Sub-processors

Complete transparency of all third-party services that may process personal data on behalf of PersonaLift

10
Total Sub-processors
8
Service Categories
100%
GDPR Compliant
30d
Notice Period

Sub-processor Change Notifications

PersonaLift provides 30 days advance notice of any new sub-processors or material changes to existing sub-processor arrangements. Enterprise customers can object to new sub-processors.

Cloud Infrastructure

Amazon Web Services (AWS)

Primary hosting platform and data storage

Added: 1/15/2024

Location

United States

Data Types Processed

All customer dataUsage analyticsSystem logs

Certifications

SOC 2ISO 27001GDPR Compliant

Google Cloud Platform

AI/ML processing and backup storage

Added: 3/10/2024

Location

United States, European Union

Data Types Processed

Personalization dataAI training data

Certifications

SOC 2ISO 27001GDPR Compliant

Analytics

Google Analytics

Website usage analytics and performance monitoring

Added: 1/15/2024

Location

United States

Data Types Processed

Anonymized usage dataPerformance metrics

Certifications

Privacy ShieldGDPR Compliant

Mixpanel

Product analytics and user behavior tracking

Added: 2/20/2024

Location

United States

Data Types Processed

Usage patternsFeature adoption metrics

Certifications

SOC 2GDPR Compliant

Payment Processing

Stripe

Payment processing and subscription management

Added: 1/15/2024

Location

United States, European Union

Data Types Processed

Billing informationPayment transactions

Certifications

PCI DSSSOC 2GDPR Compliant

Customer Support

Zendesk

Customer support ticket management

Added: 1/20/2024

Location

United States

Data Types Processed

Support communicationsAccount information

Certifications

SOC 2GDPR Compliant

Customer Communication

Intercom

Live chat and customer messaging

Added: 4/5/2024

Location

United States

Data Types Processed

Chat messagesUser profile data

Certifications

SOC 2GDPR Compliant

Email Services

SendGrid

Transactional emails and notifications

Added: 1/15/2024

Location

United States

Data Types Processed

Email addressesMessage content

Certifications

SOC 2GDPR Compliant

Product Analytics

PostHog

Feature flags and A/B testing infrastructure

Added: 5/12/2024

Location

United States, European Union

Data Types Processed

Feature usage dataExperiment results

Certifications

SOC 2GDPR Compliant

Error Monitoring

Sentry

Application error tracking and performance monitoring

Added: 1/15/2024

Location

United States

Data Types Processed

Error logsPerformance data

Certifications

SOC 2GDPR Compliant

International Data Transfers

Transfer Safeguards

  • • Standard Contractual Clauses (SCCs)
  • • Adequacy decisions where applicable
  • • Additional technical safeguards
  • • Regular compliance monitoring

Geographical Restrictions

  • • EU data stays within EU/EEA when required
  • • US data processing under Privacy Framework
  • • Regional data sovereignty options available
  • • Enterprise customers can specify regions

Sub-processor Auditing

Regular Reviews

All sub-processors undergo quarterly compliance reviews and annual security assessments.

Contract Requirements

Every sub-processor signs data processing agreements with equivalent protection levels.

Incident Response

All sub-processors must report security incidents within 24 hours of discovery.

Questions About Sub-processors?

Data Protection Team

Email: dpa@personalift.io
Response time: Within 48 hours
Available: Monday-Friday, 9 AM - 6 PM CT

Enterprise Customers

For objections to new sub-processors or custom arrangements, contact your dedicated Customer Success Manager or email enterprise@personalift.io

This sub-processor list is updated regularly. Last updated: January 2025 | Version 1.4

For the most current information, bookmark this page or subscribe to our notification service above.