Sub-processors · checked
Your sub-processor list, drafted from your code
A sub-processor list names every vendor that processes your customers' personal data for you, and GDPR Art. 28(2) says you must tell those customers before you add or replace one, so they can object. Most of the list is already written down in your code: each SDK, API host and env variable names a vendor. 69 of them are in the table below, with their DPAs (50 found). Find the ones your code depends on now, with nothing to install:
$ grep -rnE --include=package.json --exclude-dir=node_modules '"(@ai-sdk/amazon-bedrock|@ai-sdk/anthropic|@ai-sdk/azure|@ai-sdk/cohere|@ai-sdk/gateway|@ai-sdk/google|@ai-sdk/google-vertex|@ai-sdk/groq|@ai-sdk/mistral|@ai-sdk/openai|@ai-sdk/togetherai|@ai-sdk/xai|@algolia/[^"]*|@amplitude/[^"]*|@anthropic-ai/bedrock-sdk|@anthropic-ai/claude-agent-sdk|@anthropic-ai/sdk|@anthropic-ai/vertex-sdk|@auth0/[^"]*|@aws-sdk/[^"]*|@aws-sdk/client-bedrock-runtime|@aws-sdk/client-dynamodb|@aws-sdk/client-s3|@aws-sdk/client-ses|@aws-sdk/client-sesv2|@aws-sdk/client-sqs|@aws-sdk/lib-dynamodb|@aws-sdk/lib-storage|@axiomhq/[^"]*|@azure/[^"]*|@azure/openai|@azure/storage-blob|@clerk/[^"]*|@cloudflare/next-on-pages|@cloudinary/[^"]*|@datadog/[^"]*|@deepgram/sdk|@discordjs/[^"]*|@elevenlabs/[^"]*|@google-cloud/[^"]*|@google-cloud/bigquery|@google-cloud/storage|@google-cloud/vertexai|@google/genai|@google/generative-ai|@helicone/[^"]*|@huggingface/inference|@intercom/[^"]*|@langfuse/[^"]*|@lemonsqueezy/[^"]*|@libsql/client|@liveblocks/[^"]*|@logtail/[^"]*|@mistralai/mistralai|@mux/[^"]*|@neondatabase/[^"]*|@netlify/[^"]*|@openai/agents|@opennextjs/cloudflare|@openrouter/ai-sdk-provider|@openrouter/sdk|@paddle/[^"]*|@pinecone-database/[^"]*|@planetscale/database|@plausible-analytics/tracker|@posthog/[^"]*|@prisma/adapter-neon|@segment/[^"]*|@sendgrid/[^"]*|@sentry/[^"]*|@slack/[^"]*|@stripe/[^"]*|@supabase/[^"]*|@trigger\.dev/[^"]*|@tursodatabase/[^"]*|@uploadthing/[^"]*|@upstash/[^"]*|@vercel/analytics|@vercel/blob|@vercel/edge-config|@vercel/functions|@vercel/kv|@vercel/og|@vercel/postgres|@vercel/speed-insights|@workos-inc/[^"]*|ably|algoliasearch|analytics-node|apify|apify-cli|apify-client|auth0|aws-cdk-lib|aws-sdk|cloudflare|cloudinary|cohere-ai|crisp-api|crisp-sdk-web|dd-trace|discord\.js|elevenlabs|firebase|firebase-admin|firebase-tools|ga-4-react|groq-sdk|inngest|intercom-client|langfuse|langfuse-langchain|langfuse-vercel|loops|mailgun-js|mailgun\.js|mixpanel|mixpanel-browser|mongodb|mongoose|netlify-cli|next-axiom|next-cloudinary|next-plausible|openai|plausible-tracker|posthog-js|posthog-node|postmark|pusher|pusher-js|raven-js|react-ga4|react-instantsearch|react-use-intercom|replicate|resend|stripe|supabase|together-ai|twilio|uploadthing|vercel|wrangler)"[[:space:]]*:' .
Run it from the repository root; it needs nothing installed and sends nothing anywhere. It finds every dependency, in every package.json, that names one of the 69 vendors in the table below. It cannot see a vendor your code calls without an SDK (an API host in a string, a webhook URL), or one named only by an env variable; check those by hand.
Not legal advice. Whether a vendor is your sub-processor depends on the personal data you send it and on your contracts; a list drafted from code is a draft for you to confirm, row by row. It also misses vendors outside the code (your workspace, support desk, CRM, payroll): add those by hand.
What each row needs
The vendor's name, what it does for you, the categories of personal data it receives, where it processes them, and its DPA. The template explains each column; the example is a list drafted from a small app's code.
When the code adds a vendor
Adding a vendor to production is a dated event: under a general written authorisation your customers get a notice before it processes their data, and usually 30 days to object, sometimes 14. So the moment to catch it is the pull request. How to notify customers covers the notice itself.
