Sub-processors

Last updated: August 10, 2026

Overview

Preferred Data engages 42 third-party vendors to deliver our services and to run our own business. This page is the authoritative list referenced by section 5.2 of our Data Processing Agreement.

Not every vendor applies to every customer. The list is grouped by function, and each group is labelled with the role we play in that processing. All vendors have been vetted against our security standards and applicable data protection regulations, including GDPR.

Sub-processors of customer data. Vendors we engage to process personal data on behalf of a customer, on that customer's instructions. These are sub-processors in the sense of Article 28 GDPR, and the 30-day notice and objection rights described below and in section 5.1 of the DPA apply to them.

Vendors we use as a controller. Services that support our own website, marketing, and sales, where Preferred Data decides the purpose of the processing and no customer instruction is involved. They are listed here for transparency, but they do not process managed customer environments. How they handle visitor and prospect data is governed by our Privacy Policy and Cookie Policy.

For details on the cookies our website sets, see our Cookie Policy. For how we handle personal data generally, see our Privacy Policy.

Important Notice

Compliance Certifications:The compliance certifications listed for each sub-processor are attestations published by that vendor, based on publicly available information at the time of our last review, and are subject to change. Preferred Data makes reasonable efforts to keep this information current but cannot guarantee the ongoing accuracy of third-party certifications. Each entry links to the vendor's own privacy or trust page so you can verify directly.

Due Diligence: While we perform due diligence on our sub-processors, customers requiring specific compliance certifications should independently verify current compliance status with their account representative.

Notification of Changes

We will notify customers at least 30 days before adding or removing any sub-processor of customer data. Customers may object to the addition of a new sub-processor by contacting us within 14 days of notification. This commitment mirrors section 5.1 of the DPA and applies to the groups marked Sub-processor of customer data below.

Sub-processors at a Glance

The table below summarises every sub-processor and the function it serves. Full detail, including data types processed, follows in the sections beneath it.

VendorCategoryOur roleLocation
Microsoft (Azure and Microsoft 365)Cloud Infrastructure and HostingSub-processor of customer dataUnited States
Amazon Web Services (AWS)Cloud Infrastructure and HostingSub-processor of customer dataUnited States
VercelCloud Infrastructure and HostingSub-processor of customer dataUnited States
SupabaseCloud Infrastructure and HostingSub-processor of customer dataUnited States
CloudflareCloud Infrastructure and HostingSub-processor of customer dataUnited States
GitHub (Microsoft)Cloud Infrastructure and HostingSub-processor of customer dataUnited States
ConnectWise ScreenConnectManaged IT Service DeliverySub-processor of customer dataUnited States
NinjaOneManaged IT Service DeliverySub-processor of customer dataUnited States
HaloPSAManaged IT Service DeliverySub-processor of customer dataUnited Kingdom
Malwarebytes ThreatDownManaged IT Service DeliverySub-processor of customer dataUnited States
SentinelOneManaged IT Service DeliverySub-processor of customer dataUnited States
N-able Cove Data ProtectionManaged IT Service DeliverySub-processor of customer dataUnited States
Hornetsecurity (Altaro VM Backup)Managed IT Service DeliverySub-processor of customer dataGermany
VeeamManaged IT Service DeliverySub-processor of customer dataSwitzerland
WatchGuardManaged IT Service DeliverySub-processor of customer dataUnited States
AppRiver (OpenText)Managed IT Service DeliverySub-processor of customer dataUnited States
Pax8Managed IT Service DeliverySub-processor of customer dataUnited States
RewstManaged IT Service DeliverySub-processor of customer dataUnited States
IT GlueManaged IT Service DeliverySub-processor of customer dataCanada
1PasswordManaged IT Service DeliverySub-processor of customer dataCanada
SyncroManaged IT Service DeliverySub-processor of customer dataUnited States
Intuit QuickBooks OnlineBusiness OperationsSub-processor of customer dataUnited States
Zoho SignBusiness OperationsSub-processor of customer dataUnited States
PandaDocBusiness OperationsSub-processor of customer dataUnited States
IntermediaBusiness OperationsSub-processor of customer dataUnited States
StripeBusiness OperationsSub-processor of customer dataUnited States
CalendlyBusiness OperationsSub-processor of customer dataUnited States
Google (Analytics, Ads, and Tag Manager)Website, Marketing, and SalesPreferred Data acts as controllerUnited States
Microsoft ClarityWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
HubSpotWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
GoHighLevelWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
PipedreamWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
ResendWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
Apollo.ioWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
LinkedInWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
Meta (Facebook)Website, Marketing, and SalesPreferred Data acts as controllerUnited States
OpenAI (ChatGPT Ads)Website, Marketing, and SalesPreferred Data acts as controllerUnited States
VimeoWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
HotjarWebsite, Marketing, and SalesPreferred Data acts as controllerMalta
IntercomWebsite, Marketing, and SalesPreferred Data acts as controllerUnited States
AnthropicAI and Automation ServicesSub-processor of customer dataUnited States
OpenAIAI and Automation ServicesSub-processor of customer dataUnited States

