Skip to content
wopie.
  • Product
  • Integrations
  • Security
  • Pricing
  • Enterprise
Log inGet started for free
All legal documents
  • Definitions
  • General Terms
  • Acceptable Use
  • Product Terms
  • Usage Terms
  • License Terms
  • Privacy Policy
  • DPA
  • Sub-processors
  • Legal notice

Legal

  • Definitions
  • General Terms
  • Acceptable Use
  • Product Terms
  • Usage Terms
  • License Terms
  • Privacy Policy
  • DPA
  • Sub-processors
  • Legal notice

On this page

  1. 1. Current Sub-processors
  2. 2. How we vet Sub-processors
  3. 3. How changes are notified
  4. 4. Connected Tools are not Sub-processors
  5. 5. Certifications held by our providers
  6. 6. Last updated

Legal

Sub-processor List

These are the providers we rely on to run Wopie. Each one is bound by a written contract, has been through our security review, and where it is a Model Provider is prohibited from training on your data. We give 30 days' notice before adding a new one.

Effective
6 September 2026
Version
1.0
Provider
The Trustee for The Wink Group, trading as Wopie

Use your browser's print function to save this page as a PDF.

1. Current Sub-processors

A Sub-processor is a third party we engage to process Customer Data on our behalf, as defined in our Definitions and governed by the Sub-processors section of our Data Processing Agreement.

Sub-processorPurposeData processedLocationStatus
Amazon Web ServicesCloud infrastructure underlying our database, storage and processingCustomer Data, logsUnited StatesConfirmed
VercelWeb application hosting and edge networkRequest metadata, Account dataUnited States / global edgeConfirmed
SupabaseDatabase, authentication, file storageAccount data, encrypted tokens, Outputs, audit trailUnited StatesConfirmed
AnthropicLarge language model processing (Model Provider)Request context and the Customer Data needed to produce OutputsUnited StatesConfirmed. No training on Customer Data. Inputs and outputs retained no more than 30 days for abuse and safety monitoring, then deleted
Slack Technologies (Salesforce)Chat Platform delivery (Slack)Messages, user identifiersUnited StatesConfirmed
MicrosoftChat Platform delivery (Teams)Messages, user identifiersPer tenant regionConfirmed
StripePayments and billingBilling contact, payment tokens (no full card numbers are stored by us)United StatesConfirmed
PipedreamIntegration connectivity to Connected ToolsOAuth tokens, records read on requestUnited StatesConfirmed
PostHogProduct analyticsUsage events, cookiesUnited StatesPlanned. Not yet processing any data; will be activated only after the notice period below
ResendTransactional email (sign-in, notifications, renewal reminders)Account email address, notification contentUnited StatesPlanned. Not yet processing any data; will be activated only after the notice period below
Confirmed means in production use under data protection terms with the provider. Planned means named in advance; that provider will not process Customer Data until its status changes to Confirmed and the notice period in the How changes are notified section has run.

2. How we vet Sub-processors

Before any provider processes Customer Data on our behalf, and at least annually afterwards, we check that it meets the standard our Customers expect of us.

  • Contractual data protection terms. Each Sub-processor signs a written agreement requiring it to process Customer Data only on our instructions, keep it confidential, secure it to a standard no less protective than our Data Processing Agreement, assist with data subject requests and incidents, and delete or return data when the engagement ends.
  • Security review. We review the provider's security documentation, independent assessments where available, encryption, access controls and incident notification commitments before engagement, and re-check them on renewal.
  • Transfer safeguards. Where a Sub-processor processes data outside Australia, we use the transfer mechanism in the International transfers section of the DPA, including the Standard Contractual Clauses and UK Addendum for EEA and UK data.
  • No training on Customer Data. Every Model Provider we use is contractually prohibited from using Customer Data, request context or Outputs to train or improve its models.

3. How changes are notified

Before a new Sub-processor begins processing Customer Data, we update this page and email Account owners at least 30 days in advance, so you can review and, on reasonable data protection grounds, object under the Sub-processors section of the DPA. To make sure the right person in your organisation receives these notices, or to ask about any provider listed here, email privacy@wopie.ai.

Removing a Sub-processor, or changing an existing one in a way that does not increase the data it receives, is reflected here without advance notice. If we must replace a Sub-processor urgently to keep the Service secure or available, we will tell you as soon as practicable and explain why.

4. Connected Tools are not Sub-processors

The tools you connect to Wopie, such as HubSpot, Stripe, Notion, Zendesk, Xero, Google Sheets, Gmail and Outlook, are not our Sub-processors. You choose them, you hold the account with each provider, and an Authorised User authorises Wopie to act within the permissions that account already has. When Wopie reads from or writes to a Connected Tool, it does so on your instruction, under your own agreement with that provider.

Each Connected Tool provider is therefore an independent controller or processor of the data it holds, governed by its own terms and privacy policy rather than ours. The integrations we support and the permission scopes each requests are described in the Product Terms and at /security. Stripe appears in the table above only because we use it to bill you; when you connect your own Stripe account as a Connected Tool, this section governs that connection.

5. Certifications held by our providers

The Service runs on infrastructure and platforms whose security programmes are independently audited. The certifications and attestations below belong to those providers and cover the layers they operate (for example the physical data centre, the network, the managed database, or the model API). They are not certifications of Wopie itself. Wopie's own attestation programme is described in the Security section of the Privacy Policy and at /security.

ProviderAttestations and certifications reported by the providerWhere to verify
Amazon Web ServicesSOC 1, SOC 2, SOC 3; ISO/IEC 27001, 27017, 27018; PCI DSSaws.amazon.com/compliance
VercelSOC 2 Type II; ISO/IEC 27001vercel.com/security
SupabaseSOC 2 Type II. Supabase also offers a HIPAA-eligible configuration; we do not use it, and health information must not be sent to the Service.supabase.com/security
AnthropicSOC 2 Type II; ISO/IEC 27001; ISO/IEC 42001 (AI management)trust.anthropic.com
Slack (Salesforce)SOC 2, SOC 3; ISO/IEC 27001, 27017, 27018, 27701slack.com/trust
MicrosoftSOC 1, SOC 2, SOC 3; ISO/IEC 27001, 27018Microsoft Trust Center
StripePCI DSS Level 1 service provider; SOC 1, SOC 2stripe.com/docs/security
Each entry reflects what the provider publishes on its own trust page as at 6 September 2026. We re-check these at least annually and whenever we add a provider. If a provider withdraws or changes an attestation we update this page. A provider's certification does not transfer to us and we do not describe it as ours.

6. Last updated

This list was last updated on 6 September 2026 (version 1.0). It is referenced by our Privacy Policy and forms part of our Data Processing Agreement.

Questions about this document: legal@wopie.ai. Read the Definitions for the meaning of capitalised terms.

wopie.

The AI employee that finishes work inside Slack and Microsoft Teams.

Approval gates · Audit trail · DPA published

Product

ProductWopie for SlackWopie for Microsoft TeamsIndustriesIntegrationsChangelog

Company

EnterpriseSecurityPartnersContact

Get started

PricingDocsGet $100 on usLog in
wopie
© 2026 Wopie. All rights reserved.
Terms of ServicePrivacy PolicyLegal