Before a branch merges, read the dependencies it adds. A line that names a vendor in the catalog is a new sub-processor to announce:
$ git diff origin/main -- '*package.json' | grep '^+ '
Vendors a codebase shows, with their DPAs
What each vendor is usually engaged for, its data processing agreement and its own list of sub-processors (the next link in the chain, which EDPB Opinion 22/2024 expects you to be able to trace). Links checked 9 October 2026.
| Vendor | Usually engaged for | DPA | Its own list |
|---|---|---|---|
| Hosting | |||
| Vercel | Hosting and serverless functions | DPA | list |
| Cloudflare | Workers hosting and edge network | DPA | list |
| Netlify | Hosting and serverless functions | DPA | list |
| Fly.io | Application hosting | not found | list |
| Render | Application hosting | DPA | not found |
| Railway | Application hosting | DPA | list |
| Cloud infrastructure | |||
| DigitalOcean | Cloud infrastructure | DPA | list |
| Amazon Web Services | Cloud infrastructure | DPA | list |
| Google Cloud | Cloud infrastructure | DPA | list |
| Microsoft Azure | Cloud infrastructure | DPA | not found |
| Database | |||
| Neon | Serverless Postgres database | DPA | list |
| Supabase | Postgres database, auth and storage | DPA | list |
| PlanetScale | MySQL and Postgres database | DPA | list |
| Turso | SQLite database | not found | not found |
| MongoDB Atlas | Document database | DPA | not found |
| Firebase (Google) | Database, auth and hosting | DPA | list |
| Cache and queues | |||
| Upstash | Redis, rate limiting and message queues | DPA | list |
| File storage | |||
| Cloudinary | Image and video hosting | not found | not found |
| UploadThing | File uploads | not found | not found |
| Mux | Video hosting and streaming | DPA | not found |
| Payments | |||
| Stripe | Payments and billing | DPA | list |
| Paddle | Payments as merchant of record | DPA | not found |
| Lemon Squeezy | Payments as merchant of record | DPA | not found |
| Email delivery | |||
| Resend | Transactional email | DPA | list |
| Twilio SendGrid | Transactional and marketing email | DPA | list |
| Postmark | Transactional email | DPA | not found |
| Mailgun | Transactional email | not found | not found |
| Loops | Product and transactional email | DPA | not found |
| SMS and voice | |||
| Twilio | SMS, voice and verification | DPA | list |
| LLM inference | |||
| Anthropic | LLM inference (Claude) | DPA | list |
| OpenAI | LLM inference | DPA | list |
| Google Gemini API | LLM inference (Gemini) | not found | not found |
| Mistral AI | LLM inference | DPA | list |
| Groq | LLM inference | DPA | not found |
| Cohere | LLM inference and embeddings | not found | not found |
| xAI | LLM inference (Grok) | not found | not found |
| OpenRouter | LLM routing to many model providers | not found | not found |
| Together AI | LLM inference | not found | not found |
| Replicate | Model inference | not found | not found |
| Hugging Face | Model inference | not found | not found |
| AI speech and media | |||
| ElevenLabs | Speech synthesis | DPA | not found |
| Deepgram | Speech to text | not found | not found |
| Vector database | |||
| Pinecone | Vector database | DPA | list |
| Error monitoring | |||
| Sentry | Error and performance monitoring | DPA | list |
| Logs and observability | |||
| Datadog | Monitoring, logs and APM | DPA | list |
| Better Stack | Logs and uptime monitoring | DPA | not found |
| Axiom | Logs and traces | not found | not found |
| Langfuse | LLM tracing and evaluation | DPA | list |
| Helicone | LLM request logging | not found | not found |
| Product analytics | |||
| PostHog | Product analytics and session replay | DPA | list |
| Mixpanel | Product analytics | DPA | list |
| Amplitude | Product analytics | DPA | not found |
| Twilio Segment | Customer data pipeline | DPA | list |
| Google Analytics | Web analytics | DPA | not found |
| Plausible Analytics | Web analytics without cookies | DPA | not found |
| Authentication | |||
| Clerk | User authentication | DPA | list |
| Auth0 (Okta) | User authentication | not found | not found |
| WorkOS | Enterprise SSO and user management | DPA | list |
| Customer support | |||
| Intercom | Customer messaging and support | DPA | list |
| Crisp | Customer chat | not found | not found |
| Team messaging | |||
| Slack | Alerts and notifications to Slack | DPA | not found |
| Discord | Alerts and notifications to Discord | not found | not found |
| Search | |||
| Algolia | Hosted search | DPA | not found |
| Background jobs | |||
| Trigger.dev | Background jobs | DPA | list |
| Inngest | Background jobs and workflows | not found | not found |
| Realtime | |||
| Pusher | Realtime messaging | not found | not found |
| Ably | Realtime messaging | DPA | not found |
| Liveblocks | Realtime collaboration | DPA | not found |
| Automation platform | |||
| Apify | Hosted scrapers and automation (Actors) | DPA | not found |
| Code hosting and CI | |||
| GitHubusually not a sub-processor | Code hosting and CI | DPA | list |
70 vendors; 50 DPAs and 32 sub-processor lists found. Every link was fetched on 9 October 2026 and answered or led to the vendor's trust center; "not found" means none was, not that none exists. As JSON.
A hosted, dated sub-processor page that emails your customers each change is not built.
It would publish the list you approved at a public URL, keep every change with its date, email your subscribers the notice with the day their objection window closes, and record who was told when. agentcheck runs scheduled checks of endpoints today; this is not one of them. If you would pay for it, say so with one click. The click is counted; nothing else is sent or stored.
Counted. Thank you; nothing else was sent.Sources
- GDPR Art. 28: processor (read 9 October 2026)
- EDPB Opinion 22/2024 on sub-processing chains (Hogan Lovells summary) (read 9 October 2026)
- GitHub subprocessors: notice at least 30 days in advance (read 9 October 2026)
- Stripe's DPA: 30 days to object, then deemed accepted (ConductAtlas) (read 9 October 2026)
subprocessors is a free tool from agentcheck, which runs scheduled checks of your endpoints and alerts you when an answer changes. Vendor links come from each vendor's own pages, read on the day shown.