Subprocessor Agreement
To perform its Service, Searchness uses a number of third-party entities with whom it may share some of your personal data for processing. Under the European Union's General Data Protection Regulation (GDPR), these third-party entities are called data subprocessors.
This page provides a list of the data subprocessors we use, along with information about their location, the type of personal data we may share with them and the data processing agreements effective between them and us.
Amazon Web Services
aws.amazon.com
- Country: United States.
- Purpose: Data center infrastructure.
- Data disclosed: user accounts and content.
- Data security certifications: ISO/IEC 27001, SOC 1 TYPE II, SOC 2 TYPE II.
- Safeguards for data transfers outside the EU: Standard Contractual Clauses.
- Data processing agreement: signed, incorporated into terms.
Heroku (Salesforce)
heroku.com
- Country: United States.
- Purpose: Data center infrastructure.
- Data disclosed: user accounts and content.
- Data security certifications: ISO/IEC 27001, SOC 1 TYPE II, SOC 2 TYPE II.
- Data processing agreement: signed.
Sentry
sentry.io
- Country: United States.
- Purpose: technical error reporting.
- Data disclosed: user ids on Searchness, urls accessed on Searchness, technical errors encountered.
- Data security certifications: SOC 2 Type I.
- Safeguards for data transfers outside the EU: Standard Contractual Clauses.
- Data processing agreement: signed.
Stripe
stripe.com
- Country: United States.
- Purpose: payment processing.
- Data disclosed: credit card details and billing information.
- Data security certifications: PCI Service Provider Level 1.
- Safeguards for data transfers outside the EU: Standard Contractual Clauses.
- Data processing agreement: signed.
Twilio
twilio.com
- Country: United States.
- Purpose: audio and video recording of research sessions, transactional emails.
- Data disclosed: audio and video recording of research sessions, emails addresses and transactional email communications.
- Data security certifications: ISO/IEC 27001.
- Safeguards for data transfers outside the EU: Standard Contractual Clauses.
- Data processing agreement: signed, incorporated into terms.
Last updated: September 9th, 2020