Skip to content

GDPR

Subprocessor List

This list identifies production subprocessors used to process Customer Personal Data on customers’ behalf and selected customer-facing providers whose privacy roles are relevant to account registration, billing, email, monitoring, and AI-assisted extraction.

1. How Subprocessors Are Used

For Customer Personal Data covered by the Data Processing Addendum, exdata uses subprocessors for defined service functions only. Data shared with a subprocessor is limited to what the provider needs for that function, such as hosting infrastructure, transactional email, monitoring, support, or AI-assisted extraction.

Customer gives general authorization for listed subprocessors under the Data Processing Addendum. exdata will update this page or provide another reasonable notice channel before adding or replacing a production subprocessor that materially affects customer document processing.

The table also includes selected providers used for Company-controlled account registration, billing, and service operations where their processing roles are relevant to customers or visitors. Inclusion does not mean that every activity is performed as a subprocessor, and this page is not a general inventory of vendors used solely for the Company’s internal administration, accounting, or legal obligations.

Where exdata controls the deployment location, the processing location below describes the current production configuration. For provider-controlled services, it summarizes the applicable account configuration and the provider’s published service locations. Some providers also process limited account, support, security, billing, or operational metadata in other locations under their own data processing terms.

2. Current Providers And Subprocessors

3. Objections And Questions

Customers may object to a new or replacement subprocessor on reasonable data protection grounds. Send questions or objections to privacy@exdata.app and include the customer account, affected service area, and the reason for the objection.

4. Related Documents

Review the Data Processing Addendum, Technical and Organizational Measures, and Privacy Policy for the broader processing terms.