OpenSay Subprocessors Registry
Last edited: Sep 4, 2026
Official registry of third-party subprocessors, infrastructure providers, and international transfer safeguards utilized by OpenSay. Effective September 4, 2026.
Third-Party Subprocessors & Infrastructure Directory
Low-Touch SaaS Online Acceptance: In accordance with our Terms of Service and Data Processing Addendum, purchasing a SaaS subscription, activating a trial, or installing the OpenSay application into a workspace constitutes general written authorization to engage the subprocessors cataloged herein.
Executive Overview & Supply Chain Governance
To provide our scalable, highly available anonymous messaging, whistleblower hotlines, and pulse survey platform, OpenSay relies on a small, rigorously audited ecosystem of industry-leading infrastructure partners.
Our supply-chain security framework enforces five core principles across all subprocessors:
- Independent Verification: Every infrastructure provider must maintain active, third-party audited certifications, including SOC 2 Type II, ISO/IEC 27001, or PCI-DSS Level 1.
- Contractual Data Protection (Article 28 GDPR): Mandatory execution of Data Processing Agreements incorporating strict confidentiality, audit covenants, breach notification windows, and purpose limitation.
- Absolute Prohibition of AI Model Training: Any provider executing machine learning or Large Language Model (LLM) inference (such as Google Gemini or Cloudflare Workers AI) is legally bound under paid enterprise terms to never use customer data, prompts, or outputs to train or fine-tune models. Details are documented in our AI Usage & Data Security Policy.
- Cryptographic Data Minimization: Subprocessors only receive the minimum data required to execute their specific technical function. All PII (user IDs, team names, emails) is stripped prior to safety analysis.
- International Transfer Mechanisms: Transfers outside the UK/EEA are anchored by the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, the Swiss-U.S. DPF, or standard contractual clauses.
Platform Architecture & Data Flow
The diagram below illustrates how data traverses OpenSay's infrastructure and where each authorized subprocessor operates:
Active Subprocessor Directory
The entities listed below are authorized subprocessors for the OpenSay platform as of September 4, 2026:
1. Cloud Infrastructure, Storage & Selectable AI Moderation
| Subprocessor | Corporate Details | Processing Regions | Scope of Services | Data Transferred | Transfer Mechanism |
|---|---|---|---|---|---|
| Google LLC | 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA | United States & Global Cloud Regions | • Core Cloud Hosting (Google Cloud Platform) • Managed NoSQL Database (Cloud Firestore) • Serverless Microservices (Cloud Functions) • Operational & System Analytics • Selectable AI Content Moderation (Google Gemini 2.5 Flash Lite) |
• Workspace IDs & domain names • Channel IDs & names • Admin profile emails & names • Message text submitted to anonymous channels • Transient prompt text for content moderation |
• EU-U.S. Data Privacy Framework • UK Extension to EU-U.S. DPF • Swiss-U.S. DPF • EU Standard Contractual Clauses (2021/914) • UK International Data Transfer Addendum |
Key Documentation: Google Cloud DPA • Google Privacy Policy • Google Gemini Paid API Terms • Google Cloud ISO/SOC Certifications
2. Edge Compute, Network Security & Default AI Moderation
| Subprocessor | Corporate Details | Processing Regions | Scope of Services | Data Transferred | Transfer Mechanism |
|---|---|---|---|---|---|
| Cloudflare, Inc. | 101 Townsend St, San Francisco, CA 94107, USA | Global Anycast Edge Network (330+ cities) & USA | • Serverless Edge Compute (Cloudflare Workers) • Inbound Slack Bot Webhook Routing • Global Content Delivery Network (CDN) • DNS Resolution & Layer 3/4/7 DDoS Protection • Default AI Content Moderation (Cloudflare Workers AI - Meta Llama 3.2 / 3.1) |
• Inbound webhook payloads • Transient message text for safety checks • IP addresses and HTTP request metadata • Network performance telemetry |
• EU-U.S. Data Privacy Framework • UK Extension to EU-U.S. DPF • Swiss-U.S. DPF • EU Standard Contractual Clauses (2021/914) • UK International Data Transfer Addendum |
Key Documentation: Cloudflare Customer DPA • Cloudflare Privacy Policy • Cloudflare SOC 2 & ISO 27001
3. Merchant of Record & Subscription Billing
| Subprocessor | Corporate Details | Processing Regions | Scope of Services | Data Transferred | Transfer Mechanism |
