GlobalCanadaEuropeAsia-Pacific
Sign in

Back to the sub-processor register

Sub-processor records

The formal record for every sub-processor in the register: the purpose, data category, and region that our Data Processing Agreement incorporates by reference, grouped by the job each company does for you.

Distronode Corporation • Last Updated: September 10, 2026

What this page is. A sub-processor is another company we bring in to do part of the work, one that handles some customer data while doing it. Nobody builds phone networks, speech models, card processing, and global infrastructure alone, so every product like District AI relies on companies like these. What varies is how much gets disclosed: we name every one of them, with nothing summarized away.

How to read it. The register is grouped by the job each company does for you. Every entry opens with a plain-language sentence, a chip for the region it runs in, chips for the kinds of data it can see, and a label wherever something is optional, off by default, admin-only, or touches no customer data at all. Under each entry sits the formal record, the purpose, data category, and region that our Data Processing Agreement incorporates by reference.

What to take from it. If you just want to know who hears your calls, the call-data path on the register answers it: a typical call touches only a handful of these companies, and several entries below receive no customer data unless you deliberately turn a feature on. If you are running a formal vendor review, the purpose, data category, and region fields are written for your checklist, and legal@distronode.com will answer anything the page does not.

Connects your calls & texts

Twilio

  • US / EU handoff
  • call audio
  • messages
  • phone numbers
  • registration documents
  • identity documents

Carries your phone calls and text messages. Calls we place for European workspaces over Twilio connect through Twilio's Dublin edge in Ireland.

Purpose
Inbound and outbound voice (SIP) and SMS/MMS; caller-ID (CNAM) and line-type/carrier lookup
Data category
Phone numbers, call audio, message content, and caller metadata. Where you register a number in a country whose regulator requires documents, also the registration documents you provide — business registry extracts, proofs of address and, for registrations in an individual's name, government identity documents
Region

United States for calls that arrive to us over the phone network on United States and Canadian numbers, and for messaging. A call that ARRIVES on a Twilio-issued number is the same answer whether the number is Canadian or a United States one: it reaches us in the United States. That is why our Canadian residency statements name the carrier that issued a number rather than the country it is in.

A call that arrives on a European number is delivered to us by Twilio at its Dublin edge in Ireland instead, to our own equipment in Frankfurt, since August 2026. In Europe, a number in Estonia needs no paperwork from you, because we hold that country's registration ourselves, and other European countries open once your workspace's own local registration is approved. For a European workspace, a call that we place outbound over Twilio connects from our own equipment in Frankfurt to Twilio's Dublin edge in Ireland, since August 2026, and our own measurements show the call's media being handled in Ireland at that point.

For a Canadian workspace, a call that we place outbound over Twilio has left from our own equipment in Montreal since September 2026. Twilio publishes no Canadian point of presence, so such a call enters Twilio's United States infrastructure and we claim no Canadian region for it. Twilio has not yet confirmed its processing location in writing, so we do not claim a region for what happens past that handoff. Since August 2026, registration documents you submit for a number in a regulated country are held by Twilio's regulatory-compliance service, which runs in the United States. Nothing is sent to it until you submit a registration

Sinch

  • US
  • messages
  • call audio

Sends and receives SMS messages, and carries some calls.

Purpose
SMS messaging and voice
Data category
Phone numbers, message content, and call audio
Region
United States (parent company in Sweden). Sinch's messaging service keeps a copy of message content for 180 days after delivery, its default retention, then deletes it.

Telnyx

  • US / EU / CA handoff
  • call audio
  • messages

An additional carrier for calls and texts. Calls we place for European workspaces are handed to Telnyx in Frankfurt, the calls we place for Canadian workspaces are handed to Telnyx in Montreal, and a call arriving on a Canadian number we issue through Telnyx is delivered from its Canadian gateway to Montreal.

Purpose
SIP voice and SMS/MMS
Data category
Phone numbers, call audio, and message content
Region

United States for calls that arrive to us on a number issued through another carrier, and for messaging. For a European workspace, a call that we place outbound is handed to Telnyx at its Frankfurt site, from our own equipment in Frankfurt. Since September 2026 Canadian calls are Telnyx's in both directions. A call we place outbound for a Canadian workspace is handed to Telnyx at its Montreal site from our own equipment in Montreal. A call arriving on a Canadian number we issue through Telnyx is delivered to that same equipment from Telnyx's Canadian gateway.