Current Sub-processors

Cloud Infrastructure and Hosting

Sub-processor of customer data

Platforms that host our applications, store data at rest, and secure the network paths between our systems and yours. These apply to every customer.

Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.

Microsoft (Azure and Microsoft 365)

Location: United States

Privacy and trust information

Purpose:

Cloud infrastructure, productivity suite, collaboration, and identity

Data Types Processed:

  • Email data
  • Documents
  • Cloud infrastructure
  • User authentication

Compliance Certifications:

SOC 2ISO 27001GDPR

Amazon Web Services (AWS)

Location: United States

Privacy and trust information

Purpose:

Cloud infrastructure and hosting

Data Types Processed:

  • Application data
  • Database storage
  • Backups

Compliance Certifications:

SOC 2ISO 27001GDPR

Vercel

Location: United States

Privacy and trust information

Purpose:

Hosting, edge delivery, and build infrastructure for preferreddata.com and the client portal

Data Types Processed:

  • Website request logs
  • IP addresses
  • Form submissions in transit

Compliance Certifications:

SOC 2GDPR

Supabase

Location: United States

Privacy and trust information

Purpose:

Application database, authentication, and file storage for the client portal

Data Types Processed:

  • Account records
  • User authentication
  • Portal content and uploads

Compliance Certifications:

SOC 2HIPAAGDPR

Cloudflare

Location: United States

Privacy and trust information

Purpose:

Bot and abuse protection on web forms, DNS, and Zero Trust tunnelling between our applications and on-premise systems

Data Types Processed:

  • IP addresses
  • Request metadata
  • Encrypted application traffic

Compliance Certifications:

SOC 2ISO 27001GDPR

GitHub (Microsoft)

Location: United States

Privacy and trust information

Purpose:

Source control and build automation for custom software we develop and maintain for customers

Data Types Processed:

  • Application source code
  • Issue and change history
  • Build logs

Compliance Certifications:

SOC 2ISO 27001GDPR

Managed IT Service Delivery

Sub-processor of customer data

Tooling used to monitor, secure, support, and back up customer environments. These apply to managed services and support customers.

Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.

ConnectWise ScreenConnect

Location: United States

Privacy and trust information

Purpose:

Remote support sessions

Data Types Processed:

  • Remote session content
  • Session logs
  • Device identifiers

Compliance Certifications:

SOC 2GDPR

NinjaOne

Location: United States

Privacy and trust information

Purpose:

Remote monitoring and management (RMM)

Data Types Processed:

  • Device monitoring data
  • Hardware and software inventory
  • Performance metrics

Compliance Certifications:

SOC 2GDPR

HaloPSA

Location: United Kingdom

Privacy and trust information

Purpose:

Professional services automation: ticketing, scheduling, time tracking, quoting, and billing

Data Types Processed:

  • Support ticket content
  • Contact information
  • Time and billing records
  • Asset and contract records

Compliance Certifications:

ISO 27001GDPR

Malwarebytes ThreatDown

Location: United States

Privacy and trust information

Purpose:

Endpoint protection

Data Types Processed:

  • Threat detection data
  • System security events

Compliance Certifications:

SOC 2GDPR

SentinelOne

Location: United States

Privacy and trust information

Purpose:

Endpoint protection

Data Types Processed:

  • Endpoint security data
  • Security events

Compliance Certifications:

SOC 2ISO 27001GDPR

N-able Cove Data Protection

Location: United States

Privacy and trust information

Purpose:

Backup and recovery

Data Types Processed:

  • Backup data
  • Recovery points

Compliance Certifications:

SOC 2GDPR

Hornetsecurity (Altaro VM Backup)

Location: Germany

Privacy and trust information

Purpose:

Backup and recovery

Data Types Processed:

  • Backup data
  • System configurations

Compliance Certifications:

ISO 27001GDPR

Veeam

Location: Switzerland

Privacy and trust information

Purpose:

Backup and disaster recovery

Data Types Processed:

  • Backup data
  • System configurations
  • Recovery points

Compliance Certifications:

SOC 2ISO 27001GDPR

WatchGuard

Location: United States

Privacy and trust information

Purpose:

Network security and firewall management

Data Types Processed:

  • Network traffic data
  • Security logs
  • Authentication data

Compliance Certifications:

SOC 2GDPR

AppRiver (OpenText)

Location: United States

Privacy and trust information

Purpose:

Email security, filtering, and protection

Data Types Processed:

  • Email communications
  • Spam filtering data
  • Security logs

Compliance Certifications:

SOC 2GDPR

Pax8

Location: United States

Privacy and trust information

Purpose:

Cloud software licensing and subscription management

Data Types Processed:

  • Licence and subscription records
  • Billing information

Compliance Certifications:

SOC 2GDPR

Rewst

Location: United States

Privacy and trust information

Purpose:

Workflow automation for service delivery

Data Types Processed:

  • User account details
  • Ticket and workflow metadata

Compliance Certifications:

SOC 2GDPR

IT Glue

Location: Canada

Privacy and trust information

Purpose:

IT documentation and knowledge management

Data Types Processed:

  • IT documentation
  • Network configurations
  • Asset information

Compliance Certifications:

SOC 2GDPR

1Password

Location: Canada

Privacy and trust information

Purpose:

Enterprise password and secrets management

Data Types Processed:

  • Encrypted credentials
  • Access logs
  • Team sharing data

Compliance Certifications:

SOC 2GDPRCCPA

Syncro

Location: United States

Privacy and trust information

Purpose:

Professional services automation (PSA)

Data Types Processed:

  • Ticketing data
  • Time tracking
  • Billing information

Compliance Certifications:

SOC 2GDPR

Business Operations

Sub-processor of customer data

Systems used to run the commercial relationship: quoting, contracting, invoicing, and voice communications. These apply to all customers with an active agreement.

Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.

Intuit QuickBooks Online

Location: United States

Privacy and trust information

Purpose:

Accounting, invoicing, and financial record keeping

Data Types Processed:

  • Billing contact information
  • Invoice and payment records
  • Transaction history

Compliance Certifications:

SOC 2GDPR

Zoho Sign

Location: United States

Privacy and trust information

Purpose:

Electronic signature collection on agreements and authorisations

Data Types Processed:

  • Signatory name and email
  • Agreement content
  • Electronic signatures and audit trails

Compliance Certifications:

SOC 2ISO 27001GDPR

PandaDoc

Location: United States

Privacy and trust information

Purpose:

Proposal and contract management

Data Types Processed:

  • Contract data
  • Proposal content
  • Electronic signatures

Compliance Certifications:

SOC 2GDPRHIPAA

Intermedia

Location: United States

Privacy and trust information

Purpose:

Hosted voice (VOIP) telephony and related call handling

Data Types Processed:

  • Call detail records
  • Voicemail content
  • Caller identifiers

Compliance Certifications:

SOC 2GDPR

Stripe

Location: United States

Privacy and trust information

Purpose:

Online payment processing

Data Types Processed:

  • Payment card details
  • Billing contact information
  • Transaction records

Compliance Certifications:

PCI DSSSOC 2GDPR

Calendly

Location: United States

Privacy and trust information

Purpose:

Meeting scheduling and calendar management

Data Types Processed:

  • Calendar availability
  • Meeting details
  • Contact information

Compliance Certifications:

SOC 2GDPRCCPA

Website, Marketing, and Sales

Preferred Data acts as controller

Services that operate on preferreddata.com and in our sales process. These process visitor and prospect data rather than data from managed customer environments.

Used to run our own website, marketing, and sales. These vendors do not process managed customer environments, and the notice and objection rights above do not apply to them.

Google (Analytics, Ads, and Tag Manager)

Location: United States

Privacy and trust information

Purpose:

Website analytics, tag management, and marketing

Data Types Processed:

  • Website usage data
  • Marketing analytics
  • IP addresses

Compliance Certifications:

SOC 2ISO 27001GDPR

Microsoft Clarity

Location: United States

Privacy and trust information

Purpose:

Website behaviour analytics, including session replay and heatmaps

Data Types Processed:

  • Session recordings
  • Click and scroll behaviour
  • IP addresses

Compliance Certifications:

SOC 2ISO 27001GDPR

HubSpot

Location: United States

Privacy and trust information

Purpose:

CRM and marketing automation

Data Types Processed:

  • Contact information
  • Sales data
  • Marketing communications

Compliance Certifications:

