Sub-processors · checked

Your sub-processor list, drafted from your code

A sub-processor list names every vendor that processes your customers' personal data for you, and GDPR Art. 28(2) says you must tell those customers before you add or replace one, so they can object. Most of the list is already written down in your code: each SDK, API host and env variable names a vendor. 69 of them are in the table below, with their DPAs (50 found). Find the ones your code depends on now, with nothing to install:

$ grep -rnE --include=package.json --exclude-dir=node_modules '"(@ai-sdk/amazon-bedrock|@ai-sdk/anthropic|@ai-sdk/azure|@ai-sdk/cohere|@ai-sdk/gateway|@ai-sdk/google|@ai-sdk/google-vertex|@ai-sdk/groq|@ai-sdk/mistral|@ai-sdk/openai|@ai-sdk/togetherai|@ai-sdk/xai|@algolia/[^"]*|@amplitude/[^"]*|@anthropic-ai/bedrock-sdk|@anthropic-ai/claude-agent-sdk|@anthropic-ai/sdk|@anthropic-ai/vertex-sdk|@auth0/[^"]*|@aws-sdk/[^"]*|@aws-sdk/client-bedrock-runtime|@aws-sdk/client-dynamodb|@aws-sdk/client-s3|@aws-sdk/client-ses|@aws-sdk/client-sesv2|@aws-sdk/client-sqs|@aws-sdk/lib-dynamodb|@aws-sdk/lib-storage|@axiomhq/[^"]*|@azure/[^"]*|@azure/openai|@azure/storage-blob|@clerk/[^"]*|@cloudflare/next-on-pages|@cloudinary/[^"]*|@datadog/[^"]*|@deepgram/sdk|@discordjs/[^"]*|@elevenlabs/[^"]*|@google-cloud/[^"]*|@google-cloud/bigquery|@google-cloud/storage|@google-cloud/vertexai|@google/genai|@google/generative-ai|@helicone/[^"]*|@huggingface/inference|@intercom/[^"]*|@langfuse/[^"]*|@lemonsqueezy/[^"]*|@libsql/client|@liveblocks/[^"]*|@logtail/[^"]*|@mistralai/mistralai|@mux/[^"]*|@neondatabase/[^"]*|@netlify/[^"]*|@openai/agents|@opennextjs/cloudflare|@openrouter/ai-sdk-provider|@openrouter/sdk|@paddle/[^"]*|@pinecone-database/[^"]*|@planetscale/database|@plausible-analytics/tracker|@posthog/[^"]*|@prisma/adapter-neon|@segment/[^"]*|@sendgrid/[^"]*|@sentry/[^"]*|@slack/[^"]*|@stripe/[^"]*|@supabase/[^"]*|@trigger\.dev/[^"]*|@tursodatabase/[^"]*|@uploadthing/[^"]*|@upstash/[^"]*|@vercel/analytics|@vercel/blob|@vercel/edge-config|@vercel/functions|@vercel/kv|@vercel/og|@vercel/postgres|@vercel/speed-insights|@workos-inc/[^"]*|ably|algoliasearch|analytics-node|apify|apify-cli|apify-client|auth0|aws-cdk-lib|aws-sdk|cloudflare|cloudinary|cohere-ai|crisp-api|crisp-sdk-web|dd-trace|discord\.js|elevenlabs|firebase|firebase-admin|firebase-tools|ga-4-react|groq-sdk|inngest|intercom-client|langfuse|langfuse-langchain|langfuse-vercel|loops|mailgun-js|mailgun\.js|mixpanel|mixpanel-browser|mongodb|mongoose|netlify-cli|next-axiom|next-cloudinary|next-plausible|openai|plausible-tracker|posthog-js|posthog-node|postmark|pusher|pusher-js|raven-js|react-ga4|react-instantsearch|react-use-intercom|replicate|resend|stripe|supabase|together-ai|twilio|uploadthing|vercel|wrangler)"[[:space:]]*:' .

Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds every dependency, in every package.json, that names one of the 69 vendors in the table below. It cannot see a vendor your code calls without an SDK (an API host in a string, a webhook URL), or one named only by an env variable; check those by hand.

Not legal advice. Whether a vendor is your sub-processor depends on the personal data you send it and on your contracts; a list drafted from code is a draft for you to confirm, row by row. It also misses vendors outside the code (your workspace, support desk, CRM, payroll): add those by hand.

What each row needs

The vendor's name, what it does for you, the categories of personal data it receives, where it processes them, and its DPA. The template explains each column; the example is a list drafted from a small app's code.

When the code adds a vendor

Adding a vendor to production is a dated event: under a general written authorisation your customers get a notice before it processes their data, and usually 30 days to object, sometimes 14. So the moment to catch it is the pull request. How to notify customers covers the notice itself.