Text messages are a separate answer from calls on the same number. A message sent to or from a Canadian number we issue through Telnyx is carried through Telnyx's United States messaging interface, so the Montreal handling described here covers that number's calls and not its texts. Telnyx describes where it processes a call as a preference it endeavours to honour rather than something it guarantees contractually, so we do not claim a region for what happens before it hands us a call or after we hand it one

Runs the platform

Google Cloud Platform (Google LLC)

  • Your region
  • call audio
  • transcripts
  • contacts
  • CRM records
  • call events
  • web requests

Runs our databases, storage, and AI — your workspace data is stored in your chosen region.

Purpose
Database, compute, real-time media, call-recording object storage (Cloud Storage), and AI language-model inference and text embeddings (Vertex AI) for both the live call and the dashboard's own AI features. It also runs the internal message buses that carry live call events to the dashboard (Pub/Sub, one in the United States, one in Frankfurt and one in Montreal), encryption key management, secrets, mobile push notification delivery (Firebase Cloud Messaging), and logging
Data category
Contacts, call audio, transcripts, CRM records, account data, and content processed by the AI. The live call events carried on the message bus include the caller's name and the phone numbers on the call, and, for a call that arrives over the phone network, the transcript, the AI summary and the link to the recording. A push notification sent to a mobile device carries identifiers only — the workspace and call identifiers and the kind of notification — and never the message text, a phone number or a caller's name
Region

United States (us-east4) for the default workspace region, for the coordination database that keeps sign-in and phone routing working across regions, and for most AI inference. It also runs in-browser call media for United States and Asia-Pacific workspaces, the outbound calls we place for United States and Asia-Pacific workspaces, and the media of calls that ARRIVE over the telephone network on a number issued through Twilio, Canadian or United States alike. Google Cloud no longer holds the Canadian, European or Asia-Pacific workspace database: those three moved to Amazon Web Services in August 2026, in the same cities as before.

Five things no longer run here, and the first two are European. A call we place outbound for a European workspace: since August 2026 its media and the equipment that connects it to the telephone network run on our Frankfurt machine instead. A call that arrives on our first European number, in Estonia: since August 2026 it is delivered by Twilio in Ireland to that same Frankfurt machine and its media is handled there.

The other three are Canadian. In-browser call media for a Canadian workspace: since August 2026 that is processed on our Montreal machine, which is operated by Amazon Web Services. A call we place outbound for a Canadian workspace: since September 2026 its media and the equipment that connects it to the telephone network run on that same Montreal machine. And a call that arrives on a Canadian number we issue through Telnyx: since September 2026 it is delivered by Telnyx from its Canadian gateway to that machine and answered there. A call that arrives on a number issued through Twilio, Canadian or United States, is still answered and hosted here.

Recorded call audio is NOT held in one place. Each workspace's recordings are stored in a bucket in its own region: us-east4, Montreal (northamerica-northeast1), Frankfurt (europe-west3) or Singapore (asia-southeast1). Since August 2026 the same is true of number registration documents (registry extracts, proofs of address and, for registrations in an individual's name, government identity documents). Each workspace's documents rest in a bucket in its own region and are deleted 30 days after the number is released or the registration is withdrawn.

AI language-model inference is not all in one place either. The live-call language model for European workspaces runs in the EU (europe-west4). Since September 2026 the language model for Canadian workspaces runs in Montreal (northamerica-northeast1) on every voice engine but the realtime one, as do the model that writes a call's summary afterwards and the one that reads a shared screen.

The one exception is the realtime voice engine, whose single listen-and-speak model Google does not serve from Montreal at all, so a Canadian workspace on that engine is still processed in us-east4.

Since September 2026 the AI features of the dashboard itself run in Montreal (northamerica-northeast1) for a Canadian workspace, where they had run in the United States for every region until then. They are the suggested reply drafts, the meeting minutes, the analysis of a call after it ends, the lead dossiers, the console assistant's answers and the text embeddings that make a workspace's knowledge base searchable. A European workspace's dashboard AI runs in the EU (europe-west4) on the same rule.

Live call events are carried on a message bus in the United States for United States and Asia-Pacific workspaces, consumed by our dashboard service in us-east4. They ride a European message bus in Frankfurt (europe-west3) for European workspaces, consumed by our dashboard service in Frankfurt. Since September 2026 they ride a Canadian message bus in Montreal (northamerica-northeast1) for Canadian workspaces, consumed by our dashboard service in Montreal, so that the dashboard can show a call while it is happening. Only calls carried over the phone network produce them.

