Legal
Sub-processor List
These are the providers we rely on to run Wopie. Each one is bound by a written contract, has been through our security review, and where it is a Model Provider is prohibited from training on your data. We give 30 days' notice before adding a new one.
- Effective
- 6 September 2026
- Version
- 1.0
- Provider
- The Trustee for The Wink Group, trading as Wopie
Use your browser's print function to save this page as a PDF.
1. Current Sub-processors
A Sub-processor is a third party we engage to process Customer Data on our behalf, as defined in our Definitions and governed by the Sub-processors section of our Data Processing Agreement.
| Sub-processor | Purpose | Data processed | Location | Status |
|---|---|---|---|---|
| Amazon Web Services | Cloud infrastructure underlying our database, storage and processing | Customer Data, logs | United States | Confirmed |
| Vercel | Web application hosting and edge network | Request metadata, Account data | United States / global edge | Confirmed |
| Supabase | Database, authentication, file storage | Account data, encrypted tokens, Outputs, audit trail | United States | Confirmed |
| Anthropic | Large language model processing (Model Provider) | Request context and the Customer Data needed to produce Outputs | United States | Confirmed. No training on Customer Data. Inputs and outputs retained no more than 30 days for abuse and safety monitoring, then deleted |
| Slack Technologies (Salesforce) | Chat Platform delivery (Slack) | Messages, user identifiers | United States | Confirmed |
| Microsoft | Chat Platform delivery (Teams) | Messages, user identifiers | Per tenant region | Confirmed |
| Stripe | Payments and billing | Billing contact, payment tokens (no full card numbers are stored by us) | United States | Confirmed |
| Pipedream | Integration connectivity to Connected Tools | OAuth tokens, records read on request | United States | Confirmed |
| PostHog | Product analytics | Usage events, cookies | United States | Planned. Not yet processing any data; will be activated only after the notice period below |
| Resend | Transactional email (sign-in, notifications, renewal reminders) | Account email address, notification content | United States | Planned. Not yet processing any data; will be activated only after the notice period below |
2. How we vet Sub-processors
Before any provider processes Customer Data on our behalf, and at least annually afterwards, we check that it meets the standard our Customers expect of us.
- Contractual data protection terms. Each Sub-processor signs a written agreement requiring it to process Customer Data only on our instructions, keep it confidential, secure it to a standard no less protective than our Data Processing Agreement, assist with data subject requests and incidents, and delete or return data when the engagement ends.
- Security review. We review the provider's security documentation, independent assessments where available, encryption, access controls and incident notification commitments before engagement, and re-check them on renewal.
- Transfer safeguards. Where a Sub-processor processes data outside Australia, we use the transfer mechanism in the International transfers section of the DPA, including the Standard Contractual Clauses and UK Addendum for EEA and UK data.
- No training on Customer Data. Every Model Provider we use is contractually prohibited from using Customer Data, request context or Outputs to train or improve its models.
3. How changes are notified
Before a new Sub-processor begins processing Customer Data, we update this page and email Account owners at least 30 days in advance, so you can review and, on reasonable data protection grounds, object under the Sub-processors section of the DPA. To make sure the right person in your organisation receives these notices, or to ask about any provider listed here, email privacy@wopie.ai.
Removing a Sub-processor, or changing an existing one in a way that does not increase the data it receives, is reflected here without advance notice. If we must replace a Sub-processor urgently to keep the Service secure or available, we will tell you as soon as practicable and explain why.
4. Connected Tools are not Sub-processors
The tools you connect to Wopie, such as HubSpot, Stripe, Notion, Zendesk, Xero, Google Sheets, Gmail and Outlook, are not our Sub-processors. You choose them, you hold the account with each provider, and an Authorised User authorises Wopie to act within the permissions that account already has. When Wopie reads from or writes to a Connected Tool, it does so on your instruction, under your own agreement with that provider.
Each Connected Tool provider is therefore an independent controller or processor of the data it holds, governed by its own terms and privacy policy rather than ours. The integrations we support and the permission scopes each requests are described in the Product Terms and at /security. Stripe appears in the table above only because we use it to bill you; when you connect your own Stripe account as a Connected Tool, this section governs that connection.
5. Certifications held by our providers
The Service runs on infrastructure and platforms whose security programmes are independently audited. The certifications and attestations below belong to those providers and cover the layers they operate (for example the physical data centre, the network, the managed database, or the model API). They are not certifications of Wopie itself. Wopie's own attestation programme is described in the Security section of the Privacy Policy and at /security.
| Provider | Attestations and certifications reported by the provider | Where to verify |
|---|---|---|
| Amazon Web Services | SOC 1, SOC 2, SOC 3; ISO/IEC 27001, 27017, 27018; PCI DSS | aws.amazon.com/compliance |
| Vercel | SOC 2 Type II; ISO/IEC 27001 | vercel.com/security |
| Supabase | SOC 2 Type II. Supabase also offers a HIPAA-eligible configuration; we do not use it, and health information must not be sent to the Service. | supabase.com/security |
| Anthropic | SOC 2 Type II; ISO/IEC 27001; ISO/IEC 42001 (AI management) | trust.anthropic.com |
| Slack (Salesforce) | SOC 2, SOC 3; ISO/IEC 27001, 27017, 27018, 27701 | slack.com/trust |
| Microsoft | SOC 1, SOC 2, SOC 3; ISO/IEC 27001, 27018 | Microsoft Trust Center |
| Stripe | PCI DSS Level 1 service provider; SOC 1, SOC 2 | stripe.com/docs/security |
6. Last updated
This list was last updated on 6 September 2026 (version 1.0). It is referenced by our Privacy Policy and forms part of our Data Processing Agreement.