Since 2018
Privacy-safe enterprise data
VOSB & SDVOSB
U.S. Veteran-Owned, Service-Disabled
SCC Transfers
EU/UK/CH per privacy policy
GDPR · CCPA · CPRA
Consent-first data sourcing
Current sub-processors
| Sub-processor | Service | Data processed | Location | Safeguards |
|---|---|---|---|---|
| Vercel Inc. | Application hosting and CDN | Site traffic logs; no buyer dataset payloads in default web tier | United States (multi-region) | SOC 2 Type II; SCCs for EU transfers |
| Microsoft Corporation | Email (Microsoft 365) | Internal email; some buyer correspondence threads | United States, EU | SOC 2; ISO 27001; SCCs for EU transfers |
| Proofpoint, Inc. | Email security | Inbound email metadata for filtering | United States | SOC 2; encryption in transit |
| Resend Inc. | Transactional email | Addresses for lifecycle notifications where used | United States | DKIM-signed delivery |
| Calendly LLC | Scheduling | Names, emails, meeting metadata when prospects book | United States | SOC 2 Type II |
| GoDaddy.com, LLC | DNS hosting | DNS zone records | United States | SOC 2 |
| Snowflake Inc. | Buyer delivery (contracted) | Licensed dataset shares via Secure Share | Buyer-elected region | SOC 2; ISO 27001; FedRAMP Moderate |
| Amazon Web Services, Inc. | Buyer delivery (contracted) | S3 / ADX / compute for licensed payloads | Buyer-elected region | SOC 2; FedRAMP; ISO 27001 |
| Google LLC | Website analytics and tag management (GA4 / GTM) | Pseudonymized page views, events, and referrer metadata when cookies are accepted | United States | Consent-gated; SCCs for EU transfers where applicable |
| LinkedIn Corporation | Advertising measurement (Insight Tag) | Pseudonymized ad engagement signals when marketing cookies are accepted | United States | Consent-gated per privacy policy |
| HubSpot, Inc. | CRM and marketing automation | Contact-form leads and lifecycle email metadata when marketing cookies are accepted | United States | SOC 2 Type II |
| Microsoft Corporation | Advertising measurement (Bing UET) | Pseudonymized ad conversion signals when marketing cookies are accepted | United States | Consent-gated per privacy policy |
Federal deployments
| Sub-processor | Service | Data processed | Authorization |
|---|---|---|---|
| Amazon Web Services GovCloud | Compute / object storage | Federal-customer-licensed datasets | FedRAMP High (in-scope services) |
| Microsoft Azure Government | Compute / storage (alternate path) | Federal-customer-licensed datasets | FedRAMP High |
Data residency
Primary processing occurs in the United States. EU/UK/CH transfers rely on Standard Contractual Clauses with supplementary measures where appropriate, as described in our privacy policy. Region-locked deliveries (Snowflake region, AWS bucket region) can be contracted for scoped programs.
Onboarding safeguards
- DPA or equivalent vendor agreement executed before production use
- Privacy posture review (SCCs, regional certs, subprocessors list)
- Security posture review (SOC 2, ISO 27001, encryption posture)
- Mapped flows: data categories, purposes, retention
- Annual reassessment while services remain active
Report concerns
Privacy & Compliance: privacy@gsdsi.com. Enterprise customers may escalate through their customer-success channel.