Where one of those events is created is a separate question from where it is carried. For a European workspace such an event is still created in the United States when the call arrives on a number issued through Twilio, because that is where such a call reaches us. A call that arrives on our European number, like a call we place outbound for a European workspace, generates its events in Frankfurt, because the systems that write them run there.

For a Canadian workspace the same split falls on the carrier: a call we place and a call arriving on a Canadian number we issue through Telnyx generate their events in Montreal, because since September 2026 those calls run on our Montreal machine. A call arriving on a number issued through Twilio generates its event in the United States before it is carried to Montreal and stored.

Three things we do here are not regional at all, and a Canadian workspace is subject to each of them. The key that encrypts the third-party credentials a workspace connects to us lives in a key ring created in Google's GLOBAL location rather than in Montreal, so those credentials are unwrapped against a key that is not held in Canada. The store that holds our own secrets replicates automatically across Google's network rather than to a region we pick. And a push notification that wakes a mobile device is delivered by Firebase Cloud Messaging from outside Canada, carrying identifiers only, so the app fetches whatever it needs afterwards under its own credential

Amazon Web Services (Amazon Web Services, Inc.)

  • Your region
  • call audio
  • contacts
  • CRM records
  • transcripts
  • web requests
  • session data

Runs the website, dashboard and workspace database for Canada, Europe and Asia-Pacific, handles Canadian and European in-browser call media, carries a Canadian workspace's telephone calls in both directions when the number was issued through Telnyx, and since September 2026 turns speech into text and back for new Canadian workspaces.

Purpose
Website and dashboard hosting origin, and the workspace database, for the Canadian, European and Asia-Pacific regions, plus the regional container registry each of those origins pulls its software from. Real-time call media for Canadian and European workspaces' in-browser calls, including the relay used when a participant's network blocks direct connections. The equipment that connects a European workspace's outbound telephone calls to our carrier and, since September 2026, a Canadian workspace's telephone calls in both directions. Since September 2026, speech-to-text transcription (Amazon Transcribe) and text-to-speech (Amazon Polly) for Canadian workspaces on the voice engine a new Canadian workspace starts on
Data category

For workspaces in those three regions: contacts, CRM records, call metadata and transcripts, message content, and account data. Also web application requests, session data, and form submissions routed to that region's origin.

For Canadian workspaces additionally: live call audio for calls made or received in the browser, and, since September 2026, for the telephone calls we place outbound and for those arriving on a Canadian number we issue through Telnyx, processed in Montreal and not stored there. Since the same date, also the call audio a Canadian workspace's voice engine transcribes and the text it synthesizes into a voice, when that workspace is on the engine new Canadian workspaces start on. For European workspaces additionally: live call audio for in-browser calls, and for telephone calls we place outbound, processed in Frankfurt and not stored there

Region

Canada (ca-central-1, Montreal), Germany (eu-central-1, Frankfurt), and Singapore (ap-southeast-1). Each of those regions runs its website origin and its own workspace database on a single machine inside the region, and the storage volumes are encrypted with keys managed by Amazon Web Services. Speech-to-text and text-to-speech for a Canadian workspace on the engine new Canadian workspaces start on run in Montreal (ca-central-1) as well, since September 2026.

Canadian in-browser call media is processed on that same machine in Montreal, and European in-browser call media on the machine in Frankfurt. A European workspace's outbound telephone call runs on the Frankfurt machine too, up to the point our carrier takes it. Since August 2026 a call that arrives on our first European number, in Estonia, runs there as well, and Twilio delivers it to that machine from Ireland.

A Canadian workspace's telephone calls are handled here too since September 2026, in both directions, up to the point our carrier takes them or from the point it hands one to us, and this row said the opposite until then. The exception is the number's carrier rather than its country. A call arriving on a number issued through Twilio, Canadian or a United States one, reaches us in the United States and is hosted on our United States media node, because Twilio publishes no Canadian point of presence

Cloudflare, Inc.

  • Global / EU
  • web traffic
  • backups

Protects and speeds up our websites, and holds our encrypted backups.

Purpose
CDN, DNS, edge routing, bot and abuse protection (Turnstile), encrypted off-site database backups (R2), and admin-only media generation (Workers AI)
Data category
Web traffic metadata and IP addresses; encrypted database backups; legacy archived call-recording audio (aging out, new recordings are stored in regional Google Cloud Storage)
Region

Global edge network, and that phrase is doing real work rather than standing in for a region. The encrypted connection from a visitor's browser is terminated at whichever Cloudflare location is nearest them, and the small piece of our own code that decides which of our origins answers runs at that same location. For a visitor in Canada that is normally a Cloudflare location in Canada, but it is not guaranteed to be, and which one it is is not something we control.

