Effective Date: July 27, 2025
Sub-Processor | Purpose | Location | Safeguards |
---|---|---|---|
Sentry | For logging errors | USA | GDPR/CCPA aligned DPA, prohibits sensitive data, deletion on request, customer audit rights |
PostHog | For logging clicks | USA | SOC 2 Type II, GDPR/CCPA-aligned DPA, strict use‑only data purpose clauses, hardware MFA, public audit transparency |
AWS | For integrating with 3rd party apps like GCal or Outlook | USA | Encryption in transit & at rest, strict access controls, incident response plans, privacy‑focused vendor management, confidentiality contracts, staff training |
Keygen | For issuing licenses for Hyprnote Pro | USA | Strong MFA, cryptographically signed APIs/licenses, automated vulnerability scanning, penetration testing, GDPR DSR support |
Stripe | For payment processing | USA | Vendor security assessments, audit rights, DPA and Data Privacy Framework compliance, data localization options |
Linear | For collaborating with teammates | USA | SOC 2 Type II, HIPAA (BAA available), GDPR‑compliant DPA, sub‑processor assessments, admin controls, audit logging, secure data deletion/portability |
GitHub | For hosting our codebase | USA | Public sub‑processor list, contractual commitments, advance notification of changes |
CrabNebula | For CI/CD | USA | SSL/TLS, least‑privilege models, internal and external CI/CD audits, GDPR‑only data residency EU |