Sub-processors
This is the list in force. It forms Annex III to the DPA, and it is the whole list — nothing else is in the path of your data.
1The list
| PROVIDER | PURPOSE | LOCATION | WHAT IT CAN SEE |
|---|---|---|---|
| Hosting, database and file storageProvider to be confirmed | Runs the application, the Postgres database and the images you upload | See note below | All of it — account data and lead data alike |
| Resend | Transactional email: result emails, lead alerts, invitations, account notices | United States, with EU delivery infrastructure | Recipient address and the contents of the message |
| Stripe | Subscriptions, card details and invoices | Ireland and United States | Billing contact and company details. No lead data, and no card number reaches Sondr |
| OpenAI | Drafting questions and suggesting scoring — only while AI is switched on for the workspace | United States | Only the source text and question wording a maker submits. No respondent names, emails or answers |
2Changes and objections
We email workspace owners 30 days before adding a sub-processor or moving one. You may object on reasonable data-protection grounds within those 30 days; if we cannot resolve it, you may terminate the affected service and we refund the unused period.
3What is not here
Sondr runs no advertising network, no analytics vendor, no session-replay tool and no data broker. There is no error-tracking service in the deployment today; if one is added it will be listed here first, with the same 30 days' notice.
A model provider only sees traffic while AI is switched on for the workspace, and only the source text and question wording a maker submits — never a respondent's name, email or answers.