Previous
SecurityNext
Terms of ServiceThird-party services that help us deliver collab.space.
We carefully select and monitor all subprocessors that process customer data. Each subprocessor undergoes security review and is bound by data processing agreements that meet GDPR and other regulatory requirements.
| Subprocessor | Purpose | Location |
|---|---|---|
| Convex | Backend database and real-time infrastructure | United States |
| Vercel | Application hosting and CDN | Global (Edge) |
| Cloudflare | DDoS protection and security | Global |
| Subprocessor | Purpose | Location |
|---|---|---|
| Cloudflare Turnstile | Bot protection and CAPTCHA | Global |
| Subprocessor | Purpose | Location |
|---|---|---|
| Resend | Transactional email delivery | United States |
| 100ms | Video conferencing infrastructure | Global |
| Subprocessor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and billing | United States |
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Analytics | Usage analytics and performance monitoring | United States |
| Subprocessor | Purpose | Location |
|---|---|---|
| OpenAI | AI assistant and semantic search capabilities | United States |
| Unstructured | Document parsing and text extraction | United States |
| Attendee Labs, Inc | Meeting transcription | United States |
| Subprocessor | Purpose | Location |
|---|---|---|
| Cal.com | Demo booking and scheduling embed | United States |
All subprocessors must meet these requirements:
| Requirement | Description |
|---|---|
| Security Assessment | Comprehensive security review before onboarding |
| Data Processing Agreement | Binding DPA with GDPR-compliant terms |
| SOC 2 or ISO27001 | Independent security certification |
| Encryption | Data encrypted in transit and at rest |
| Access Controls | Principle of least privilege |
| Incident Response | Defined breach notification procedures |
| Regular Review | Annual review of security posture |
| Region | Available | Subprocessors |
|---|---|---|
| United States | Default | All subprocessors |
| European Union | On Request | Selected subprocessors with EU presence |
| Australia | On Request | Selected subprocessors with AU presence |
We provide advance notice of subprocessor changes:
| Change Type | Notice Period |
|---|---|
| New Subprocessor | 30 days |
| Material Change | 30 days |
| Removal | Immediate notification |
To receive subprocessor change notifications:
| Method | Details |
|---|---|
| Subscribe at [email protected] | |
| RSS Feed | Available in your workspace settings |
| In-App | Notifications for workspace admins |
If you object to a new subprocessor:
| Step | Action |
|---|---|
| 1 | Submit objection within 30 days of notification |
| 2 | We'll work to address your concerns |
| 3 | If concerns cannot be resolved, termination rights apply |
Our subprocessor evaluation includes:
| Area | Assessment |
|---|---|
| Security Certifications | SOC 2, ISO 27001, or equivalent |
| Privacy Practices | GDPR compliance, DPA terms |
| Financial Stability | Business viability assessment |
| Incident History | Review of past security incidents |
| Technical Controls | Architecture and security review |
| Contract Terms | Liability, indemnification, termination |
| Question | Answer |
|---|---|
| Can I opt out of specific subprocessors? | Some subprocessors are essential for service delivery. Contact us to discuss alternatives. |
| Do subprocessors access my content? | Access is limited to what's necessary for service delivery. Most processing is automated. |
| How often is this list updated? | We update this page whenever subprocessors change. Last updated: January 2025. |
| Can I get subprocessor audit reports? | SOC 2 reports for key subprocessors are available under NDA. |
| Inquiry | Contact |
|---|---|
| Subprocessor Questions | [email protected] |
| Change Notifications | Subscribe at [email protected] |
| Objections | [email protected] |