Sub-Processor List & Third-Party Data Source Disclosure

Effective date: June 12, 2026

About This Document

This page discloses (1) all third-party sub-processors that Excede Inc. engages to process customer personal data in connection with the Excede Unified Platform, and (2) third-party services that customers may elect to connect to the Platform as data sources.

This list is maintained in compliance with GDPR Article 28(2) and CCPA/CPRA service-provider disclosure requirements. Customers with a signed Data Security Addendum (DSA) are entitled to object to the addition of new sub-processors with 30 days' written notice. To receive notifications of changes to this list, email privacy@excede.ai with subject "Sub-Processor Notification Request".

Section 1 — Sub-Processors (Engaged by Excede)

Infrastructure & Hosting

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Supabase Inc.Database hosting, authentication, file storage, real-time subscriptionsAll customer data (projects, contacts, financials, user accounts)USAExecuted — Supabase DPA signed June 2026; EU SCCs providedsupabase.com/privacy
Vercel Inc.Application hosting, serverless functions, CDN, CI/CDRequest logs, IP addresses, usage telemetry, build artifactsUSAExecuted — Vercel DPA; EU SCCs for EEA trafficvercel.com/legal/privacy-policy
Amazon Web Services (AWS)Underlying cloud infrastructure (via Supabase)Customer data at rest and in transitUSA (us-east-1)Executed — AWS DPA / SCCsaws.amazon.com/privacy
Cloudflare Inc.CDN, DNS proxy, DDoS protection, TLS terminationIP addresses, request metadata, all inbound trafficUSA (global network)Executed — June 2026cloudflare.com/privacypolicy
OttomatikDatabase backup automationFull database backup — all personal data stored in Supabase (excluding regenerable AI embedding tables per backup configuration)USAExecuted — June 2026ottomatik.io/privacy

Code Repository & Security

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
GitHub (Microsoft)Primary source code repository, CI/CDSource code, developer identities, commit metadataUSAExecuted — GitHub DPA / Microsoft OSTGitHub privacy statement
GitLab Inc.Backup source code repositorySource code, developer identities, commit metadataUSAExecuted — June 2026about.gitlab.com/privacy
Snyk Ltd.Security vulnerability scanningSource code, dependency manifestsUSA / UKExecuted — June 2026snyk.io/policies/privacy

Monitoring, Logging & Uptime

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Functional Software Inc. (Sentry)Error monitoring, performance trackingStack traces, request metadata, user IDs (PII scrubbing via beforeSend)USAExecuted — June 2026sentry.io/privacy
Axiom Inc.Application log managementApplication logs — may include user IDs, IP addresses, email addresses, request parametersUSAExecuted — June 2026axiom.co/privacy
Better Stack Inc.Uptime monitoring, incident alertingEndpoint URLs, ping/response metadataUSAExecuted — June 2026betterstack.com/privacy

Caching & Queuing

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Upstash Inc.Redis — session caching, rate limiting, queuing (QStash)Session tokens, hashed user identifiers, rate-limit keys, cached payloadsUSAExecuted — verified June 2026upstash.com/trust/privacy.pdf

Consent Management

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Cybot A/S (Cookiebot)Cookie consent managementConsent records, visitor preferencesDenmark (EU)Executed — June 2026cookiebot.com/en/privacy-policy

Email Delivery

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Resend Inc.Transactional email deliveryRecipient email addresses, message contentUSAExecuted — June 2026resend.com/legal/privacy-policy

Payments

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Stripe Inc.Payment processing, subscription billingCustomer billing contact data, payment method data (card data held by Stripe, never stored by Excede)USAExecuted — June 2026stripe.com/privacy

Productivity & Business Operations

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Google LLC (Google Workspace)Email, document collaboration, support communicationsCustomer contact data and support correspondence that transits Excede’s WorkspaceUSAExecuted — June 2026policies.google.com/privacy

AI / ML Processing

VendorPurposeData ProcessedHQDPA StatusPrivacy Policy
Google LLC (Vertex AI / Gemini)AI model inference for platform features (lead scoring, content generation)Prompt inputs which may include contact and project dataUSAExecuted — June 2026cloud.google.com/terms/data-processing-addendum

Section 2 — Internal Vendors (Excede as Controller)

These vendors process Excede's own business records (in which Excede acts as data controller). They do not process customer platform data and are tracked in the internal Vendor Register rather than as sub-processors.

VendorPurposeData ProcessedHQPrivacy Policy
Intuit Inc. (QuickBooks Online)Excede corporate accounting and invoicingExcede financial records; customer billing contact details on invoicesUSAintuit.com/privacy

Section 3 — Tenant-Authorized Data Sources

The Excede Platform allows Customers to connect third-party business systems as data sources. These services are selected, connected, and authorized by the Customer via OAuth or API credentials. They are governed by the Customer's own agreements with the respective providers and are not sub-processors of Excede. Excede accesses these systems solely on the Customer's documented instructions to provide the Services.

Security controls applied by Excede to tenant integrations: OAuth tokens and API credentials are encrypted at rest in dedicated encrypted columns; permissions and OAuth scopes are limited to the product features the Customer enables (broader vendor permissions may require Customer admin consent); credentials are used server-side only; stored credentials are cleared when an integration is disconnected, with vendor-side OAuth revocation attempted where supported, and integration credential records are removed when a Customer workspace is deleted.

ServiceTypical Data AccessedConnection Method
Microsoft 365 (Graph API)Email, calendar, user directoryCustomer-authorized OAuth
Zoho Corporation (Zoho Books / CRM)Financial data, invoices, vendor recordsCustomer-authorized OAuth
Intuit QuickBooks Online (customer instance)Financial data, invoicesCustomer-authorized OAuth
BambooHR LLCEmployee roster, roles, employment dataCustomer-authorized API key
Cake.com Inc. (Clockify)Time entries, project codesCustomer-authorized API key
Toggl OÜ (Toggl Track)Time entries, project codesCustomer-authorized API key

Customer responsibility: Customer represents and warrants that it has all rights, consents, and authority necessary to connect third-party integrations to the Service. See DSA Section 3 (Customer Compliance Obligations).

Change Notification

Excede will provide 30 days' written notice (via email to subscribed customers) before adding any new sub-processor in Section 1. Changes to Section 3 reflect platform capability additions and do not require notice, as connection of any data source is at the Customer's sole election.

Document history: v1.1 — Clarified tenant integration security controls; v1.0 — Initial release.