Back to Foundable

Subprocessors and Data Recipients

How to read this registry

A subprocessor processes Customer Personal Data for Foundable to deliver the Service. The table states the production path that uses each provider; an entry does not mean every customer uses every provider. Providers used only for Foundable's own analytics or internal operations, and third parties that determine their own purposes, are described separately after the table.

The location column identifies verified project regions or the provider's published processing footprint. It is not a promise that support, security, or subprocessor access can occur in only one country. Contact us if your procurement process requires the account-specific contracting entity, data-residency configuration, or transfer mechanism.

Customer-data subprocessors

ProviderScope and purposeData processedPrimary storage / processing locations
Anthropic, PBCCore AI: Claude inference for Ted, workers, and primary build agentsCustomer Content, including chat messages, attached files, retrieved context, and tool inputs and outputsStored in the United States; processing may occur in the United States, Europe, Asia, and Australia unless a separate arrangement narrows it
Agnost Tech Inc.AI quality analytics: AI conversation analytics and product-quality monitoringProjected chat and tool inputs and outputs; tool status; operator and thread identifiers; operator display name and email. Onboarding public-profile source details are omitted before transmission.Provider and subprocessor locations under the applicable service terms; contact Foundable for account-specific details
Exa Labs Inc.Research features: Public-web research, audience discovery, and professional-profile searchDerived search queries, requested public URLs and page content, and limited onboarding identity hints. Full email addresses and locally generated email-username hints are not sent for onboarding search.Provider and subprocessor locations; no single processing region is asserted by Foundable
OpenAIPurpose-specific AI: Embeddings, structured extraction, and audio transcriptionSelected company records or Customer Content submitted for embedding or structured extraction; audio submitted for transcriptionUnited States and other OpenAI or subprocessor locations unless a separate data-residency arrangement applies
Cohere Inc.Purpose-specific AI: Reranking search results and retrieved company contextThe search query and candidate text passages selected for rerankingAccount and subprocessor locations under the applicable Cohere agreement; no single region is asserted by Foundable
Supabase, Inc.Core infrastructure: Managed Postgres database, authentication, and object storageAccount data, Customer Content, authentication data, and encrypted integration credentialsFoundable's primary project is in AWS us-west-1; support and subprocessor processing may occur elsewhere under Supabase's DPA
Amazon Web Services, Inc.Core infrastructure: API hosting, worker runtime, network protection, and service logsRequests in transit, runtime data needed to execute work, and application, security, and infrastructure logsAWS us-west-1 for Foundable's API and worker infrastructure; other AWS locations may support the service
Daytona Platforms Inc.Build features: Isolated cloud sandboxes and previews for building appsBuild instructions, generated or uploaded app source and files, build output, logs, and preview artifactsProvider infrastructure selected for the Foundable tenant; contact Foundable for account-specific details
fal.aiCreative features: Image and video generationCreative prompts, reference media, generated outputs, and request metadataProvider and model infrastructure locations; no single processing region is asserted by Foundable
AgentMail, Inc.Email features: Managed inboxes and customer-directed email outreachSender and recipient addresses, subjects, message bodies, attachments, replies, and delivery eventsUnited States and European Union under AgentMail's current subprocessor list
ZERNIO SOFTWARE SLSocial features: Connection and publishing to social networksConnected-account credentials and identifiers, post copy and media, publishing status, and engagement analyticsSpain / European Union and provider subprocessor locations
PostHog, Inc.Product analytics: First-party product analytics, feature flags, and selective session replay for operational debugging and product improvementOperator and pseudonymous session identifiers, bounded operator role, page and route families, interaction and product events, performance and limited network diagnostic metadata, replay page structure, ordinary interface text outside designated private regions, and Customer Content in submitted chat with Ted replies as displayed. Input values and unsent drafts are masked; media and designated private regions are blocked; recorded URLs are sanitized; request and response header and body contents are omitted.United States (Foundable uses PostHog Cloud US); provider support and subprocessor processing may occur elsewhere under PostHog's DPA and subprocessor list
Functional Software, Inc. (Sentry)Error monitoring: Error monitoring and performance tracingStack traces, request URLs, user identifiers, and diagnostic context. Sensitive headers, URL credentials, known secret fields, and structured PII are redacted, but diagnostic context can still incidentally contain Customer Content.United States ingestion region
Stripe, LLC and applicable Stripe affiliatesBilling: Payment processing and subscription administration where Stripe acts for FoundableBilling contact and address, payment-method metadata, invoices, subscriptions, transaction history, and fraud or dispute information. Full card numbers are entered directly with Stripe.Stripe and payment-network locations under the applicable agreement
Plus Five Five, Inc. (Resend)Transactional email: Delivery of login links, notices, and receiptsRecipient addresses, message content, attachments where applicable, and delivery metadataUnited States and subprocessor locations under Resend's DPA
Vercel, Inc.Web application: UI hosting and edge deliveryWeb requests, IP and device metadata, static assets, and data transmitted through the UI; Customer Content is not intentionally stored in the UI hosting layerPrimary processing in the United States with global edge and support processing
Cloudflare, Inc.Selected infrastructure features: Turnstile bot protection, browser rendering, and DNS management for applicable customer domainsChallenge, device, and network data; rendered page or preview content; and domain names and DNS records for domains managed through CloudflareGlobal network
Hunter Web Services, Inc.Grow email features: Email finding and verification performed on customer-submitted inputsNames, company domains, email addresses, and verification or lookup inputs. Hunter separately acts as a controller for the professional Profile Data it maintains and returns.Primary servers in Belgium, with other European Union and United States service providers
LoopMessageText-message channel: Delivery and receipt of customer-directed iMessage or SMS conversationsMessage content, sender and recipient identifiers, replies, thread and delivery metadata, webhooks, and diagnostic recordsUnited States hosting; message and API history may be retained for up to six months under the current public policy

