Legal

Subprocessors

The third parties that process personal data on our behalf to run Zernio. This list is Schedule 2 of our Data Processing Agreement.

Last updated: October 9, 2026

How this list works

We review every subprocessor before we use it and at least once a year after that, and we only share the personal data each one needs for the purpose listed below.

We post any new or replacement subprocessor here at least 14 days before it starts processing personal data. To get those notices by email, write to support@zernio.com with the subject "Subscribe to subprocessor updates". If you object to a change on reasonable data protection grounds, tell us within those 14 days and we will work with you to resolve it.

Where personal data leaves the EU or EEA, each entry below shows the safeguard: the EU-US Data Privacy Framework for certified providers, otherwise the EU Standard Contractual Clauses (Module 3). The social platforms you publish to, such as Instagram or LinkedIn, act as independent controllers and are not our subprocessors.

Infrastructure

  • Purpose:
    Application hosting and request processing
    Data:
    All service data in transit through the API and dashboard
    Location:
    London, UK (functions); global edge
    Transfer safeguard:
    EU-US Data Privacy Framework (Vercel Inc.)
  • Purpose:
    Primary database (Postgres)
    Data:
    Accounts, profiles, connected social accounts, posts, messages and service records
    Location:
    London, UK (AWS eu-west-2)
    Transfer safeguard:
    EU-US Data Privacy Framework (PlanetScale Inc.)
  • Purpose:
    CDN, network security, workers, queues and media storage
    Data:
    Media files and service data in transit
    Location:
    Media storage in Western Europe; global edge network
    Transfer safeguard:
    EU-US Data Privacy Framework (Cloudflare, Inc.)
  • Purpose:
    Redis for caching, coordination and locks
    Data:
    Short-lived cache and coordination entries
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Upstash, Inc.)
  • Purpose:
    Hosting for the MCP server (mcp.zernio.com)
    Data:
    Requests from AI assistants connected to an account
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Railway Corporation)

Messaging and telephony

  • Purpose:
    Phone numbers, SMS, RCS, calls and number registration (only when these features are used)
    Data:
    Messages, call records, phone numbers, and the identity and business documents submitted for regulated numbers
    Location:
    Depends on the service and the number's country
    Transfer safeguard:
    EU-US Data Privacy Framework (Telnyx LLC)
  • Purpose:
    iMessage sending and receiving (only when iMessage is used)
    Data:
    Messages, attachments and recipient phone numbers or email addresses
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Transactional email
    Data:
    Recipient email addresses and notification content
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Plus Five Five, Inc.)

Monitoring and analytics

  • Purpose:
    Operational logging and monitoring
    Data:
    Application logs and queue metrics
    Location:
    US East (N. Virginia), USA
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Error monitoring
    Data:
    Error reports, which can include account identifiers and request contents
    Location:
    Germany (EU region)
    Transfer safeguard:
    EU-US Data Privacy Framework (Functional Software, Inc.)
  • Purpose:
    API analytics and application logs
    Data:
    Service events and post analytics
    Location:
    London, UK
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Product analytics
    Data:
    Dashboard and product interaction events
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (PostHog Inc)

Support and AI

  • Purpose:
    Customer support chat and email
    Data:
    Support conversations, contact details and attachments
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    No transfer (EU-based)
  • Purpose:
    AI-assisted support and automated review of phone number registrations
    Data:
    Support conversations and diagnostic context; registration documents for regulated numbers
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    AI-assisted support (fallback model provider and support search)
    Data:
    Support conversations and diagnostic context, when used
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Microsoft Corporation)
  • Purpose:
    AI checks inside the support assistant
    Data:
    Excerpts of support conversations
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Issue tracking for escalated support cases
    Data:
    Account context and diagnostics from escalated cases
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Internal team notifications for support and billing events
    Data:
    Account contact details and summaries of support or billing events
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Slack Technologies, LLC)
  • Purpose:
    Feature requests board (requests.zernio.com)
    Data:
    Requests, comments and the submitter's name and email
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    No transfer (EU-based)
  • Purpose:
    Business email, and address autocomplete in phone number registration forms
    Data:
    Email correspondence with customers; addresses typed into registration forms
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Google LLC)

Billing, attribution and compliance

  • Purpose:
    Payments
    Data:
    Billing identity, payment methods and invoices
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Stripe, LLC)
  • Purpose:
    Usage-based billing
    Data:
    Customer identifiers and usage metering
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Referral attribution (only for signups that arrive through a referral link)
    Data:
    Name, email and account identifier at signup
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    Standard Contractual Clauses (Module 3)
  • Purpose:
    Server-side tagging for signup conversion measurement
    Data:
    Signup email, name, country, IP address and browser details
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Stape Inc.)
  • Purpose:
    Trust Center administration
    Data:
    Access requests, requester identity and NDA signatures
    Location:
    Provider-managed, not pinned to one region
    Transfer safeguard:
    EU-US Data Privacy Framework (Bubba AI, Inc. d/b/a Comp AI)