflected in the change log below.
Change log
| Date | Change |
|---|---|
| July 24, 2026 | Added the Customer-selected providers surfaced by the current integration UI (Google Drive, Notion, Confluence, Microsoft 365, Drata, Secureframe, and Slack); clarified that Vanta remains dormant and unprovisioned |
| July 24, 2026 | Disclosed TrueClara aggregate behavioral and revenue telemetry; clarified that query strings are removed before transmission and invite/share routes block telemetry egress |
| June 15, 2026 | Corrected AI subprocessor disclosure: replaced Anthropic (not used) with OpenAI and Google (Gemini API), the providers actually used for AI generation, ingestion, judging, and embeddings |
| May 10, 2026 | Updated standardized subprocessor list and separated DPA subprocessors, independent controllers, and customer-selected integrations |
Contact
Subprocessor questions and objections: legal@accountmade.com