Cloudflare sells an add-on that would confine that processing to a chosen country, and we do not subscribe to it for Canada. So a Canadian workspace's web traffic metadata may be seen at an edge location outside Canada before it reaches our Montreal origin.

Encrypted database backups are not all held in the same place. European backups are written to an R2 bucket created in Cloudflare's European jurisdiction, so those objects stay in the EU. The United States, Canadian and Asia-Pacific backups are written to a bucket in R2's default jurisdiction, each region under its own key prefix. A key prefix is a filing convention, not a jurisdiction, and we would rather say that than let the layout imply otherwise. Every dump is encrypted inside its own region before it is uploaded, and the decryption key is held in a managed secret store separate from Cloudflare

Redis Ltd. (Redis Cloud)

  • US / EU / CA
  • call signaling
  • operational keys

Coordinates live calls across our servers and holds the short-lived operational state that keeps the service running.

Purpose
Managed Redis, in six separate databases. One is fleet-wide shared state for the website and dashboard and is touched on every request from every region, including Europe and Canada: rate limits, short-lived caches, webhook idempotency claims, and the lock that decides which of our four origins runs each scheduled job. Two hold only the rate-limit counters for requests that reach a particular origin, one in Frankfurt for our European origin and one in Montreal for our Canadian origin, added in September 2026. The remaining three are the real-time media signaling buses for our United States media node, our European one and our Canadian one
Data category
Rate-limit counters, short-lived cached values, webhook idempotency claims and scheduling locks, keyed to identifiers such as an account, a workspace, a call or an IP address. Where a key name would otherwise contain an email address, a phone number or an IP address, it carries a one-way keyed hash of that value instead. On the three signaling buses: live-call room and participant state, and, on all three, telephone trunk configuration, the Canadian bus carrying it since September 2026, when telephone equipment started running on that node. No call audio is held on any of them
Region

United States (us-east4), the European Union (Frankfurt, eu-central-1) and Canada (Montreal, ca-central-1). The fleet-wide shared state runs in the United States, so every request in every region, Europe and Canada included, touches a United States database for caching, idempotency claims and scheduling locks. The separate European database in Frankfurt holds rate-limit counters for the European origin only, and since September 2026 a separate Canadian database in Montreal holds them for the Canadian origin. Requests to our Asia-Pacific origin have no counter database of their own and use the fleet-wide United States one.

The signaling bus for our United States media node runs in the United States. The one for our European media node runs in Frankfurt, alongside that node, and the one for our Canadian media node runs in Montreal, alongside that node

Turns speech into text — and back

Deepgram

  • US / EU
  • call audio
  • transcripts

Turns caller speech into text, and our replies into a voice — the engine a new workspace starts on everywhere except Canada. European workspaces use its European endpoint.

Purpose
Speech-to-text transcription and text-to-speech (the starting engine outside Canada)
Data category
Call audio and transcripts
Region
United States by default (api.deepgram.com). For a European workspace, both speech-to-text and speech synthesis run on Deepgram's European endpoint (api.eu.deepgram.com), which Deepgram commits to keeping inside the EU without naming a country. A Canadian workspace reaches Deepgram only if it has chosen an engine that uses it, and is then processed in the United States, because Deepgram publishes no Canadian endpoint; since September 2026 a new Canadian workspace starts on Amazon Transcribe and Amazon Polly in Montreal instead. Asia-Pacific workspaces are processed in the United States, because Deepgram publishes no endpoint in Singapore, where our Asia-Pacific region runs

ElevenLabs

  • US
  • agent audio
  • optional

An optional voice for the assistant.

Purpose
Text-to-speech voice synthesis (optional voice engine)
Data category
Agent text and synthesized audio
Region
United States

Cartesia

  • US
  • agent audio
  • optional

An optional voice for the assistant, on Cartesia's Sonic model.

Purpose
Text-to-speech voice synthesis (optional voice engine)
Data category
Agent text and synthesized audio
Region

United States (api.cartesia.ai), for every workspace that chooses this engine.

Cartesia offers European, British, Indian and Australian endpoints only on its Enterprise tier, which we do not hold, and publishes no Canadian one. So a European or Canadian workspace that selects this engine has its speech synthesis in the United States, and the engine picker says so before the choice is made.

