Subprocessors
CoordOS uses a small set of trusted third-party vendors ("Subprocessors") to deliver the Service. This page lists those Subprocessors, the purpose for which we use each, the categories of data they may access on our or your behalf, and the primary region in which they process data. It supplements our Privacy Policy and our Terms of Service.
We will update this page when we add or change a material Subprocessor and will provide at least thirty (30) days' prior notice of material additions by posting an update here and, where applicable, by emailing the Owner. To receive notice of Subprocessor changes, email hello@coordos.ai.
Current Subprocessors
| Subprocessor | Purpose | Data accessed | Location | DPA |
|---|---|---|---|---|
| Google Cloud Platform (Google LLC / Google Ireland Ltd.) | Primary infrastructure: hosting (Cloud Run), database (Firestore), secrets and key management (Cloud KMS), object storage (Cloud Storage), background processing. | All Customer Data stored or processed by the Service, integration tokens (encrypted), audit logs. | us-central1 (United States), with multi-region replication for some managed services. | GCP DPA |
| Google Workspace APIs (Google LLC) | Customer-authorized read and write access to Google Drive, Gmail, Calendar, and Sheets, used to deliver Agent Desks where the Customer has authorized those scopes. | Drive files, mailbox content, calendar events, and spreadsheet content the Customer has authorized the Service to access. | Google global infrastructure; data remains in the Customer's own Google account. | Google DPA |
| Anthropic, PBC | AI model inference for the Agent Desks (chat, drafting, classification, document extraction, takeoff and quote extraction). | Prompts and contextual content sent to the model on the Customer's behalf (which may include excerpts of Customer Data) and the model's responses. | United States. | Anthropic DPA |
| Stripe, Inc. / Stripe Payments Canada, Ltd. | Subscription billing and payment processing for Agent Desks and add-ons. | Billing contact, email, company, payment-method tokens, invoices, subscription identifiers. CoordOS does not store full card numbers; that data lives with Stripe. | United States and global Stripe infrastructure. | Stripe DPA |
| SendGrid (Twilio Inc.) | Transactional and notification email delivery (such as Agent updates, approval requests, billing notices). | Recipient email address, sender identity, subject, message body, delivery metadata. | United States. | Twilio DPA |
| Microsoft Corporation (optional) | Customer-authorized read and write access to Outlook and Microsoft 365 (Graph API) for Customers who choose to integrate Microsoft mailboxes or calendars. | Mailbox content, calendar events, and other Microsoft 365 content the Customer has authorized the Service to access. | Microsoft global infrastructure; data remains in the Customer's own Microsoft 365 tenant. | Microsoft DPA |
| Intuit Inc. | QuickBooks Online integration: read of financial records and, on Customer approval, write of bills, invoices, and journal entries. | QuickBooks Online company data the Customer has authorized the Service to access, plus call metadata for audit and debugging. | United States. | Intuit security & compliance |
| Vercel Inc. | Hosting and serverless functions for the marketing site at coordos.ai. | Marketing-site request logs (IP, user-agent, request path), and form submissions sent to our marketing-site endpoints. No portal Customer Data is processed by Vercel. | United States (primary), with edge points of presence globally. | Vercel DPA |
Questions, objections, or change notifications
To ask about Subprocessors, raise an objection to a proposed change, or subscribe to change notifications, email hello@coordos.ai.