This is a superseded version. It is kept at a permanent address so the text in force on a past date can be produced. It is not the current policy — read the current sub-processors instead.

Sub-processors — version 1.4
In effect from 2026-09-14. Supersedes version 1.3. Previous versions remain available at /legal/subprocessors/versions/.

Sub-processors

Version 1.4 · In effect from 14 September 2026 · supersedes 1.3 of 10 September 2026

Aporta Systems, LLC uses the providers below to deliver the Service. Each is engaged under a written data processing agreement, and we remain responsible to our customers for what each of them does.

We give customers at least thirty days’ notice before we add or replace a provider, and a right to object on reasonable data protection grounds.

Provider What it does for us What personal data it can reach Location
Cloudflare, Inc. Edge compute; storage of audit records; DNS and email routing; cookieless analytics on this website and in the Aporta dashboard Encrypted audit records; tokenized content in transit. Prompt text is present unencrypted at the edge for the moment detection runs. Analytics on this website and in the dashboard are aggregate only, with no cookie and no visitor identifier. United States
Modal Labs, Inc. Second-tier detection Prompt text and extracted attachment text, in the clear, at the moment of detection. Processed in memory and not retained. A customer can turn this tier off. United States
Turso (ChiselStrike, Inc.) Per-customer vault and metadata databases Encrypted token-to-value mappings; account metadata United States
WorkOS, Inc. Sign-in, directory and role assignment Names, work email addresses, role assignments. No prompt content. United States
Resend (Plus Five Five, Inc.) Delivers one message, and only one: the email telling your administrators that browsers are waiting to be enrolled The work email addresses of those administrators, because they are the recipients — which also tells this provider your domain. The message itself carries a count of how many browsers are waiting and how long the oldest has waited. No employee names, no prompt content, no token mappings, no audit records, no account identifiers. Delivery metadata is held by the provider under its own terms. United States
Microsoft Corporation Business email, document storage and support correspondence Contact details, and anything personal included in correspondence, contracts or support requests. No prompt content, token maps or audit records. United States
Stripe, LLC Payment processing and billing Billing contact name and email, subscription and invoice records. Card details go to Stripe directly and are never held by us. No prompt content. United States
Twilio Inc. Operational alerting by text message to our own staff, so that someone is reached when an internal check needs attention. It carries no part of the Service you use. The mobile numbers of the Aporta personnel who receive those alerts, because they are the recipients, and with them this provider’s own message log — a record of who was messaged and when, which is a second surface beyond the message itself. This row is here because the account and the credential exist, not because a message has been sent: as of this version none has been, and no part of our system calls the channel yet. We are not making a statement here about what this provider does not receive. The rule that would make such a statement true is not yet built into the product, and we would rather list a provider plainly than describe a limit that nothing checks. Not yet established. We read this provider’s data protection terms on 14 September 2026 for the questions below, and that read did not settle where processing happens. We are publishing this cell unfilled rather than filling it from what is usual.

Two things worth saying plainly

Three of these do not run the Service. Microsoft holds our email and documents; Stripe holds our billing; Twilio carries alerts to our own staff. Personal data reaches all three. They are listed for the same reason as the five that run the Service — a provider holding your correspondence or your invoices is handling your personal data as surely as one running our servers, and a list covering only the second would be a list chosen to look short.

Our payment processor is not purely acting on our instructions. Stripe uses payment data on its own account for fraud prevention and regulatory compliance, as its own terms describe. That is true of every payment processor and is rarely said out loud.

Their vendors

The chain does not end here.

Our second-tier detection provider operates no physical infrastructure of its own. It schedules work across a pool of cloud providers it publishes. Our configuration fixes the country that work runs in. It does not fix which provider runs it.

The mobile carriers that deliver a text message sit outside the chain we watch. Our messaging provider’s terms state that the telecommunications providers it uses are not its sub-processors. So those carriers do not appear on the list it publishes, and it owes us no notice if they change. That is a limit on what we can see rather than a criticism of the provider — the handset end of a text message is carried by networks that no vendor list enumerates — and we would rather tell you where our visibility stops than let a watched list read as though it covered the whole path.

Each of the others engages its own vendors under its own terms.

Notice we receive, compared with notice we give

We promise our customers thirty days. Five of these providers give us less.

Provider Notice we receive
Microsoft Six months for customer data; thirty days for sub-processors supporting AI features
Amazon Web Services (from the date it appears above) Thirty days
Stripe Thirty days
Cloudflare Thirty days
WorkOS Fourteen days, by updating a page we are responsible for checking
Turso Ten days, by email — and silence for ten days counts as agreement
Modal Thirty days, but it may replace a provider urgently and tell us afterwards
Resend Fourteen days, in writing — and silence for fourteen days counts as agreement
Twilio No fixed period at all. Its terms name no number of days; the whole commitment is to tell us as soon as is reasonably practicable. It does offer a way to subscribe to those notices on the page where it lists its own providers. The right to object runs “during the applicable notice period” — a window defined by reference to a period that is not itself defined — and silence before that window ends counts as agreement

So for a change that starts in one of those chains, we cannot give you the thirty days we promise. We would give you what we have, as soon as we have it. For one of them we cannot tell you in advance how much that will be, because its terms fix no period to measure. We would rather say that than promise a chain of notice we cannot enforce.

Not on this list

Software stores. Our extension is distributed through the Chrome Web Store and Microsoft Edge Add-ons. They host a package and report install counts. No prompt content, token map or audit record reaches either, and the relationship each has with someone installing the extension is its own, not one we direct. They matter to us — they gate every release — but they are not sub-processors and we would rather not pad this list with names that hold nothing.

Questions

privacy@aportasystems.com


Changelog

1.4 — 14 September 2026. Adds Twilio Inc., which carries operational alerts by text message to our own staff. It is listed from the day its account and credential exist rather than from the day it is first used, and the row says so. Two of the things this version records are not improvements. Its terms set no notice period for a change among its own providers, which is why the comparison above moves from four providers to five and why its entry there carries no number of days; and the mobile carriers that actually deliver a message are outside the chain we watch, which is now stated under Their vendors. One cell on the new row — where processing happens — is published unfilled, because the terms we read did not answer it and we would rather show you the gap than close it with an assumption.

1.3 — 10 September 2026. Corrects our payment processor’s legal name from Stripe, Inc. to Stripe, LLC. Stripe converted the entity on 3 January 2026 and records the change on its own service-providers page; this list had carried the former name since the row was added on 4 September. Nothing about what Stripe does, or what reaches it, changes. No provider was added or removed, so the notice period in the comparison above is unchanged and no new thirty-day objection window opens.

1.2 — 10 September 2026. Adds Resend (Plus Five Five, Inc.), which delivers the enrollment notice described in its row. It has been wired into the Service since that notice was built and appeared on no earlier version of this list; it was found on 9 September 2026 by reading our own code, which is not how a gap in this page should be found. Its location and notice period were taken from its data processing addendum rather than from what is usual, and the notice comparison above changes from three providers to four as a result.

1.1 — 4 September 2026. Added Stripe, Inc. (payment processing) on wiring billing. Added Microsoft Corporation (business email, document storage, support correspondence). Recorded cookieless analytics, on this website and in the dashboard, under Cloudflare’s existing entry. Added the notice comparison above.

1.0 — 4 September 2026. First published list.

Generated from docs/governance/legal/subprocessors.md. The source of truth is the governance register in the application repository, not this page.