Intriq Logo
IntriqDocumentation
⌘K
HomeDashboardGitHub
User DocsAPI ReferenceChangelogSecurity

Loading Documentation

Preparing content for you...

Sub-Processors

Third-party service providers processing customer data

Version 2.0•Last Updated: 2025-12-05
Overview

Intriq AI uses carefully selected sub-processors to provide and improve our services. All sub-processors are subject to strict data processing agreements and security assessments. This list is updated as sub-processors are added or removed.

Change Notification

We will notify customers at least 30 days in advance of adding or replacing sub-processors. Customers may object to new sub-processors within 14 days of notification. If objection cannot be resolved, customers may terminate their agreement without penalty.

Subscribe to Updates
Sub-Processor Assessment

Selection Criteria:

Security certifications (SOC 2, ISO 27001, or equivalent)
Data protection and privacy controls (GDPR compliance)
Incident response and breach notification procedures
Data residency and transfer mechanisms
Financial stability and business continuity
References and reputation in the industry

All sub-processors must sign a Data Processing Agreement (DPA) with security and confidentiality obligations equivalent to our customer agreements.

Active Sub-Processors

Amazon Web Services (AWS)
Amazon.com, Inc.
Active

Location

United States (primary), EU (eu-west-1)

Data Residency

EU West (Ireland) - eu-west-1

Purpose

Cloud infrastructure and hosting (compute, storage, database, authentication)

Added

2024-01-15

Services Provided:

Amazon ECS (Elastic Container Service) - Application hosting
Amazon RDS (Relational Database Service) - PostgreSQL database
Amazon S3 (Simple Storage Service) - File storage
Amazon Cognito - User authentication and identity management
Amazon Bedrock - AI/ML model inference (Claude 3.5 Sonnet)
Amazon Textract - Document text extraction
AWS Lambda - Serverless compute for background jobs
Amazon CloudWatch - Monitoring and logging
AWS Secrets Manager - Secrets storage
Amazon SES - Email delivery

Certifications & Compliance:

SOC 1, SOC 2, SOC 3ISO 27001, ISO 27017, ISO 27018PCI DSS Level 1GDPR compliantHIPAA eligible

Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs), AWS GDPR DPA

WebsitePrivacy PolicySecurity
Sentry
Functional Software, Inc.
Active

Location

United States (San Francisco, CA)

Data Residency

United States (us-east-1), EU available

Purpose

Application performance monitoring and error tracking

Added

2024-02-01

Services Provided:

Error and exception tracking
Performance monitoring
Release tracking
User feedback collection

Data Processed:

Application errors and stack tracesUser identifiers (hashed)Request metadata (URL, user agent, IP address)Performance metrics

Certifications & Compliance:

SOC 2 Type IIISO 27001GDPR compliantEU-U.S. Data Privacy Framework

Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)

Data Retention: 90 days (configurable, default 30 days)

WebsitePrivacy PolicySecurityDPA
GitHub
Microsoft Corporation
Active

Location

United States

Data Residency

United States (primary), global CDN

Purpose

Source code repository and version control

Added

2024-01-15

Services Provided:

Git repository hosting
Code review and collaboration
CI/CD pipelines (GitHub Actions)
Dependency scanning (Dependabot)
Secret scanning

Data Processed:

Source code (internal repositories only)Commit history and metadataIssue and pull request dataDeveloper identities (email, username)

Certifications & Compliance:

SOC 1, SOC 2ISO 27001GDPR compliant

Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs), Microsoft GDPR commitments

WebsitePrivacy PolicySecurity

GitHub does not process customer production data. Used for internal development and CI/CD only.

PostHog
PostHog, Inc.
Active

Location

United States (San Francisco, CA)

Data Residency

EU (eu.i.posthog.com - Frankfurt, Germany)

Purpose

Product analytics and session recording

Added

2025-12-01

Services Provided:

Product analytics and event tracking
Session recording and replay
Feature flag management
A/B testing and experimentation
User surveys and feedback

Data Processed:

User interactions and eventsSession recordings (opt-in)User identifiers (user ID, email)Device and browser metadataPage views and navigation

Certifications & Compliance:

SOC 2 Type IIGDPR compliantISO 27001 (in progress)

Data Transfer Mechanism: EU hosting (Frankfurt), GDPR DPA available

Data Retention: 7 years (configurable)

WebsitePrivacy PolicySecurityDPA

EU cloud hosting ensures all analytics data stays in EU (Frankfurt). Session recording enabled only in production for authenticated users.