SOC 2ISO 27001GDPR

GoHighLevel

Location: United States

Privacy and trust information

Purpose:

Secondary CRM, marketing campaigns, and lead follow-up

Data Types Processed:

  • Contact information
  • Campaign engagement data
  • Marketing communications

Compliance Certifications:

GDPR

Pipedream

Location: United States

Privacy and trust information

Purpose:

Event routing between our website forms and downstream business systems

Data Types Processed:

  • Form submission payloads
  • Contact information
  • Integration logs

Compliance Certifications:

SOC 2GDPR

Resend

Location: United States

Privacy and trust information

Purpose:

Transactional email delivery, such as confirmations and notifications

Data Types Processed:

  • Recipient email addresses
  • Email content
  • Delivery and engagement logs

Compliance Certifications:

SOC 2GDPR

Apollo.io

Location: United States

Privacy and trust information

Purpose:

Lead generation, sales intelligence, and website visitor identification

Data Types Processed:

  • Business contact information
  • Company data
  • Engagement analytics

Compliance Certifications:

SOC 2GDPR

LinkedIn

Location: United States

Privacy and trust information

Purpose:

Professional networking and advertising

Data Types Processed:

  • Professional profile data
  • Advertising analytics
  • Website visitor data

Compliance Certifications:

SOC 2GDPR

Meta (Facebook)

Location: United States

Privacy and trust information

Purpose:

Social media marketing and analytics

Data Types Processed:

  • Advertising data
  • Website visitor behaviour
  • Conversion tracking

Compliance Certifications:

SOC 2GDPR

OpenAI (ChatGPT Ads)

Location: United States

Privacy and trust information

Purpose:

ChatGPT advertising conversion measurement via the OpenAI measurement pixel on preferreddata.com

Data Types Processed:

  • Advertising data
  • Website visitor behaviour
  • Conversion tracking

Compliance Certifications:

SOC 2GDPR

Vimeo

Location: United States

Privacy and trust information

Purpose:

Video hosting and playback embedded on our website

Data Types Processed:

  • Video playback data
  • IP addresses
  • Device information

Compliance Certifications:

SOC 2GDPR

Hotjar

Location: Malta

Privacy and trust information

Purpose:

Website analytics and user behaviour

Data Types Processed:

  • User behaviour data
  • Session recordings
  • Heatmap data

Compliance Certifications:

GDPRCCPA

Intercom

Location: United States

Privacy and trust information

Purpose:

Customer support messaging and communications

Data Types Processed:

  • Customer communications
  • Support tickets
  • User interactions

Compliance Certifications:

SOC 2GDPR

AI and Automation Services

Sub-processor of customer data

Large language model providers used to assist with support triage, documentation, and software development. Content submitted to these services is not used to train their models under our enterprise terms.

Engaged to process customer data on customer instructions. The 30-day notice and objection rights apply to these vendors.

Anthropic

Location: United States

Privacy and trust information

Purpose:

AI assistance for support ticket triage, documentation, and software development

Data Types Processed:

  • Support ticket content
  • Technical documentation
  • Application source code

Compliance Certifications:

SOC 2ISO 27001GDPR

OpenAI

Location: United States

Privacy and trust information

Purpose:

AI features within our web applications and internal tooling

Data Types Processed:

  • Prompt content submitted by users
  • Generated output
  • Usage metadata

Compliance Certifications:

SOC 2GDPR

Infrastructure Sub-processors

The following categories of sub-processor are used as part of our infrastructure and may process customer data indirectly:

  • DNS providers for domain resolution
  • Certificate authorities for SSL/TLS certificates
  • Telecommunications providers for network connectivity

Security Measures

We require our sub-processors to maintain appropriate security measures, which typically include:

  • Implementation of technical and organizational security measures appropriate to the risk
  • Processing personal data only on our documented instructions
  • Ensuring personnel are subject to appropriate confidentiality obligations
  • Providing reasonable assistance with data subject rights and breach notifications
  • Making available information necessary to demonstrate compliance
  • Deleting or returning data upon termination of services, where technically feasible

The specific security requirements for each sub-processor are detailed in our agreements with them and are appropriate to the nature of the services they provide and the data they process.

Data Transfers

Where sub-processors transfer data outside the EEA, appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Other valid transfer mechanisms under GDPR

Contact Us

For questions about our sub-processors or to object to a new sub-processor:

Preferred Data Data Protection Officer

Email: [email protected]

Phone: (336) 886-3282

Address: 1208 Eastchester Drive, Suite 131, High Point, NC 27265

Support