1. About this list
The list is updated at least quarterly. Before we onboard a new subprocessor that will process Personal Data, we complete a diligence review: security posture, DPA availability, data-residency, subcontractor chain, and incident history.
2. Subprocessor table
| Vendor | Purpose | Data processed | Location | DPA / Safeguards |
|---|---|---|---|---|
| Railway | Application hosting, PostgreSQL database, background workers. | All application data (encrypted at rest). | United States | Standard DPA available |
| Stripe | Payment processing, subscriptions, refunds, payouts. | Name, email, phone, address, tokenized card (Stripe PCI DSS Level 1). | United States / global payment rails | DPA + SCCs incorporated via Stripe Services Agreement |
| OpenPhone | Business phone — SMS send/receive, inbound/outbound calls, call recording. | Phone numbers, message content, call audio and transcripts. | United States | DPA available |
| Twilio SendGrid | Transactional and marketing email delivery, bounce handling. | Email addresses, email subject + body. | United States | DPA available |
| Google Workspace | Internal email, calendar, Drive storage, Docs. | Customer communications, attachments, calendar events. | United States | G-Suite Cloud DPA incorporated |
| Groq | AI inference (primary) — call summarization, draft replies, dispatcher suggestions. | Call transcript text, customer messages (anonymized where feasible). | United States | DPA available; no training on customer data |
| OpenAI | AI inference (fallback when Groq is unavailable). | Call transcript text, customer messages. | United States | Business DPA; no training on API data (per OpenAI API terms) |
| Cloudflare | DNS, TLS termination, CDN, DDoS protection, WAF. | Traffic metadata, IP, request headers. | Global edge network | DPA + SCCs available |
| GitHub | Source-code hosting, CI/CD, security scanning. | Code — not customer data. | United States | N/A (not a personal-data processor) |
| Nominatim (OpenStreetMap) | Free geocoding lookup of service addresses. | Address text only (no customer name linked). | Germany (Europe) | Public service; no DPA; anonymized queries only |
3. DPA availability
If you are a B2B customer and require a signed Data Processing Addendum incorporating EU Standard Contractual Clauses and, where applicable, the UK IDTA, email legal@gogreenorganicclean.com with your entity legal name, jurisdiction, and signing authority. Our standard DPA is ready to countersign within 5 business days.
4. Change notifications
For customers who have signed a DPA, we commit to provide at least 14 days' prior notice by email before adding or replacing a subprocessor that would process your Personal Data. You may object on reasonable grounds; if we cannot accommodate the objection, you may terminate the affected service.
5. Audits & due diligence
For each subprocessor we review, on at least an annual basis, its SOC 2 Type II report, ISO/IEC 27001 certification, PCI DSS AOC (for Stripe), or equivalent. Diligence summaries are available to enterprise customers under NDA.