|---|---|---|---|---|---|
| Paddle Payments Limited / Paddle.com Market Limited | Core 10, 80 Fenchurch St, London, EC3M 4BY, United Kingdom | United Kingdom & European Union | • Merchant of Record (MoR) • Subscription lifecycle management • Global sales tax, VAT, and invoice compliance • PCI-DSS Level 1 payment gateway integration |
• Customer billing contact name • Work email address • Company billing address • Transaction metadata & VAT numbers (Note: Raw credit card numbers are handled exclusively by Paddle and are never received or stored by OpenSay) |
• UK Adequacy Regulations • UK Data Protection Act 2018 • EU Standard Contractual Clauses |
Key Documentation: Paddle Privacy Policy • Paddle Security Portal • Paddle Merchant Agreement
4. Customer Support & Diagnostics
| Subprocessor | Corporate Details | Processing Regions | Scope of Services | Data Transferred | Transfer Mechanism |
|---|---|---|---|---|---|
| Crisp IM SAS | 2 Boulevard de Launay, 44100 Nantes, France | France (Within European Economic Area) | • Customer support ticket management • In-app live chat support widget • Customer service communications |
• Name and work email (as provided by admin) • Support conversation transcripts • Customer-submitted screenshots and diagnostics |
• Intra-EEA transfer (Article 44 GDPR compliance not required; within European Union) |
| Functional Software, Inc. (d/b/a Sentry) (Standby / Conditional) | 45 Fremont St, 8th Fl, San Francisco, CA 94105, USA | United States | • Application exception reporting • Software crash logging • Real-time performance monitoring |
• Anonymized error stack traces • Browser and OS version details (Automated scrubbers remove emails, tokens, and Slack message contents prior to ingestion) |
• EU-U.S. Data Privacy Framework • UK Extension to EU-U.S. DPF • EU Standard Contractual Clauses (2021/914) |
Key Documentation: Crisp Privacy Policy • Sentry Privacy Policy • Sentry Security & Compliance
Customer-Integrated Communication Channels (Customer as Controller)
OpenSay provides native Slack, Microsoft Teams, and Google Chat integrations. The communication platforms themselves are selected, contracted, and controlled by the Customer. OpenSay acts as a Processor operating within the boundaries of the permissions granted by Customer administrators:
Subprocessor Change Notification & Objection Mechanism
OpenSay maintains a formal subprocessor onboarding and notification process in compliance with Section 5 of the OpenSay DPA and GDPR Article 28(2):
- Advance Notice Period: OpenSay will notify Customer at least thirty (30) calendar days before onboarding any new subprocessor or replacing an existing subprocessor.
- Notification Channels:
- Updates are posted directly to this public registry at /subprocessors/.
- Workspace administrators are notified via email and in-dashboard announcements.
- Customers may subscribe to dedicated email alerts by emailing
[email protected]with the subject line "Subscribe to Subprocessor Notifications".
- Right to Object: Customer may object in writing to the engagement of a new subprocessor on reasonable data protection grounds within thirty (30) calendar days of receiving notice.
- Resolution & Termination: If an objection cannot be resolved through technical workarounds or alternative configurations, Customer may terminate the affected Services without penalty upon written notice.
Decommissioned Subprocessors Log
To ensure historical accountability and supply-chain auditability, OpenSay maintains a permanent log of decommissioned service providers:
| Subprocessor | Original Purpose | Date Decommissioned | Reason for Retirement |
|---|---|---|---|
| Chart.io (Atlassian, Inc.) | Historical business analytics and charts | June 30, 2022 | Product sunset by vendor (Atlassian acquired and shut down Chartio). Replaced with internal GCP reporting. |
| Google Perspective API (Jigsaw) | Legacy text toxicity scoring | September 1, 2024 | Upgraded to multimodal, higher-accuracy Google Gemini 2.5 Flash Lite with custom enterprise rules and zero-training guarantees. |
Inquiries & Data Protection Contact
For questions regarding our subprocessors, vendor risk assessments, or to request a copy of a subprocessor DPA, please contact our privacy team:
- Data Protection Officer (DPO): Sagi Kedmi
- Email:
[email protected]or[email protected] - Operating Entity: Heterodox Ltd. (Global Privacy & Compliance)
- Security Portal: /security/
- Data Processing Addendum: /dpa/
- AI Usage Policy: /ai-usage-policy/