# Processor Registry

## Sub-processors List

**Effective Date**  
November 11, 2025

**Version**  
Protocol v2.0 (Stable)

### Table of Contents

- 01. AI Model Providers
- 02. Payment & Financial Services
- 03. Cloud Infrastructure
- 04. Analytics & Monitoring
- 05. Authentication Services
- 06. Communication Services
- 07. Data Processing Safeguards
- 08. Changes & Notifications
- 09. Contact Information

This document constitutes a binding registry of authorized data sub-processors.

## GDPR ARTICLE 28 COMPLIANT REGISTRY

In accordance with Article 28 of the General Data Protection Regulation (GDPR) and our Data Processing Agreement (DPA), Blankline maintains this comprehensive list of sub-processors that may process personal data on behalf of our customers.

All sub-processors are bound by strict contractual obligations including Data Processing Agreements (DPAs), Standard Contractual Clauses (SCCs) where applicable, and appropriate technical and organizational security measures.

## Section 01  
### AI Model Providers

Third-party AI service providers that process user prompts, code, and interaction data to deliver AI-powered features.

#### OpenAI Inc.
- **Country:** United States  
- **Services:** AI model processing, NLG, code assistance (GPT-4, GPT-5).  
- **Data:** User prompts, code snippets, context data.  
- **Safeguards:** Zero-retention agreements, no training data usage.

#### Anthropic PBC
- **Country:** United States  
- **Services:** Advanced AI model processing (Claude-3-haiku, Claude-4).  
- **Data:** User prompts, code snippets, context data.  
- **Safeguards:** Commercial Terms compliance, no training data usage.

#### Deepseek
- **Country:** International  
- **Services:** Specialized AI model processing (Deepseek-V3).  
- **Data:** User prompts, code snippets, technical queries.  
- **Safeguards:** API Terms compliance, DPA, encrypted transmission.

#### xAI Corp
- **Country:** United States  
- **Services:** AI model processing, advanced reasoning.  
- **Data:** User prompts, reasoning queries.  
- **Safeguards:** Developer Agreement compliance, data restrictions.

## Section 02  
### Payment & Financial Services

#### Stripe Inc.
- **Country:** United States  
- **Services:** Payment processing, subscription management, fraud prevention.  
- **Data:** Billing info, transaction amounts, subscription details.  
- **Safeguards:** PCI DSS Level 1, SOC 2 Type II.

## Section 03  
### Cloud Infrastructure

#### Amazon Web Services (AWS)
- **Country:** United States  
- **Services:** Cloud hosting, compute, storage, backups.  
- **Data:** Application data, user files, logs.  
- **Safeguards:** SOC 1/2/3, ISO 27001, FedRAMP.

#### Neon Database
- **Country:** United States  
- **Services:** Serverless PostgreSQL database.  
- **Data:** User accounts, app data, preferences.  
- **Safeguards:** SOC 2 Type II, encryption.

#### Vercel Inc.
- **Country:** United States  
- **Services:** Frontend hosting, CDN, performance monitoring.  
- **Data:** Visitor data, performance metrics.  
- **Safeguards:** SOC 2 Type II, DPA.

## Section 04  
### Analytics & Monitoring

#### PostHog Inc.
- **Country:** United States  
- **Services:** Product analytics, feature tracking.  
- **Data:** Anonymized usage patterns, metrics.  
- **Safeguards:** GDPR compliant, SOC 2 Type II.

#### Sentry
- **Country:** United States  
- **Services:** Error monitoring, crash reporting.  
- **Data:** Error logs, stack traces, diagnostics.  
- **Safeguards:** SOC 2 Type II, data scrubbing.

## Section 05  
### Authentication Services

#### Google OAuth
- **Country:** United States  
- **Services:** SSO authentication, verification.  
- **Data:** Profile info, email, tokens.  
- **Safeguards:** OAuth 2.0 standards, encryption.

#### GitHub OAuth
- **Country:** United States  
- **Services:** Developer auth, repo integration.  
- **Data:** GitHub profile, email, tokens.  
- **Safeguards:** OAuth 2.0 standards, scope limits.

## Section 06  
### Communication Services

#### Resend
- **Country:** United States  
- **Services:** Transactional email delivery.  
- **Data:** Email addresses, content, metadata.  
- **Safeguards:** GDPR compliance, encryption.

## Section 07  
### Data Processing Safeguards

All sub-processors listed above operate under comprehensive contractual obligations that ensure appropriate protection of personal data:

- **DPAs:** GDPR Article 28 compliant agreements.
- **SCCs:** EU-approved safeguards for transfers.
- **Technical:** Encryption, access controls, monitoring.
- **Organizational:** Staff training, audits, background checks.

## Section 08  
### Changes & Notifications

#### Notification Protocol

Blankline will provide at least 30 days' advance written notice of any intended changes concerning sub-processors. Customers may object to new sub-processors on reasonable data protection grounds within 15 days of notice.

## Section 09  
### Contact Information

**Data Protection Lead:** [privacy@blankline.org](mailto:privacy@blankline.org)  
**Legal Notices:** [legal@blankline.org](mailto:legal@blankline.org)

BY USING THE DROPSTONE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE REVIEWED THIS SUB-PROCESSOR REGISTRY AND AGREE TO THE APPOINTMENT OF THESE PROCESSORS.