AssemblyAI

  • US / EU
  • call audio
  • transcripts
  • optional

An optional speech-to-text engine. European workspaces use its EU data zone.

Purpose
Speech-to-text transcription (optional voice engine)
Data category
Call audio and transcripts
Region
United States, on AssemblyAI's US data zone (streaming.us.assemblyai.com). For a European workspace, transcription runs on its EU data zone (streaming.eu.assemblyai.com), which AssemblyAI states keeps the data inside the EU. Canadian and Asia-Pacific workspaces are processed in the United States, because AssemblyAI offers no data zone in either region

Inworld

  • US
  • call audio
  • agent audio
  • experimental

An experimental voice engine, not yet generally available.

Purpose
Speech-to-text and text-to-speech (optional voice engine; experimental)
Data category
Call audio, agent text, and synthesized audio
Region
United States

Tavus

  • US
  • video
  • audio
  • optional
  • off by default

Optional video avatar for face-to-face calls — off unless you turn it on.

Purpose
Real-time video avatar rendering (optional; off by default, enabled per workspace)
Data category
Video and audio streams for avatar sessions
Region
United States

Payments & email

Stripe

  • US
  • billing info

Processes your payments. Never sees call data.

Purpose
Payment processing, billing, tax calculation, and metered usage
Data category
Name, email, billing address, payment method, and tax identifiers
Region
United States

Postmark

  • US
  • email

Delivers our emails to you.

Purpose
Transactional and newsletter email delivery
Data category
Email address, name, and message content
Region
United States

When you contact support

Atlassian (Atlassian Pty Ltd)

  • CA (all regions)
  • support requests
  • email

Runs our support desk, so it holds the support requests you send us and our replies. One site in Canada serves all four regions.

Purpose
Support ticketing and the agent workbench behind it (Jira Service Management): receiving, tracking, and replying to support requests; and, only where a workspace chooses the linked knowledge base, composing answers to questions asked of the assistant
Data category
Your name, your email address, the subject, and the full text of the support request you send us, together with the replies in that conversation. Where a workspace chooses the linked knowledge base, the text of each question asked is sent as well. We do not send your IP address, your browser details, or your workspace identifier
Region

Canada. Atlassian hosts each of its cloud products in a chosen realm, and ours is pinned to Canada, which our organisation administrator confirmed in the Atlassian admin console in August 2026. One Atlassian cloud site receives support requests from all four regions, so a support request still does not stay in your workspace's region. For a Canadian workspace the desk is in your region, and for a European, United States or Asia-Pacific workspace your name, email address and the text of your request are held in Canada instead of in your own region.

Atlassian publishes this setting only in its administration console. Its administration API has no endpoint that reports it: re-checked in August 2026, the organisation endpoints answer normally while every residency path returns not-found, so the console is the only place the value can be read

Website analytics

Stape

  • Canada
  • web analytics
  • consent-gated

First-party gateway for our website analytics, hosted in Canada.

Purpose
First-party server-side Google Tag Manager container (sst.distronode.com) that forwards consented analytics events to Google Analytics
Data category
Web analytics events and IP addresses
Region
Canada (Toronto)

Google Analytics & Google Ads (Google LLC)

  • US
  • web analytics
  • conversions
  • consent-gated

Measures sign-ups and purchases — only with your consent.

Purpose
Server-side conversion and analytics measurement (GA4 Measurement Protocol and Google Ads Data Manager) for consented sign-ups and purchases
Data category
Consented web and conversion events, including hashed billing email addresses and purchase amounts
Region
United States

LinkedIn (LinkedIn Corporation)

  • US
  • web analytics
  • conversions
  • consent-gated

Measures which of our LinkedIn ads led to a sign-up — only with your consent.

Purpose
Advertising measurement for our own LinkedIn campaigns: the LinkedIn Insight Tag records consented website events, and the LinkedIn Conversions API receives consented conversion events sent from our servers
Data category
Consented web and conversion events, including SHA-256 hashed email addresses and LinkedIn's first-party advertising cookie identifier. We do not send plaintext email addresses, IP addresses or mobile advertising identifiers
Region
United States

Mixpanel (Mixpanel, Inc.)

  • EU
  • product usage
  • email
  • consent-gated

Shows us how the signed-in dashboard is actually used, held in the EU. Never your calls, messages or contacts.

