Change Notifications
We provide 30 days advance notice before adding or changing subprocessors. You have 14 days to object to any changes.
Subscribe to updates: Email legal@simplyasking.io with subject "Subscribe to Subprocessor Updates"
Overview
This page lists all subprocessors that Simply Asking uses to provide our services. A subprocessor is a third-party service provider that processes personal data on our behalf. All subprocessors must meet our security and privacy standards, including SOC 2 certification and data protection agreements.
Current Subprocessors
Infrastructure & Hosting
| Subprocessor | Purpose |
|---|---|
| Supabase | Database hosting, authentication, storage |
| Vercel | Frontend hosting, API routes, CDN, DDoS protection, DNS |
| Railway | Background worker hosting |
| Upstash | Distributed rate limiting and caching |
AI & Machine Learning
| Subprocessor | Purpose |
|---|---|
| OpenAI | Language models, embeddings |
| Google (Gemini API) | Entity extraction, chat fallback, embeddings fallback |
| Anthropic | Alternative language models |
| LlamaParse | Document parsing and extraction (PDF, DOCX, PPTX) |
Payment Processing
| Subprocessor | Purpose |
|---|---|
| Stripe | Payment processing, subscriptions |
Monitoring & Communication
| Subprocessor | Purpose |
|---|---|
| Resend | Transactional emails |
Optional Integrations
These subprocessors are only used if you enable the corresponding integration:
| Integration | Purpose |
|---|---|
| Google Drive | Document sync |
| Notion | Page sync |
| Dropbox | File sync |
| Slack | Notifications |
| Trello | Card sync |
| HubSpot | CRM sync |
Security Requirements
All subprocessors must meet the following minimum requirements:
- SOC 2 Type II or equivalent
- Regular third-party security audits
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
Regional Data Processing
Data Location: All data is currently processed and stored in the United States. For questions about international data transfers, we maintain Standard Contractual Clauses (SCCs) with applicable subprocessors.
Contact legal@simplyasking.io for questions about international data handling.
Vendor Security Certifications
Our subprocessors maintain industry-standard security certifications. Customers can request copies of relevant certifications by contacting security@simplyasking.io.
| Vendor | SOC 2 Type II | Trust Center |
|---|---|---|
| Supabase | Yes | View |
| Vercel | Yes | View |
| Railway | Yes | View |
| Stripe | Yes | View |
| OpenAI | Yes | View |
| Anthropic | Yes | View |
| Google Cloud | Yes | View |
| LlamaParse | Yes | View |
Certification status is verified annually. Contact security@simplyasking.io to request copies of vendor certifications for your compliance records.
Questions About Subprocessors?
Reach out for subprocessor change subscriptions, DPA requests, or international data handling questions.