Skip to content
Skip to content
Legal documents· Sub-processors
Legal

Sub-processors

Every third party that may process personal data for Sequenz, with its purpose, data categories and processing region. 22 disclosed.

Last updated: 22 sub-processors disclosed at Launch
On this page

What a sub-processor is

A sub-processor is a third-party service that may process personal data on Sequenz's behalf in the course of providing the platform. Sequenz remains accountable for the data; each sub-processor is engaged under a written agreement and processes data only on documented instructions.

For the data in your workspace you are the controller and Sequenz Ltd is your processor; you authorise the sub-processors on this list when you accept our Data Processing Agreement (Section 6). We pass on data-protection obligations no less protective than that agreement, and we remain responsible to you for how each sub-processor performs them.

Back to top

Notification of changes

Sequenz maintains this list as the canonical, version-controlled record. When a new sub-processor is added or an existing one materially changes, Sequenz gives notice at least 30 days before the change takes effect, so customers can review and, where their agreement allows, object.

  • To receive change notices, email privacy@sequenz.ai.
  • Each entry below names the company, its purpose, the categories of data it may process, and its processing region.
  • To object, write to privacy@sequenz.ai within 30 days of the notice with your data-protection reasons. If we cannot reasonably accommodate the objection, you may end the affected part of the service (DPA Section 6.3).
Back to top

The full list

Every third party that can touch personal data is listed below, grouped by function.

Processing region
Showing 22 of 22
Sequenz sub-processors: name, purpose, data categories, processing location and status
Sub-processorPurposeDataLocationStatus
CRM sync
HubSpotDisclosedCRM lead and activity syncContact and company records, engagement eventsUS / EUDisclosed
SalesforceDisclosedCRM lead and activity syncContact and account records, activitiesUS / EUDisclosed
PipedriveDisclosedCRM lead and activity syncContact and deal records, activitiesEUDisclosed
Messaging channels
Meta WhatsApp Business CloudDisclosedWhatsApp message delivery (your WABA)Phone number, message content, delivery stateUS / EUDisclosed
Google (Gmail API)DisclosedCampaign email sending from your mailboxEmail address, message contentUS / EUDisclosed
Microsoft (Outlook / Graph)DisclosedCampaign email sending from your mailboxEmail address, message contentUS / EUDisclosed
Scheduling & lead ingest
CalendlyDisclosedMeeting scheduling and event ingestName, email, meeting metadataUSDisclosed
Google Sheets APIDisclosedLead list ingest from your sheetLead fields you provideUS / EUDisclosed
AI & transactional email
OpenAIDisclosedAI-written drafts, reply sorting and in-app assistantsLead context provided in promptsUSDisclosed
ResendDisclosedTransactional and system email (not campaigns)Account email addressUS / EUDisclosed
BouncerDisclosedCatch-all domain check (only when the sending policy is switched on)Email domain names only — no address, name, or lead identifierEUDisclosed
Infrastructure
VercelDisclosedWeb application hostingRequest metadataEU edge / USDisclosed
NorthflankDisclosedBackend API + worker hosting and managed PostgreSQL (primary data store)All stored platform dataEUDisclosed
UpstashDisclosedRedis queue and cacheTransient job payloadsEUDisclosed
Cloudflare R2DisclosedObject storage for data-export filesExported account/lead data (temporary)EUDisclosed
IPRoyal (IPRoyal Services FZE LLC)DisclosedDedicated egress IP for LinkedIn automation — a TLS conduit that carries your LinkedIn traffic. It does not see message or profile content.Connection metadata (address, timing, volume)UAE (Ajman) — EU SCCs; egress IP in your declared countryDisclosed
Bright Data (Bright Data Ltd.)DisclosedDedicated egress IP for LinkedIn automation in the UAE and Saudi Arabia, where the provider above has no coverage — a TLS conduit that carries your LinkedIn traffic. It does not see message or profile content.Connection metadata (address, timing, volume)Israel (Netanya) — EU adequacy decision; UAE + Saudi egress onlyDisclosed
Identity & billing
ClerkDisclosedAuthentication and workspace identityName, email, auth metadataUS / EUDisclosed
StripeDisclosedSubscription billing and paymentsBilling contact, payment metadataUS / EUDisclosed
Monitoring & analytics
SentryDisclosedError monitoringDiagnostic data, user identifiersEU / USDisclosed
PostHogDisclosedProduct analyticsUsage events, user identifiersEUDisclosed
Chrome extension telemetryDisclosedLinkedIn extension health telemetryExtension diagnostics, user identifierEUDisclosed
Back to top

Notes and reconciliation

The legal entity behind each service is named in Annex B of the DPA. Sequenz does not claim SOC 2 or ISO certifications it does not hold.

Where a sub-processor is outside the UK and the EEA, the transfer rests on one of three grounds: the EU–US Data Privacy Framework (with its UK Extension) for certified US companies; a European Commission adequacy decision (Bright Data, Israel); or the EU Standard Contractual Clauses (OpenAI, with the UK Addendum; IPRoyal). The DPA sets these out.

Before engaging a sub-processor we review its security and data-protection terms and record its transfer ground. Your rights over this list (notice, objection and audit) are in Sections 6 and 10 of the DPA.

Back to top