ManySignal publishes its full sub-processor list here in accordance with Article 28(3) of the GDPR and the equivalent requirements of the UK GDPR and Swiss revFADP. We believe transparency about who touches your data is a baseline expectation, not a negotiating point.
About this list
ManySignal relies on third-party service providers ("sub-processors") to deliver and operate the Service. Each sub-processor is bound by a data-processing agreement imposing obligations at least as protective as those in the ManySignal Data Processing Addendum. ManySignal remains fully liable for the acts and omissions of its sub-processors with respect to Customer Personal Data.
This page reflects the current approved sub-processor list as of the date shown above. When Customer Personal Data is stored in a specific region because of a Customer's deployment selection, the regional column below reflects the region(s) that apply.
Current sub-processors
| Provider | Purpose | Data category | Processing region(s) |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud infrastructure, compute, object storage (S3), relational database (RDS), message queuing (SQS/SNS), secret management (Secrets Manager) | Customer telemetry, account data, audit logs | us-east-1, eu-west-1, ap-southeast-2 (per Customer deployment selection) |
| Google Cloud Platform (GCP) | Large-scale data warehouse and analytics pipeline (BigQuery), vector search (Vertex AI Matching Engine), ML model inference hosting | Aggregated and pseudonymised telemetry features | us-central1, europe-west4 |
| Datadog | Infrastructure and application performance monitoring, distributed tracing, log aggregation, uptime alerting | System metrics, application logs (no Customer telemetry content) | US, EU |
| Sentry | Application error tracking and crash reporting for platform services | Error stack traces, session context (no Customer telemetry) | US |
| GitHub (Microsoft) | Source code management, CI/CD pipeline orchestration, security advisory scanning | Source code only; no Customer Personal Data | US |
| LaunchDarkly | Feature flag management and progressive delivery for safe rollout of platform capabilities | User identifiers and tenant IDs (for flag targeting) | US, EU |
| Stripe | Payment card processing and subscription billing management | Billing contact and payment method data | US, EU |
| HubSpot | CRM, marketing automation, and customer support ticketing for website leads and trial users | Business contact data, email engagement | US |
| PostHog | Product analytics and session recording for the marketing website and application UI | Pseudonymised visitor and user behaviour data | EU (self-hosted on GCP europe-west4) |
| Anthropic | LLM inference for triage summarisation, investigation narrative generation, and report drafting within the Service | Structured security context; governed by zero-data-retention API agreement | US |
| PagerDuty | On-call scheduling and incident alerting for ManySignal engineering and SOC response teams | Engineer contact data; no Customer telemetry | US |
Notice-of-change policy
ManySignal will provide Customers with at least 30 days' written notice before adding a new sub-processor or making a material change to an existing sub-processor's processing activities. Notice is delivered via: (a) an update to this page with a revised "Last updated" date; (b) an email notification to the technical contact on file for each Customer tenant; and (c) an in-app notification in the ManySignal customer portal.
Customers who have opted in to sub-processor change alerts via the customer portal will receive email notifications within 24 hours of any change to this list. To register for notifications, navigate to Settings > Security & Privacy > Sub-processor Alerts in the ManySignal dashboard.
Objecting to a new sub-processor
Customers may object to the addition of a new sub-processor on reasonable, documented grounds related to data protection by notifying privacy@manysignal.com within 14 days of receiving notice of the change. ManySignal will engage with the Customer in good faith to resolve the objection. If the parties cannot reach agreement within 30 days, Customer may terminate the affected Service without penalty by providing written notice before the new sub-processor's effective date.
Data transfer mechanisms
Where sub-processors located outside the EEA, UK, or Switzerland receive Customer Personal Data, ManySignal ensures that an appropriate transfer mechanism is in place, including Standard Contractual Clauses (EU Commission Decision 2021/914, Module Two or Three as applicable), the UK Addendum, or an equivalent recognised transfer mechanism.
Transfer Impact Assessments have been conducted for all cross-border sub-processor transfers. Summaries are available from your account team upon written request under a non-disclosure agreement.
Questions and corrections
If you believe this list is inaccurate or incomplete, or if you have questions about how a specific sub-processor handles Customer Personal Data, contact privacy@manysignal.com. We update this list promptly following any change and maintain a version history in our internal change-management system.
Questions about this document?
Contact our legal team at privacy@manysignal.com. For security disclosure, use security@manysignal.com.