Zyphr acts as a processor for the personal data our customers send through the platform. This page lists the third parties that process that data on our behalf, what each one receives, and where the processing takes place. It is published under Article 28(3)(d) of the GDPR and is referenced by our Privacy Policy.
All customer data rests in the United States, in AWS region us-east-2 (Ohio). We do not offer EU data residency. Personal data originating in the EU, EEA or UK is transferred to the United States and handled under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses, with full Article 28 processor obligations.
Platform Subprocessors
These process personal data on our instructions, under our own vendor accounts, for every customer.
| Subprocessor | Purpose | Data categories | Location |
|---|---|---|---|
| Amazon Web Services Amazon Web Services, Inc. | Core infrastructure: compute, database, storage, queuing, caching, email and SMS delivery, CDN, DNS, secrets management and logging. | All data the platform holds — account and end-user identifiers, message content and recipients, delivery and engagement events, IP addresses and logs. | United States (us-east-2) |
| Amazon Bedrock Amazon Web Services, Inc. | AI assistance features (template drafting, subject-line suggestions). Served by AWS within our own account. | Customer-authored template content and subject lines; aggregate engagement statistics. Not used to train models. | United States |
| Slack Slack Technologies, LLC (Salesforce, Inc.) | Internal operational alerting to our own engineering channel. | Operational alerts only. End-user identifiers are masked before sending — email addresses and IP addresses are redacted rather than transmitted in full. | United States |
| GitHub GitHub, Inc. (Microsoft) | Source control and continuous integration. | Source code and deployment credentials. No customer or end-user personal data is stored in source control. | United States |
| Better Stack Better Stack, s.r.o. | Uptime monitoring for background workers. | Heartbeat pings only. No personal data is transmitted. | United States / EU |
Independent Controllers
| Company | Purpose | Data categories | Location |
|---|---|---|---|
| Google Google LLC — Google Ads | Measuring the effectiveness of our own advertising on our marketing site, documentation and dashboard. | Conversion events tied to a browser identifier, cookie and IP address. Loaded only after you accept non-essential cookies. | United States |
| PayPal PayPal (Europe) S.à r.l. et Cie, S.C.A. / PayPal, Inc. | Payment processing for subscriptions. | Billing contact details and transaction records. Card and bank details are entered directly with PayPal and never reach Zyphr. | United States / Luxembourg |
Customer-Configured Integrations
Some providers are connected by you, using your own credentials. Zyphr holds no account with any of them and no data flows to them unless you configure the integration. They are your subprocessors, not ours, and are not covered by the change-notice commitment below.
- SMS providers — Twilio, Vonage, MessageBird, Plivo, Telnyx, Sinch
- Push providers — Firebase Cloud Messaging, Apple Push Notification service, web push
- Social login identity providers — Google, Apple, Meta, GitHub, Microsoft
- Your own Slack, Discord or Microsoft Teams workspaces
- Automation platforms such as Zapier
Not Used
Stated explicitly because their absence is often assumed rather than checked:
- No error-tracking or APM vendor. We do not use Sentry, Datadog, New Relic or any equivalent. Application logs stay within AWS.
- No product-analytics or session-replay vendor. Removed in August 2026; we no longer send behavioural data to any analytics provider.
- No IP-intelligence vendor. Geolocation for fraud prevention is performed locally from a database on our own infrastructure — no IP address is sent to a third party.
- No third-party email delivery vendor. Email is sent through AWS. We do not use SendGrid, Mailgun or Postmark.
- No CAPTCHA vendor and no third-party font or CDN hosting.
Our password-breach check queries the Have I Been Pwned range API using k-anonymity: only the first five characters of a SHA-1 hash are sent, with padding enabled. No password, full hash, email address or account identifier leaves our infrastructure, so no personal data is disclosed and HIBP is not a subprocessor.
Changes to This List
We will give at least 30 days' advance notice before adding a new subprocessor or materially changing what an existing one processes.
Notice is given by email to the account owner and by a notice in the dashboard, so it does not depend on anyone watching this page. To receive notices at a different address, or to add a compliance contact, email privacy@zyphr.dev.
Right to object. If you object to a new subprocessor on reasonable data protection grounds, tell us within the notice period. We will work with you to find an alternative. If we cannot, you may terminate the affected service and receive a pro-rata refund of any prepaid fees for the remainder of the term.
Contact
Questions about this list, or requests for the underlying data processing agreements: privacy@zyphr.dev.