Abstract Sub-processors
Last revised: June 27, 2022
A sub-processor is a third-party company Abstract uses to process customer-related data. We've included the name of these companies, contact information, a brief description of the processing, and technical and organizational measures to be taken by the sub-processor to be able to provide assistance to the Customer.
Amazon Web Services
https://aws.amazon.com/contact-us/compliance-support/
Mail
Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109-5210, ATTN: AWS Legal
Amazon Web Services provides cloud data center services.
They store Abstract’s personal data and host the Abstract applications that process the data.
AWS manages all physical security of the data centers and equipment. They also provide maintenance for the physical equipment.
APIHub (Clearbit)
Mail
90 Sheridan St. in San Francisco, California, 94103. ATTN: Data Protection Officer
Phone Number
(866) 241-4820
Email
privacy@clearbit.com
Clearbit provides data enrichment on marketing leads.
The transferred GDPR Personal Data typically relates to the following categories of data: email or IP addresses Customer has provided.
Clearbit is responsible for securing personal data against accidental or unlawful loss, access, or disclosure, identifying risks, and minimizing risks through assessment and regular testing.
Braintree
Mail
PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal L-2449, Luxembourg. ATTN: Data Protection Officer
Braintree provides payment processing.
Customer name, amount to be charged, date/time, bank account details, payment card details, CVC code, post code, country code, address, email address, fax, phone, website, expiry data, shipping details, tax status, unique customer identifier, IP Address, location, and any other data received by PayPal under the Agreement.
Braintree is responsible for the confidentiality and integrity of personal data, including: physical security of their systems and facilities, access control to customer data, access control to processing systems, Least Privilege, encryption, logging and monitoring, deletion prevention, and backups.
Datadog
Mail
Datadog, Inc.,
620 8th Avenue, Floor 45, New York, NY 10018
Email
gdpr@datadoghq.com.
Privacy Policy
Datadog is a monitoring and analytics tool for information technology (IT) and DevOps teams that can be used to determine performance metrics as well as event monitoring for infrastructure and cloud services.
For a full list of what information Datadog can collect, click here.
Datadog is used to monitor services such as servers, databases and tools.
They take physical, technical and organizational measures, to protect your personal information from unauthorized access and against unlawful processing, accidental loss, destruction and damage.
Google Analytics
Phone
855-548-2777
Privacy Help Center
Google Analytics collects identifying data about Abstract’s website visitors, including device information, web activity, and location information.
Google is responsible for data protections such as encryption, implementing and reviewing security controls, physical and logical access control.
Mode Analytics
Mail
Mode Analytics,
Attn: Data Protection Officer,
208 Utah St., Suite 400,
San Francisco, CA 94103
Mode provides general data analytics and visualizations.
Data processed may include:
Contact information,
Profile information,
Communications,
Transaction information,
Marketing information.
Mode is responsible for developing security policies and controls, developing security controls, auditing controls, conducting risk assessment, data security controls, encryption, access control, secure software development processes, incident response and disaster recovery, network security controls, and vulnerability assessment and mitigation.
Pusher
Mail (HQ)
MessageBird B.V.
Attn. Legal Department (Data Protection)
Trompenburgstraat 2C1079 TX Amsterdam
The Netherlands
Data Protection Officer Email
privacy@messagebird.com
Pusher Channels provides realtime communication between servers, apps and devices for realtime UI updates.Pusher Channels has libraries for web browsers, iOS and Android apps, PHP frameworks, cloud functions, bash scripts, IoT devices.
For a full list of data Pusher can process and collect, click here.
Pusher channels are used to update web-pages, apps and devices when an event happens on an app, the app can notify all other apps and your system.
Data security is paramount to Pusher from MessageBird. They invest in state-of-the-art tech and thorough security screenings of their infrastructure and employees to minimize security risks.
Recurly
Mail (U.S.A)
400 Alabama Street, Suite 202, San Francisco, CA 94110, ATTN: Recurly Compliance Team
Email (U.S.A)
support@recurly.com
Data Protection Officer dpo@recurly.com
EU Representative
DP-Dock GmbH, Attn: Recurly Inc., Ballindamm 39, 20095 Hamburg, Germany
UK Representative
DP Data Protection Services UK Ltd., Attn: Recurly Inc., 16 Great Queen Street, Covent Garden, London, WC2B 5AH, United Kingdom
Email
recurly@gdpr-rep.com
Recurly provides payment processing
Data processed includes
• Name
• Company Name, VAT Number
• Phone Number
• Email
• Address
• IP Address
• Username
• Account Code (can include email addresses)
• Notes on an account, invoice or transaction
• Account Number Last Four
• Payment card details
Recurly has implemented and will maintain appropriate technical and organisational measures, internal controls and
information security routines intended to protect Personal Data. The technical and organisational measures, internal controls and the information security standards including, SOC 2 Type II and PCI DSS which the Recurly is audited against.
Salesforce
Salesforce provides Customer Relationship Management services
Data processed includes:
• First and last name
• Title
• Position
• Employer
• Contact information (company, email, phone, physical business address)
• ID data
• Professional life data
• Personal life data
• Localisation data
Salesforce will maintain administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Personal Data uploaded to the SCC Services, as described in the Security, Privacy and Architecture Documentation applicable to the specific SCC Services purchased by Abstract, and accessible via http://help.salesforce.com or otherwise made reasonably available by Salesforce.
Sentry
Mail
Functional Software, Inc. dba Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105.
Email
compliance@sentry.io
security@sentry.io
Sentry provides application error reporting
Data processed may include:
Direct identifying information (e.g. name, email address, telephone)
Indirect identifying information (e.g. job title, gender, date of birth)
Device identification data and traffic data (e.g. IP addresses, MAC addresses, web logs,
browser agents)
Any personal data supplied by end users of the Service
Sentry is responsible for controlling access to personal data, and ensures that all personnel with data access have confidentiality agreements in place.
Twilio-SendGrid
Documentation
SendGrid FAQs
Privacy Policy
twilio.com/legal/privacy
SendGrid provides marketing email management and automation.
Data processed by SendGrid include Direct identifying information (e.g. name, email address, telephone)Indirect identifying information (e.g. job title, gender, date of birth)
Device identification data and traffic data (e.g. IP addresses, MAC addresses, web logs,
browser agents) and any personal data supplied by end users of the Service
SendGrid is responsible for protection of personal data.
SendGrid’s US-based data centers are located in Herndon, VA; Las Vegas, NV; and Chicago, IL. When you send mail, it will go to the inbound data center that is closest to you in order to transfer mailto our pipeline quickly. Mail is not processed at these locations, but is forwarded to our US-based data centers for processing and sending.
Zendesk
Mail
Zendesk, Inc.
Attn: Shanti Ariker, General Counsel
989 Market Street
San Francisco, CA 94103, United States
Email
privacy@zendesk.com
Zendesk provides a customer support platform
Processing may include, but is not limited to, the following categories of data: first and last name, email address, telephone number, address (business or personal), date of birth, communications (telephone recordings, voicemail), customer service information, title.
Zendesk provides our customers compliance with high security standards, such as encryption of data in motion over public networks, auditing standards (SOC 2, ISO 27001, ISO 27018), Distributed Denial of Service (“DDoS”) mitigations, and a Support team that is on-call 24/7