AI-provider data handling

Claude is the primary model family for Ted's conversational reasoning and build agents. OpenAI and Cohere handle narrower embedding, extraction, transcription, and reranking tasks. fal.ai receives prompts or media only when creative generation is used. Each provider is limited to the feature scope and data categories listed in the table.

  • Anthropic's commercial terms prohibit training on Customer Content submitted through its services. Its standard API retention is generally up to 30 days, with longer trust-and-safety or legal retention in documented cases. See its current retention documentation.
  • OpenAI states that business/API data is not used to train models by default. Its endpoint-specific retention and abuse-monitoring rules are described in its data-control documentation.
  • Agnost receives the projected conversation and tool data described in the table for product-quality analytics. Contact Foundable with account-specific contractual or data-handling requirements.

Operational service providers

These vendors support Foundable's controller-side operations. They are not included in DPA Annex III when they do not process Customer Personal Data on a customer's behalf:

  • Better Stack: public endpoint and job-heartbeat availability, status, latency, and incident metadata; it does not intentionally receive Customer Content.
  • GitHub: Foundable source code and CI/CD. Customer-report metadata may appear when employees handle an issue, but product Customer Content is not intentionally stored there.
  • Slack: Foundable's internal feedback and operational notifications. Feedback submitted to Foundable may be delivered to our internal Slack account.

Recipients acting under their own terms

Some features send data to a recipient that acts as an independent or joint controller, or has a role that varies by activity. Those recipients are not blanket Foundable subprocessors for that activity:

  • Connected integrations and social networks receive the data and actions you direct Foundable to send. Their own terms govern their use of it.
  • Meta Platforms, Inc. (Meta Ads), Google LLC (Google Ads, including YouTube ads), TikTok (TikTok For Business), and X Corp. (X Ads) may receive advertising-measurement data only when a visitor both arrives from that provider and explicitly allows ad measurement. Foundable uses no browser advertising pixels for this measurement; every provider receives only bounded server-side conversion measurement. The eligible data is an applicable provider click identifier (for Meta, a click identifier derived from fbclid and the first-party time when the ad landing was observed), event type, timestamp, provider-scoped pseudonymous stable event ID, the fixed event-source URL https://foundable.com/ for Meta, TikTok, and X, and an optional actual payment value/currency. The fixed URL has no path, query, or fragment and does not reveal the page viewed. Event type can include a successful refund or payment reversal as a distinct non-purchase event without payment value. Foundable's server payloads do not add the visitor's IP address, browser user agent, email, phone, actual page URL, referrer, provider browser cookie, idea/private-prompt text, form contents, account details, or Customer Content. GPC, DNT, no consent, or conflicting provider signals keep this measurement off. Each provider's own business, advertising, and privacy terms govern its use of received data.
  • Meta for operator-approved Foundable Ads separately receives approved creative, campaign and delivery metadata, and eligible conversion events needed to deliver and measure an operator's approved advertising workflow under Meta's business and advertising terms.
  • OpenSRS / Tucows, registry operators, ICANN, and escrow providers receive domain, registrant, contact, and transaction data required to register or administer a domain. Registry and legal retention may continue under their own obligations.
  • Hunter acts for Foundable when verifying submitted contact data, but independently controls the professional Profile Data in its own database.
  • Stripe and Link process some billing operations for Foundable and determine their own purposes for payment-network, fraud, compliance, tax, and merchant-of-record activities.
  • Pexels / Canva Germany receives prompt-derived public-image search queries when the stock-photo rail is used.

Changes and objections

We update this registry when a provider or its role changes. Where a countersigned DPA or applicable law requires advance notice, we use the notice method and period stated in that agreement or law.

To ask about a provider, request account-specific processing details, or raise a data-protection objection, email privacy@foundable.com. If an effective DPA gives you a formal objection right, its process and deadline control.

Contract status

The public DPA page is available for review. Foundable and the customer complete an account-specific agreement to activate transfer mechanisms, audit rights, and notice periods.

Questions about this document? privacy@foundable.com

Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.

Continue to footer navigation