Resend
Resend, Inc.
Active

Location

United States (San Francisco, CA)

Data Residency

United States (AWS us-east-1)

Purpose

Transactional email delivery (development and testing only)

Added

2025-10-01

Services Provided:

Email template rendering (React Email)
Email delivery API
Email analytics and tracking

Data Processed:

Email addresses (recipients)Email content (verification codes, notifications)Delivery status and bounce data

Certifications & Compliance:

SOC 2 Type II (in progress)GDPR compliant

Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)

Data Retention: 30 days (email logs)

WebsitePrivacy PolicySecurity

Used for development and testing environments only. Production emails sent via AWS SES (eu-west-1).

Linear
Linear Orbit, Inc.
Active

Location

United States (San Francisco, CA)

Data Residency

United States (AWS us-east-1), EU available

Purpose

Project management and issue tracking (internal operations only)

Added

2024-03-01

Services Provided:

Issue and task tracking
Sprint planning and roadmaps
Team collaboration
API integration for workflow automation

Data Processed:

Internal project data (tasks, bugs, features)Team member identitiesComments and attachmentsNo customer production data

Certifications & Compliance:

SOC 2 Type IIGDPR compliant

Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)

WebsitePrivacy PolicySecurity

Linear does not process customer production data. Used exclusively for internal project management and development workflows.

Slack
Salesforce, Inc.
Active

Location

United States (San Francisco, CA)

Data Residency

United States (primary), EU available

Purpose

Internal team communication and automated notifications

Added

2024-01-15

Services Provided:

Team messaging and collaboration
Automated system notifications
Alert monitoring (errors, deployments)
Workflow automation via Slack API

Data Processed:

Internal team messagesSystem alerts and notificationsTeam member identitiesNo customer production data (anonymized error logs only)

Certifications & Compliance:

SOC 2, SOC 3ISO 27001, ISO 27017, ISO 27018GDPR compliantFedRAMP Moderate (US Gov)

Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs), Salesforce GDPR commitments

WebsitePrivacy PolicySecurityDPA

Slack does not process customer production data. Used for internal team communication and system monitoring alerts only. Error logs are anonymized before posting.

Historical Sub-Processors

Auth0 (Legacy)

Removed

Parent: Okta, Inc.

Purpose: User authentication (replaced by AWS Cognito)

Removed: 2024-12-15

Reason: Migrated to AWS Cognito for unified AWS infrastructure and cost optimization

Vercel (Legacy)

Removed

Parent: Vercel Inc.

Purpose: Frontend hosting (replaced by AWS ECS Fargate with ALB)

Removed: 2025-01-31

Reason: Consolidated all production infrastructure on AWS. All traffic now served via AWS ECS Fargate with Application Load Balancer for better control, security, and cost optimization.

Postmark (Never Deployed)

Removed

Parent: ActiveCampaign, LLC

Purpose: Transactional email (replaced by AWS SES before production launch)

Removed: 2025-10-22

Reason: Decided to use AWS SES directly for unified AWS infrastructure and better integration with Cognito

Data Flow Summary
How customer and internal data flows through our sub-processors

Customer Data:

  • User credentials (email, password hash) → AWS Cognito (eu-west-1)
  • User profile data → AWS RDS PostgreSQL (eu-west-1)
  • Uploaded files → AWS S3 (eu-west-1)
  • Document processing → AWS Lambda → AWS Bedrock (eu-west-1)
  • Transactional emails → AWS SES (eu-west-1, production), Resend (development only)
  • Application errors → Sentry (EU de.sentry.io)
  • Product analytics → PostHog (EU eu.i.posthog.com, Frankfurt)

Internal Data:

  • Source code → GitHub (US)
  • Production hosting → AWS ECS Fargate (eu-west-1)
  • Project management → Linear (US, internal only)
  • Team communication → Slack (US, internal only, anonymized alerts)
Data Retention Policies
customer Data: Retained as long as customer account is active. Deleted within 90 days of account deletion request.
logs: CloudWatch logs retained for 90 days. Sentry data retained for 30 days (default).
backups: RDS automated backups retained for 7 days. Manual snapshots retained until explicitly deleted.

Questions about sub-processors?

Privacy: privacy@intriq.ai

DPO: dpo@intriq.ai

For questions about sub-processors or to request a Data Processing Agreement, contact privacy@intriq.ai

Contact Privacy Team