Sub-processors
Every third party that may process personal data for Sequenz, with its purpose, data categories and processing region. 22 disclosed.
On this page
What a sub-processor is
A sub-processor is a third-party service that may process personal data on Sequenz's behalf in the course of providing the platform. Sequenz remains accountable for the data; each sub-processor is engaged under a written agreement and processes data only on documented instructions.
For the data in your workspace you are the controller and Sequenz Ltd is your processor; you authorise the sub-processors on this list when you accept our Data Processing Agreement (Section 6). We pass on data-protection obligations no less protective than that agreement, and we remain responsible to you for how each sub-processor performs them.
Back to topNotification of changes
Sequenz maintains this list as the canonical, version-controlled record. When a new sub-processor is added or an existing one materially changes, Sequenz gives notice at least 30 days before the change takes effect, so customers can review and, where their agreement allows, object.
- To receive change notices, email privacy@sequenz.ai.
- Each entry below names the company, its purpose, the categories of data it may process, and its processing region.
- To object, write to privacy@sequenz.ai within 30 days of the notice with your data-protection reasons. If we cannot reasonably accommodate the objection, you may end the affected part of the service (DPA Section 6.3).
The full list
Every third party that can touch personal data is listed below, grouped by function.
| Sub-processor | Purpose | Data | Location | Status |
|---|---|---|---|---|
| CRM sync | ||||
| HubSpotDisclosed | CRM lead and activity sync | Contact and company records, engagement events | US / EU | Disclosed |
| SalesforceDisclosed | CRM lead and activity sync | Contact and account records, activities | US / EU | Disclosed |
| PipedriveDisclosed | CRM lead and activity sync | Contact and deal records, activities | EU | Disclosed |
| Messaging channels | ||||
| Meta WhatsApp Business CloudDisclosed | WhatsApp message delivery (your WABA) | Phone number, message content, delivery state | US / EU | Disclosed |
| Google (Gmail API)Disclosed | Campaign email sending from your mailbox | Email address, message content | US / EU | Disclosed |
| Microsoft (Outlook / Graph)Disclosed | Campaign email sending from your mailbox | Email address, message content | US / EU | Disclosed |
| Scheduling & lead ingest | ||||
| CalendlyDisclosed | Meeting scheduling and event ingest | Name, email, meeting metadata | US | Disclosed |
| Google Sheets APIDisclosed | Lead list ingest from your sheet | Lead fields you provide | US / EU | Disclosed |
| AI & transactional email | ||||
| OpenAIDisclosed | AI-written drafts, reply sorting and in-app assistants | Lead context provided in prompts | US | Disclosed |
| ResendDisclosed | Transactional and system email (not campaigns) | Account email address | US / EU | Disclosed |
| BouncerDisclosed | Catch-all domain check (only when the sending policy is switched on) | Email domain names only — no address, name, or lead identifier | EU | Disclosed |
| Infrastructure | ||||
| VercelDisclosed | Web application hosting | Request metadata | EU edge / US | Disclosed |
| NorthflankDisclosed | Backend API + worker hosting and managed PostgreSQL (primary data store) | All stored platform data | EU | Disclosed |
| UpstashDisclosed | Redis queue and cache | Transient job payloads | EU | Disclosed |
| Cloudflare R2Disclosed | Object storage for data-export files | Exported account/lead data (temporary) | EU | Disclosed |
| IPRoyal (IPRoyal Services FZE LLC)Disclosed | Dedicated egress IP for LinkedIn automation — a TLS conduit that carries your LinkedIn traffic. It does not see message or profile content. | Connection metadata (address, timing, volume) | UAE (Ajman) — EU SCCs; egress IP in your declared country | Disclosed |
| Bright Data (Bright Data Ltd.)Disclosed | Dedicated egress IP for LinkedIn automation in the UAE and Saudi Arabia, where the provider above has no coverage — a TLS conduit that carries your LinkedIn traffic. It does not see message or profile content. | Connection metadata (address, timing, volume) | Israel (Netanya) — EU adequacy decision; UAE + Saudi egress only | Disclosed |
| Identity & billing | ||||
| ClerkDisclosed | Authentication and workspace identity | Name, email, auth metadata | US / EU | Disclosed |
| StripeDisclosed | Subscription billing and payments | Billing contact, payment metadata | US / EU | Disclosed |
| Monitoring & analytics | ||||
| SentryDisclosed | Error monitoring | Diagnostic data, user identifiers | EU / US | Disclosed |
| PostHogDisclosed | Product analytics | Usage events, user identifiers | EU | Disclosed |
| Chrome extension telemetryDisclosed | LinkedIn extension health telemetry | Extension diagnostics, user identifier | EU | Disclosed |
Notes and reconciliation
The legal entity behind each service is named in Annex B of the DPA. Sequenz does not claim SOC 2 or ISO certifications it does not hold.
Where a sub-processor is outside the UK and the EEA, the transfer rests on one of three grounds: the EU–US Data Privacy Framework (with its UK Extension) for certified US companies; a European Commission adequacy decision (Bright Data, Israel); or the EU Standard Contractual Clauses (OpenAI, with the UK Addendum; IPRoyal). The DPA sets these out.
Before engaging a sub-processor we review its security and data-protection terms and record its transfer ground. Your rights over this list (notice, objection and audit) are in Sections 6 and 10 of the DPA.
Back to top