Skip to main contentSkip to navigation

Subprocessor List

Last Updated: 2025-01-15

GDPR Compliance: This page lists all third-party subprocessors (service providers) that process personal data on behalf of OmniOps. We maintain Data Processing Agreements (DPAs) with all subprocessors and ensure they comply with GDPR Article 28 requirements.

About This List

As a data controller, OmniOps uses various third-party service providers (subprocessors) to deliver our services. This list is maintained in compliance with:

  • GDPR Article 28 (Processor obligations)
  • GDPR Article 46 (Data transfers outside the EU)
  • CCPA disclosure requirements

We will notify customers at least 30 days before adding new subprocessors or making changes to existing ones.

Change Notification

To receive notifications about subprocessor changes:

  • Email privacy@omniops.com to subscribe to notifications
  • Check this page regularly for updates
  • Review the "Last Updated" date above

Enterprise customers can object to new subprocessors within the notification period.

Current Subprocessors

SubprocessorPurposeData ProcessedLocationCompliance
Vercel Inc.
Application hosting and CDN
Application data, Usage logs
United States
SOC 2 Type IIPrivacy Shield
Supabase Inc.
Database hosting and authentication
Customer data, User credentials, Business data
United States
SOC 2 Type II
Stripe, Inc.
Payment processing
Payment information, Billing details
United States
PCI DSS Level 1SOC 2 Type II
Twilio Inc.
SMS messaging
Phone numbers, Message content
United States
SOC 2 Type IIISO 27001
Resend
Transactional email delivery
Email addresses, Email content
United States
SOC 2 Type II
OpenAI, L.L.C.
AI-powered features
Business data, Customer messages (anonymized)
United States
SOC 2 Type II
Anthropic PBC
AI-powered features
Business data, Customer messages (anonymized)
United States
SOC 2 Type II
Google LLC
Maps, geocoding, and analytics
Location data, Usage analytics
United States / Global
ISO 27001SOC 2/3
Sentry
Error monitoring and performance tracking
Error logs, Performance metrics
United States
SOC 2 Type IIPrivacy Shield
Upstash
Rate limiting and caching
Request metadata, Cache data
United States
SOC 2 Type II

Data Transfer Safeguards

For subprocessors located outside the European Economic Area (EEA), we use the following safeguards:

  • Standard Contractual Clauses (SCCs): EU Commission-approved contracts for international data transfers
  • Adequacy Decisions: Countries recognized by the EU as having adequate data protection (e.g., EU-US Data Privacy Framework participants)
  • Additional Safeguards: Encryption, access controls, and security certifications

Due Diligence

Before engaging any subprocessor, we:

  • Conduct security and privacy assessments
  • Verify compliance certifications
  • Execute Data Processing Agreements (DPAs)
  • Review their data breach notification procedures
  • Assess their technical and organizational security measures
  • Conduct ongoing monitoring and audits

Your Rights

As an OmniOps customer, you have the right to:

  • Receive 30 days' notice before we add or replace subprocessors
  • Object to the use of a specific subprocessor (enterprise customers)
  • Request information about our subprocessors' security practices
  • Receive copies of relevant DPAs (enterprise customers)

Contact Us

For questions about our subprocessors or to exercise your rights:

Email: privacy@omniops.com