Trust Center / Legal

Sub-processors

Last updated: April 2026Trust Center

Workiflow uses a limited number of third-party sub-processors to assist in delivering our Services. Each sub-processor is contractually required to protect personal data in accordance with our Data Processing Agreement and applicable data protection laws.

We only engage sub-processors where necessary for the delivery of our Services. Not all sub-processors are used in every client engagement. The specific sub-processors involved depend on the Services being provided.

Current Sub-processors

/01

Service Delivery and Project Management

Sub-processorPurposeLocation
monday.comProject management, client workspace management, and service deliveryUS / EU
Make.comWorkflow automation and integration servicesEU
FrontClient email communication and shared inbox managementUS
SlackInternal team communication (may include client-related discussions)US
/02

Cloud Infrastructure and Hosting

Sub-processorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure and application hostingUS
Google Cloud PlatformCloud infrastructure and application servicesUS
Google FirebaseApplication backend and hostingUS
SupabaseDatabase backend for applications and websiteUS
VercelWebsite hosting and deploymentUS
GitHubSource code management and version controlUS
/03

AI and Automation

Sub-processorPurposeLocation
Anthropic (Claude)AI-powered analysis, content generation, and workflow assistanceUS
OpenAI (ChatGPT)AI-powered agents and automationUS

Workiflow maintains paid business plans with both AI providers, under terms that prohibit training on inputs and outputs. Client data is never used to train AI models.

/04

Communication and Collaboration

Sub-processorPurposeLocation
Google WorkspaceEmail, documents, calendars, and internal collaborationUS
ZoomVideo conferencing, phone, scheduling, and meeting recordingsUS
Recall.aiMeeting bot for automated recording, transcription, and note-takingUS
ResendTransactional and automated email deliveryUS

Recall.ai joins meetings as an automated participant to capture recordings and transcripts. Meeting content may include client discussions, strategy sessions, and sensitive business information. Recordings and transcripts are used for internal reference, meeting follow-ups, and service delivery. Clients will be informed when a meeting bot is present.

/05

Time Tracking and Operations

Sub-processorPurposeLocation
EverhourTime tracking and activity monitoring (includes periodic screenshots during active work sessions)US

Everhour's screenshot feature captures periodic screen images during tracked work sessions. These screenshots may incidentally contain client data visible on screen. Screenshots are used solely for internal time verification and are retained in accordance with our data retention policies.

/06

Financial and Billing

Sub-processorPurposeLocation
StripePayment processing and invoicingUS
QuickBooksAccounting, invoicing, and financial record-keepingUS
MercuryBusiness banking and payment operationsUS

Financial sub-processors may process limited client information such as company name, billing contact details, and transaction amounts in connection with invoicing and payment processing.

/07

Security

Sub-processorPurposeLocation
At-Bay (Stance)Security monitoring, vulnerability management, and threat detectionUS

How We Manage Sub-processors

Before engagement.

We assess each sub-processor's security practices, data handling policies, and compliance posture before granting access to any personal data.

Contractual protections.

Every sub-processor is bound by a written agreement that imposes data protection obligations consistent with our DPA and applicable data protection laws.

Ongoing review.

We periodically review our sub-processors to ensure continued compliance with our security and privacy standards.

Notification of Changes

When we engage a new sub-processor, we update this page and notify clients with an active Data Processing Agreement at least fourteen (14) days before the new sub-processor begins processing personal data.

If you have concerns about a new sub-processor, you may object in writing within the notification period as described in our DPA.

Questions

If you have questions about our sub-processors or data processing practices, contact us at security@workiflow.com.