Sub-processors
Overview
Preferred Data engages 42 third-party vendors to deliver our services and to run our own business. This page is the authoritative list referenced by section 5.2 of our Data Processing Agreement.
Not every vendor applies to every customer. The list is grouped by function, and each group is labelled with the role we play in that processing. All vendors have been vetted against our security standards and applicable data protection regulations, including GDPR.
Sub-processors of customer data. Vendors we engage to process personal data on behalf of a customer, on that customer's instructions. These are sub-processors in the sense of Article 28 GDPR, and the 30-day notice and objection rights described below and in section 5.1 of the DPA apply to them.
Vendors we use as a controller. Services that support our own website, marketing, and sales, where Preferred Data decides the purpose of the processing and no customer instruction is involved. They are listed here for transparency, but they do not process managed customer environments. How they handle visitor and prospect data is governed by our Privacy Policy and Cookie Policy.
For details on the cookies our website sets, see our Cookie Policy. For how we handle personal data generally, see our Privacy Policy.
Important Notice
Compliance Certifications:The compliance certifications listed for each sub-processor are attestations published by that vendor, based on publicly available information at the time of our last review, and are subject to change. Preferred Data makes reasonable efforts to keep this information current but cannot guarantee the ongoing accuracy of third-party certifications. Each entry links to the vendor's own privacy or trust page so you can verify directly.
Due Diligence: While we perform due diligence on our sub-processors, customers requiring specific compliance certifications should independently verify current compliance status with their account representative.
Notification of Changes
We will notify customers at least 30 days before adding or removing any sub-processor of customer data. Customers may object to the addition of a new sub-processor by contacting us within 14 days of notification. This commitment mirrors section 5.1 of the DPA and applies to the groups marked Sub-processor of customer data below.
Sub-processors at a Glance
The table below summarises every sub-processor and the function it serves. Full detail, including data types processed, follows in the sections beneath it.
| Vendor | Category | Our role | Location |
|---|---|---|---|
| Microsoft (Azure and Microsoft 365) | Cloud Infrastructure and Hosting | Sub-processor of customer data | United States |
| Amazon Web Services (AWS) | Cloud Infrastructure and Hosting | Sub-processor of customer data | United States |
| Vercel | Cloud Infrastructure and Hosting | Sub-processor of customer data | United States |
| Supabase | Cloud Infrastructure and Hosting | Sub-processor of customer data | United States |
| Cloudflare | Cloud Infrastructure and Hosting | Sub-processor of customer data | United States |
| GitHub (Microsoft) | Cloud Infrastructure and Hosting | Sub-processor of customer data | United States |
| ConnectWise ScreenConnect | Managed IT Service Delivery | Sub-processor of customer data | United States |
| NinjaOne | Managed IT Service Delivery | Sub-processor of customer data | United States |
| HaloPSA | Managed IT Service Delivery | Sub-processor of customer data | United Kingdom |
| Malwarebytes ThreatDown | Managed IT Service Delivery | Sub-processor of customer data | United States |
| SentinelOne | Managed IT Service Delivery | Sub-processor of customer data | United States |
| N-able Cove Data Protection | Managed IT Service Delivery | Sub-processor of customer data | United States |
| Hornetsecurity (Altaro VM Backup) | Managed IT Service Delivery | Sub-processor of customer data | Germany |
| Veeam | Managed IT Service Delivery | Sub-processor of customer data | Switzerland |
| WatchGuard | Managed IT Service Delivery | Sub-processor of customer data | United States |
| AppRiver (OpenText) | Managed IT Service Delivery | Sub-processor of customer data | United States |
| Pax8 | Managed IT Service Delivery | Sub-processor of customer data | United States |
| Rewst | Managed IT Service Delivery | Sub-processor of customer data | United States |
| IT Glue | Managed IT Service Delivery | Sub-processor of customer data | Canada |
| 1Password | Managed IT Service Delivery | Sub-processor of customer data | Canada |
| Syncro | Managed IT Service Delivery | Sub-processor of customer data | United States |
| Intuit QuickBooks Online | Business Operations | Sub-processor of customer data | United States |
| Zoho Sign | Business Operations | Sub-processor of customer data | United States |
| PandaDoc | Business Operations | Sub-processor of customer data | United States |
| Intermedia | Business Operations | Sub-processor of customer data | United States |
| Stripe | Business Operations | Sub-processor of customer data | United States |
| Calendly | Business Operations | Sub-processor of customer data | United States |
| Google (Analytics, Ads, and Tag Manager) | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Microsoft Clarity | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| HubSpot | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| GoHighLevel | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Pipedream | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Resend | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Apollo.io | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Website, Marketing, and Sales | Preferred Data acts as controller | United States | |
| Meta (Facebook) | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| OpenAI (ChatGPT Ads) | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Vimeo | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Hotjar | Website, Marketing, and Sales | Preferred Data acts as controller | Malta |
| Intercom | Website, Marketing, and Sales | Preferred Data acts as controller | United States |
| Anthropic | AI and Automation Services | Sub-processor of customer data | United States |
| OpenAI | AI and Automation Services | Sub-processor of customer data | United States |
Current Sub-processors
Cloud Infrastructure and Hosting
Sub-processor of customer dataPlatforms that host our applications, store data at rest, and secure the network paths between our systems and yours. These apply to every customer.
Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.
Purpose:
Cloud infrastructure, productivity suite, collaboration, and identity
Data Types Processed:
- Email data
- Documents
- Cloud infrastructure
- User authentication
Compliance Certifications:
Purpose:
Cloud infrastructure and hosting
Data Types Processed:
- Application data
- Database storage
- Backups
Compliance Certifications:
Purpose:
Hosting, edge delivery, and build infrastructure for preferreddata.com and the client portal
Data Types Processed:
- Website request logs
- IP addresses
- Form submissions in transit
Compliance Certifications:
Purpose:
Application database, authentication, and file storage for the client portal
Data Types Processed:
- Account records
- User authentication
- Portal content and uploads
Compliance Certifications:
Purpose:
Bot and abuse protection on web forms, DNS, and Zero Trust tunnelling between our applications and on-premise systems
Data Types Processed:
- IP addresses
- Request metadata
- Encrypted application traffic
Compliance Certifications:
Purpose:
Source control and build automation for custom software we develop and maintain for customers
Data Types Processed:
- Application source code
- Issue and change history
- Build logs
Compliance Certifications:
Managed IT Service Delivery
Sub-processor of customer dataTooling used to monitor, secure, support, and back up customer environments. These apply to managed services and support customers.
Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.
Purpose:
Remote support sessions
Data Types Processed:
- Remote session content
- Session logs
- Device identifiers
Compliance Certifications:
Purpose:
Remote monitoring and management (RMM)
Data Types Processed:
- Device monitoring data
- Hardware and software inventory
- Performance metrics
Compliance Certifications:
Purpose:
Professional services automation: ticketing, scheduling, time tracking, quoting, and billing
Data Types Processed:
- Support ticket content
- Contact information
- Time and billing records
- Asset and contract records
Compliance Certifications:
Purpose:
Endpoint protection
Data Types Processed:
- Threat detection data
- System security events
Compliance Certifications:
Purpose:
Endpoint protection
Data Types Processed:
- Endpoint security data
- Security events
Compliance Certifications:
Purpose:
Backup and recovery
Data Types Processed:
- Backup data
- Recovery points
Compliance Certifications:
Purpose:
Backup and recovery
Data Types Processed:
- Backup data
- System configurations
Compliance Certifications:
Purpose:
Backup and disaster recovery
Data Types Processed:
- Backup data
- System configurations
- Recovery points
Compliance Certifications:
Purpose:
Network security and firewall management
Data Types Processed:
- Network traffic data
- Security logs
- Authentication data
Compliance Certifications:
Purpose:
Email security, filtering, and protection
Data Types Processed:
- Email communications
- Spam filtering data
- Security logs
Compliance Certifications:
Purpose:
Cloud software licensing and subscription management
Data Types Processed:
- Licence and subscription records
- Billing information
Compliance Certifications:
Purpose:
Workflow automation for service delivery
Data Types Processed:
- User account details
- Ticket and workflow metadata
Compliance Certifications:
Purpose:
IT documentation and knowledge management
Data Types Processed:
- IT documentation
- Network configurations
- Asset information
Compliance Certifications:
Purpose:
Enterprise password and secrets management
Data Types Processed:
- Encrypted credentials
- Access logs
- Team sharing data
Compliance Certifications:
Purpose:
Professional services automation (PSA)
Data Types Processed:
- Ticketing data
- Time tracking
- Billing information
Compliance Certifications:
Business Operations
Sub-processor of customer dataSystems used to run the commercial relationship: quoting, contracting, invoicing, and voice communications. These apply to all customers with an active agreement.
Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.
