DeadpanLabs
// subprocessors

Subprocessors

The complete list of third parties that can touch data we hold on your behalf — what each one does, what it can see, and what it publishes about its own security.

Last updated July 25, 2026

How to read this

A subprocessor is a company we rely on that may process data you entrust to us. We keep the list deliberately short — every additional vendor is another place your data can go — and we list services even when the feature that uses them is switched off for your workspace, because a dormant vendor is still a vendor.

The “posture” line restates what each vendor publishes on its own trust page, linked so you can check it rather than take our word for it. We don’t audit our vendors ourselves and we’re not warranting their certifications — we’re telling you who they are so your own review can proceed.

Subprocessors

These may process client or personal data.

Why we use it
Hosts and serves the marketing site and the client portal, and provides our cookieless site analytics.
What it can touch
Everything you send us passes through Vercel in transit. Request metadata (IP address, timestamp) is processed transiently to serve and protect the request. The analytics product stores no cookie, no IP, and no identifier.
Where
United States
Its posture
SOC 2 Type II. Publishes a DPA and a subprocessor list.
Why we use it
Our managed Postgres database and authentication service. This is the system of record for the client portal.
What it can touch
All client workspace data: accounts and roles, projects and updates, dashboard content, uploaded assets, messages (stored encrypted by us before they reach the database), and sales inquiries submitted through our website.
Where
United States
Its posture
SOC 2 Type II; encryption at rest; automated daily backups on our plan. Publishes a DPA and a subprocessor list.

Cloudflare

trust page ↗
Why we use it
Turnstile bot protection on our public forms. Nothing else — we do not proxy our sites through Cloudflare.
What it can touch
A challenge token and the request metadata needed to decide whether a form submission is automated. Turnstile is designed not to track users across sites and sets no advertising cookie.
Where
Global edge network
Its posture
SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS.
Why we use it
Delivers our transactional email — portal invitations, password resets, and the notification copy of a form submission that reaches our inbox.
What it can touch
Recipient email address, sender, subject, and message body of transactional mail. No marketing profiles are built.
Where
United States
Its posture
Publishes its security posture and a GDPR data-processing agreement. Our sending key is held in our own relay, never in the website.

Google Workspace (Google LLC)

trust page ↗
Why we use it
Runs our company mailboxes — including the inbox a copy of your inquiry lands in — and the Drive workspace where client deliverables are prepared and shared.
What it can touch
Email correspondence with you, and the documents and deliverables produced for your engagement.
Where
United States
Its posture
ISO/IEC 27001, 27017, 27018, 27701; SOC 1/2/3. Publishes a Cloud Data Processing Addendum.
Why we use it
Processes platform fees and subscription payments when in-platform billing is enabled for a workspace.
What it can touch
Billing contact and payment details. Card numbers are entered on Stripe-hosted checkout pages and never touch our servers, our database, or our logs — we store only Stripe's identifiers and the fact that a charge cleared.
Where
United States
Its posture
PCI DSS Level 1 service provider; SOC 1 and SOC 2.

Google Maps Platform (Google LLC)

trust page ↗
Why we use it
Renders the map in the property-tracking dashboard widget. Loaded only in workspaces where that widget is enabled — most workspaces never contact it.
What it can touch
When the widget renders, your browser sends the addresses or coordinates being mapped to Google in order to draw the map.
Where
United States
Its posture
Covered by Google Cloud's ISO/IEC 27001 and SOC 1/2/3 programs and its Data Processing Addendum.

Other vendors in our stack

Listed for completeness. These support how we build and run the platform but do not process client data.

Why we use it
Private network between our own machines for internal operations tooling.
What it can touch
No client data. It carries our internal administrative traffic and is not in the path of the platform your workspace runs on.
Where
United States
Its posture
Publishes its security documentation and a DPA.
Why we use it
Distribution of our iOS application.
What it can touch
App distribution metadata only. No client workspace data is transferred to Apple by us.
Where
United States
Its posture
Publishes its privacy and security documentation.

GitHub (Microsoft)

trust page ↗
Why we use it
Source-code hosting and our CI security checks.
What it can touch
Our source code and build logs. No client data, no personal data of your users, and no production credentials — secrets are scanned for and blocked on every push.
Where
United States
Its posture
SOC 1 Type II, SOC 2 Type II, ISO/IEC 27001.
Why we use it
Domain registration and authoritative DNS for deadpanlabs.com.
What it can touch
Domain records only. No client data.
Where
United States
Its posture
Registrar; publishes its own security and privacy documentation.

Automated analysis and generation

Some of what we deliver — content drafting, competitive analysis, visibility research — involves automated generation. Today, no client data is sent to any third-party model provider as part of running this platform: none of the applications your workspace touches call one. We do use such services for our own first-party content operations, on data we own — we mention it because it is true, not because it touches you.

If an engagement of yours would involve automated processing of your data, the specific provider, what it receives, and its retention and training terms are named in your data-processing agreement and agreed in writing before any of your data reaches it. We would rather tell you that this category exists and is disclosed at contract than let you find the gap yourself.

What this list deliberately excludes

Purely financial and administrative relationships that process no client or personal data — our bank, our accountant, our registered agent — are not listed, because naming them tells you nothing about where your data goes. If you want the full corporate vendor register for a diligence process, ask and we will share it under NDA.

Our own infrastructure

Outbound email from our website is relayed through integration infrastructure we build and operate ourselves rather than a third-party automation service, which is why our email provider key never sits in the website. It is our system, not a subprocessor — but it is in the path, so we name it here rather than let you discover it.

International transfers

Deadpan Labs LLC is a Florida company and our infrastructure is operated in the United States. Where a client is subject to the GDPR or UK GDPR, transfers rely on the Standard Contractual Clauses or equivalent mechanisms offered in each vendor’s data-processing agreement, which we execute with them.

Changes to this list

When we add or remove a subprocessor we update this page and move the date at the top. Clients under contract are notified in accordance with their agreement, and any objection process agreed in a DPA applies. To be told directly when this list changes, email contact@deadpanlabs.com and ask to be added to the notification list.

Need a DPA, or the full picture?

Our security page covers how the platform itself is built. For a data-processing agreement or a completed questionnaire, just ask.

Get in touch →