Purpose
Product analytics for the signed-in District dashboard, by two paths. First, a consent-gated analytics SDK that runs in your browser inside the dashboard only, and which stores its identifiers in browser storage (localStorage) rather than in cookies. Second, cookieless lifecycle events sent from our own servers when an account is created, a workspace is created, a subscription is purchased, a workflow run completes, or a call is handled. Not used on marketing pages and not used for advertising
Data category
Product usage events keyed to a one-way SHA-256 hashed account identifier, the account email address on the user profile, and the workspace identifier, region, and plan tier. We do not send call audio, transcripts, message content, contact records, phone numbers, or IP addresses, and IP geolocation is switched off, so no location is derived from your connection
Region
European Union (Mixpanel EU data residency, api-eu.mixpanel.com)

Keeps the service reliable

Sentry

  • EU
  • diagnostics

Tells us when something breaks, held in the EU.

Purpose
Error tracking and application monitoring
Data category
Diagnostic data, which may include IP addresses and user identifiers
Region
Germany, for all four of our regions rather than one provider region for each of ours. A Canadian workspace's error diagnostics are therefore held in Germany rather than in Canada, because Sentry operates no Canadian region

New Relic

  • EU
  • telemetry
  • logs

Watches uptime and performance, held in the EU.

Purpose
Infrastructure metrics, logs, and alerting
Data category
Operational telemetry and scoped application logs
Region
European Union (New Relic EU region), for all four of our regions rather than one provider region for each of ours. A Canadian workspace's infrastructure telemetry and logs are therefore held in the European Union rather than in Canada, because New Relic operates no Canadian region

Optional: business-contact enrichment

People Data Labs

  • US
  • business contact info
  • off by default

Looks up business details for your contacts — only if you turn enrichment on.

Purpose
B2B company and person enrichment (primary source)
Data category
Business domains and firmographic data, and professional contact details (name, role, business email); phone numbers are used as lookup keys
Region
United States

Apollo.io

  • US
  • business contact info
  • off by default

Backup source for business-contact lookups — only if enrichment is on.

Purpose
B2B company and person enrichment (fallback source)
Data category
Business domains and firmographic data, and professional contact details (name, role, business email)
Region
United States

SerpAPI

  • US
  • search queries
  • off by default

Web search used during enrichment — only if it's on.

Purpose
Web search used to locate public business information during enrichment
Data category
Business names, contact names, and in some cases phone numbers submitted as web-search queries
Region
United States

Our own marketing

Bluesky (Bluesky Social, PBC)

  • N/A
  • our marketing content
  • admin-only
  • no customer data

Receives our own Bluesky posts directly. No customer data.

Purpose
Publishing to Distronode's own Bluesky account directly, rather than through a publishing tool
Data category
Distronode's own marketing content only; no customer personal data
Region
Not applicable (Distronode content only)

Zernio

  • N/A
  • our marketing content
  • admin-only
  • no customer data

The publishing tool that posts our own X and Reddit updates for us. No customer data.

Purpose
Relaying Distronode's own marketing posts to Distronode's own X and Reddit accounts, where we publish through a tool rather than through the platform's own interface
Data category
Distronode's own marketing content only, together with the credentials for Distronode's own social accounts; no customer personal data
Region
Not applicable (Distronode content only)

Clarifications

LiveKit is self-hosted, not a sub-processor. Our real-time voice platform runs LiveKit's open-source software on our own media nodes: Google Cloud in the United States (us-east4) and Amazon Web Services in Frankfurt (eu-central-1) and Montreal (ca-central-1). LiveKit, Inc. does not receive or process your data as a third party.

Email runs entirely through Postmark. An earlier email provider (Resend) has been retired and no longer processes customer data.

Retired providers. The legacy enrichment provider Clearbit has been removed and no longer processes any data; People Data Labs and Apollo are the active sources. Two hosting providers have also come off this register: Akamai / Linode, which hosted the Asia-Pacific region until August 13 2026, and Civo, which hosted the European region until August 14 2026. The machines they ran for us were destroyed on those dates and neither company holds anything of ours. Amazon Web Services runs those regions now, in the same cities.

Services you connect are not sub-processors. When you link Google or Microsoft sign-in, calendars, or contact imports, or configure a custom API connector, those providers process data at your direction under your agreements with them, not as our sub-processors.

Questions about a specific sub-processor, or how one fits your own vendor review? Contact us at legal@distronode.com. See also the data residency map and our Data Processing Agreement.