Before a branch merges, read the dependencies it adds. A line that names a vendor in the catalog is a new sub-processor to announce:

$ git diff origin/main -- '*package.json' | grep '^+ '

Vendors a codebase shows, with their DPAs

What each vendor is usually engaged for, its data processing agreement and its own list of sub-processors (the next link in the chain, which EDPB Opinion 22/2024 expects you to be able to trace). Links checked 9 October 2026.

VendorUsually engaged forDPAIts own list
Hosting
VercelHosting and serverless functionsDPAlist
CloudflareWorkers hosting and edge networkDPAlist
NetlifyHosting and serverless functionsDPAlist
Fly.ioApplication hostingnot foundlist
RenderApplication hostingDPAnot found
RailwayApplication hostingDPAlist
Cloud infrastructure
DigitalOceanCloud infrastructureDPAlist
Amazon Web ServicesCloud infrastructureDPAlist
Google CloudCloud infrastructureDPAlist
Microsoft AzureCloud infrastructureDPAnot found
Database
NeonServerless Postgres databaseDPAlist
SupabasePostgres database, auth and storageDPAlist
PlanetScaleMySQL and Postgres databaseDPAlist
TursoSQLite databasenot foundnot found
MongoDB AtlasDocument databaseDPAnot found
Firebase (Google)Database, auth and hostingDPAlist
Cache and queues
UpstashRedis, rate limiting and message queuesDPAlist
File storage
CloudinaryImage and video hostingnot foundnot found
UploadThingFile uploadsnot foundnot found
MuxVideo hosting and streamingDPAnot found
Payments
StripePayments and billingDPAlist
PaddlePayments as merchant of recordDPAnot found
Lemon SqueezyPayments as merchant of recordDPAnot found
Email delivery
ResendTransactional emailDPAlist
Twilio SendGridTransactional and marketing emailDPAlist
PostmarkTransactional emailDPAnot found
MailgunTransactional emailnot foundnot found
LoopsProduct and transactional emailDPAnot found
SMS and voice
TwilioSMS, voice and verificationDPAlist
LLM inference
AnthropicLLM inference (Claude)DPAlist
OpenAILLM inferenceDPAlist
Google Gemini APILLM inference (Gemini)not foundnot found
Mistral AILLM inferenceDPAlist
GroqLLM inferenceDPAnot found
CohereLLM inference and embeddingsnot foundnot found
xAILLM inference (Grok)not foundnot found
OpenRouterLLM routing to many model providersnot foundnot found
Together AILLM inferencenot foundnot found
ReplicateModel inferencenot foundnot found
Hugging FaceModel inferencenot foundnot found
AI speech and media
ElevenLabsSpeech synthesisDPAnot found
DeepgramSpeech to textnot foundnot found
Vector database
PineconeVector databaseDPAlist
Error monitoring
SentryError and performance monitoringDPAlist
Logs and observability
DatadogMonitoring, logs and APMDPAlist
Better StackLogs and uptime monitoringDPAnot found
AxiomLogs and tracesnot foundnot found
LangfuseLLM tracing and evaluationDPAlist
HeliconeLLM request loggingnot foundnot found
Product analytics
PostHogProduct analytics and session replayDPAlist
MixpanelProduct analyticsDPAlist
AmplitudeProduct analyticsDPAnot found
Twilio SegmentCustomer data pipelineDPAlist
Google AnalyticsWeb analyticsDPAnot found
Plausible AnalyticsWeb analytics without cookiesDPAnot found
Authentication
ClerkUser authenticationDPAlist
Auth0 (Okta)User authenticationnot foundnot found
WorkOSEnterprise SSO and user managementDPAlist
Customer support
IntercomCustomer messaging and supportDPAlist
CrispCustomer chatnot foundnot found
Team messaging
SlackAlerts and notifications to SlackDPAnot found
DiscordAlerts and notifications to Discordnot foundnot found
Search
AlgoliaHosted searchDPAnot found
Background jobs
Trigger.devBackground jobsDPAlist
InngestBackground jobs and workflowsnot foundnot found
Realtime
PusherRealtime messagingnot foundnot found
AblyRealtime messagingDPAnot found
LiveblocksRealtime collaborationDPAnot found
Automation platform
ApifyHosted scrapers and automation (Actors)DPAnot found
Code hosting and CI
GitHubusually not a sub-processorCode hosting and CIDPAlist

70 vendors; 50 DPAs and 32 sub-processor lists found. Every link was fetched on 9 October 2026 and answered or led to the vendor's trust center; "not found" means none was, not that none exists. As JSON.

A hosted, dated sub-processor page that emails your customers each change is not built.

It would publish the list you approved at a public URL, keep every change with its date, email your subscribers the notice with the day their objection window closes, and record who was told when. agentcheck runs scheduled checks of endpoints today; this is not one of them. If you would pay for it, say so with one click. The click is counted; nothing else is sent or stored.

Sources

subprocessors is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Vendor links come from each vendor's own pages, read on the day shown.