Trust

Sub-processors

Effective:
Last updated:

1. About this list

This is the canonical, version-stamped list of sub-processors that Worql, Inc. ("Worql") engages to process Personal Data on customers' behalf when delivering the Worql service. Each sub-processor is bound by a written agreement requiring data-protection commitments no less protective than our Data Processing Addendum.

The list updates when we add, replace, or remove a sub-processor. Customers on paid plans are notified by email at least 30 days before any addition or replacement; the change appears here on the same day. Pages older than today's "Last updated" date are not authoritative.

2. Current sub-processors

| Sub-processor | Service | Personal Data category | Hosting region | |---|---|---|---| | Clerk, Inc. | Authentication, session management, profile storage | Account identifiers, email, name, OAuth provider claims | United States | | Stripe, Inc. | Subscription billing, customer portal, card processing | Billing contact, payment method (held by Stripe, not by Worql), subscription state | United States (Stripe's compliance scope) | | Anthropic PBC | AI clause-generation API (Claude) used to draft SOW text | Project briefs, intake answers, draft SOW text passed to the API at generation time. Anthropic does not retain inputs for training under its commercial terms. | United States | | Neon, Inc. | Application database (PostgreSQL) — primary store for accounts, projects, SOWs, billing metadata | All workspace data | AWS us-east-1 (United States) | | Upstash, Inc. | Redis used for rate limiting and ephemeral key/value state | Hashed user identifiers used as rate-limit keys; counters | AWS us-east-1 (United States) | | Resend, Inc. | Transactional and notification email (welcome, upgrade, payment failed, account events) | Email address, name, message content | United States | | Vercel, Inc. | Application hosting, edge runtime, request logs, cookieless Analytics and Speed Insights | Request metadata (IP, user-agent, path), Customer Personal Data only as it transits through hosting | United States |

3. Sub-processors used in limited situations

These are not engaged routinely but may process Personal Data in specific, narrow contexts. They are listed for completeness.

| Sub-processor | When engaged | Data category | |---|---|---| | Stripe Atlas (Stripe, Inc.) | Corporate / tax compliance services used by Worql, Inc. itself (not the customer-facing Service). Not a customer-data processor. | None of the Customer's Personal Data. |

4. How to object

Customers on paid plans may object in writing to a proposed addition or replacement for material privacy or security reasons. If we cannot resolve the objection, the customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid fees per Section 7 of the DPA.

Send objections or questions to privacy@worql.app.

5. Older versions

We maintain the prior versions of this list on request for audit purposes. Email legal@worql.app if you need the version that was in effect on a specific date.