Purpose:
Accounting, invoicing, and financial record keeping
Data Types Processed:
- Billing contact information
- Invoice and payment records
- Transaction history
Compliance Certifications:
Purpose:
Electronic signature collection on agreements and authorisations
Data Types Processed:
- Signatory name and email
- Agreement content
- Electronic signatures and audit trails
Compliance Certifications:
Purpose:
Proposal and contract management
Data Types Processed:
- Contract data
- Proposal content
- Electronic signatures
Compliance Certifications:
Purpose:
Hosted voice (VOIP) telephony and related call handling
Data Types Processed:
- Call detail records
- Voicemail content
- Caller identifiers
Compliance Certifications:
Purpose:
Online payment processing
Data Types Processed:
- Payment card details
- Billing contact information
- Transaction records
Compliance Certifications:
Purpose:
Meeting scheduling and calendar management
Data Types Processed:
- Calendar availability
- Meeting details
- Contact information
Compliance Certifications:
Website, Marketing, and Sales
Preferred Data acts as controllerServices that operate on preferreddata.com and in our sales process. These process visitor and prospect data rather than data from managed customer environments.
Used to run our own website, marketing, and sales. These vendors do not process managed customer environments, and the notice and objection rights above do not apply to them.
Purpose:
Website analytics, tag management, and marketing
Data Types Processed:
- Website usage data
- Marketing analytics
- IP addresses
Compliance Certifications:
Purpose:
Website behaviour analytics, including session replay and heatmaps
Data Types Processed:
- Session recordings
- Click and scroll behaviour
- IP addresses
Compliance Certifications:
Purpose:
CRM and marketing automation
Data Types Processed:
- Contact information
- Sales data
- Marketing communications
Compliance Certifications:
Purpose:
Secondary CRM, marketing campaigns, and lead follow-up
Data Types Processed:
- Contact information
- Campaign engagement data
- Marketing communications
Compliance Certifications:
Purpose:
Event routing between our website forms and downstream business systems
Data Types Processed:
- Form submission payloads
- Contact information
- Integration logs
Compliance Certifications:
Purpose:
Transactional email delivery, such as confirmations and notifications
Data Types Processed:
- Recipient email addresses
- Email content
- Delivery and engagement logs
Compliance Certifications:
Purpose:
Lead generation, sales intelligence, and website visitor identification
Data Types Processed:
- Business contact information
- Company data
- Engagement analytics
Compliance Certifications:
Purpose:
Professional networking and advertising
Data Types Processed:
- Professional profile data
- Advertising analytics
- Website visitor data
Compliance Certifications:
Purpose:
Social media marketing and analytics
Data Types Processed:
- Advertising data
- Website visitor behaviour
- Conversion tracking
Compliance Certifications:
Purpose:
ChatGPT advertising conversion measurement via the OpenAI measurement pixel on preferreddata.com
Data Types Processed:
- Advertising data
- Website visitor behaviour
- Conversion tracking
Compliance Certifications:
Purpose:
Video hosting and playback embedded on our website
Data Types Processed:
- Video playback data
- IP addresses
- Device information
Compliance Certifications:
Purpose:
Website analytics and user behaviour
Data Types Processed:
- User behaviour data
- Session recordings
- Heatmap data
Compliance Certifications:
Purpose:
Customer support messaging and communications
Data Types Processed:
- Customer communications
- Support tickets
- User interactions
Compliance Certifications:
AI and Automation Services
Sub-processor of customer dataLarge language model providers used to assist with support triage, documentation, and software development. Content submitted to these services is not used to train their models under our enterprise terms.
Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.
Purpose:
AI assistance for support ticket triage, documentation, and software development
Data Types Processed:
- Support ticket content
- Technical documentation
- Application source code
Compliance Certifications:
Purpose:
AI features within our web applications and internal tooling
Data Types Processed:
- Prompt content submitted by users
- Generated output
- Usage metadata
Compliance Certifications:
Infrastructure Sub-processors
The following categories of sub-processor are used as part of our infrastructure and may process customer data indirectly:
- DNS providers for domain resolution
- Certificate authorities for SSL/TLS certificates
- Telecommunications providers for network connectivity
Security Measures
We require our sub-processors to maintain appropriate security measures, which typically include:
- Implementation of technical and organizational security measures appropriate to the risk
- Processing personal data only on our documented instructions
- Ensuring personnel are subject to appropriate confidentiality obligations
- Providing reasonable assistance with data subject rights and breach notifications
- Making available information necessary to demonstrate compliance
- Deleting or returning data upon termination of services, where technically feasible
The specific security requirements for each sub-processor are detailed in our agreements with them and are appropriate to the nature of the services they provide and the data they process.
Data Transfers
Where sub-processors transfer data outside the EEA, appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Other valid transfer mechanisms under GDPR
Contact Us
For questions about our sub-processors or to object to a new sub-processor:
Preferred Data Data Protection Officer
Email: [email protected]
Phone: (336) 886-3282
Address: 1208 Eastchester Drive, Suite 131, High Point, NC 27265