Privacy and Data

Subprocessors

Current third-party processors with purpose and data handling role transparency.

Effective date
March 1, 2026
Last updated
March 16, 2026
Category
Privacy and Data
Applies to
Business and compliance evaluators
At a glance

Lists subprocessors, purpose, data category, and governance expectations for vendor controls.

TransparencyEnterprise

This page lists subprocessors used to deliver cyang.io and Doclinks services. Subprocessors are selected for operational necessity and are expected to maintain appropriate security and privacy controls.

1. How We Use Subprocessors

Subprocessors are engaged to support infrastructure, storage, delivery, billing, communications, and operational security.

2. Subprocessor Selection Principles

We evaluate subprocessors for:

  • security posture,
  • reliability and operational maturity,
  • privacy and contractual safeguards,
  • service fit for controlled document delivery.

3. Current Subprocessors

ProviderPurposeData categories processedPrimary region relevanceTrust / privacy reference
Vercel Inc.Primary application hosting, build pipeline, static asset delivery, and serverless executionIP address, request metadata, deployment metadata, application telemetryUS and global edge footprinthttps://vercel.com/legal/privacy-policy
Neon, Inc.Managed Postgres database hosting, branching, backup, and restore operationsAccount data, document metadata, audit logs, billing state, operational telemetryUS-hosted managed database infrastructurehttps://neon.tech/privacy-policy
Cloudflare, Inc.DNS, CDN caching, WAF/rate limiting, R2 object storage, and scheduled worker executionIP address, request metadata, security telemetry, stored document objects, backup artifactsGlobal edge network and storage footprinthttps://www.cloudflare.com/trust-hub/
GitHub, Inc.Source control, CI/CD automation, and scheduled backup workflowsSource code metadata, deployment metadata, backup artifacts, operational run metadataUS-hosted and regional automation infrastructurehttps://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
Google LLCGoogle OAuth authentication for supported sign-in flowsEmail address, profile identifier, authentication metadataGlobal infrastructurehttps://policies.google.com/privacy
Functional Software, Inc. (Sentry)Error monitoring, crash diagnostics, and request-level observabilityError events, request metadata, limited operational telemetryUS and global processing footprinthttps://sentry.io/privacy/
Hetzner Online GmbHOptional self-hosted malware scanning and supporting compute when dedicated scanner infrastructure is enabledOperational service data, scanner telemetry, encrypted document workflows routed for malware reviewEU-hosted infrastructure footprinthttps://www.hetzner.com/legal/privacy-policy
Stripe, Inc.Subscription billing and payment processingBilling identifiers, transaction metadata, business contact detailsUS and regional processing infrastructurehttps://stripe.com/privacy
Resend, Inc.Transactional email deliveryEmail addresses, email event metadata, support communications metadataUS and regional delivery infrastructurehttps://resend.com/legal/privacy-policy

4. Data Protection Expectations

Subprocessors are bound by contractual and operational requirements appropriate to their role, including confidentiality and data protection obligations.

5. Change Management

We may update this list as vendors are added, replaced, or removed for operational reasons. Material changes are reflected in this document's Last Updated date.

6. Vendor Questions

For subprocessor and data handling questions:

  • privacy@cyang.io
  • legal@cyang.io