Subprocessors and Data Recipients
Effective and last updated: July 25, 2026
This registry separates providers that process Customer Personal Data for Foundable from operational vendors and recipients that act under their own terms. Feature-specific providers see data only when the relevant feature or channel is used.
How to read this registry
A subprocessor processes Customer Personal Data for Foundable to deliver the Service. The table states the production path that uses each provider; an entry does not mean every customer uses every provider. Providers used only for Foundable's own analytics or internal operations, and third parties that determine their own purposes, are described separately after the table.
The location column identifies verified project regions or the provider's published processing footprint. It is not a promise that support, security, or subprocessor access can occur in only one country. Contact us if your procurement process requires the account-specific contracting entity, data-residency configuration, or transfer mechanism.
Customer-data subprocessors
| Provider | Scope and purpose | Data processed | Primary storage / processing locations |
|---|---|---|---|
| Anthropic, PBC | Core AI: Claude inference for Ted, workers, and primary build agents | Customer Content, including chat messages, attached files, retrieved context, and tool inputs and outputs | Stored in the United States; processing may occur in the United States, Europe, Asia, and Australia unless a separate arrangement narrows it |
| Agnost Tech Inc. | AI quality analytics: AI conversation analytics and product-quality monitoring | Projected chat and tool inputs and outputs; tool status; operator and thread identifiers; operator display name and email. Onboarding public-profile source details are omitted before transmission. | Provider and subprocessor locations under the applicable service terms; contact Foundable for account-specific details |
| Exa Labs Inc. | Research features: Public-web research, audience discovery, and professional-profile search | Derived search queries, requested public URLs and page content, and limited onboarding identity hints. Full email addresses and locally generated email-username hints are not sent for onboarding search. | Provider and subprocessor locations; no single processing region is asserted by Foundable |
| OpenAI | Purpose-specific AI: Embeddings, structured extraction, and audio transcription | Selected company records or Customer Content submitted for embedding or structured extraction; audio submitted for transcription | United States and other OpenAI or subprocessor locations unless a separate data-residency arrangement applies |
| Cohere Inc. | Purpose-specific AI: Reranking search results and retrieved company context | The search query and candidate text passages selected for reranking | Account and subprocessor locations under the applicable Cohere agreement; no single region is asserted by Foundable |
| Supabase, Inc. | Core infrastructure: Managed Postgres database, authentication, and object storage | Account data, Customer Content, authentication data, and encrypted integration credentials | Foundable's primary project is in AWS us-west-1; support and subprocessor processing may occur elsewhere under Supabase's DPA |
| Amazon Web Services, Inc. | Core infrastructure: API hosting, worker runtime, network protection, and service logs | Requests in transit, runtime data needed to execute work, and application, security, and infrastructure logs | AWS us-west-1 for Foundable's API and worker infrastructure; other AWS locations may support the service |
| Daytona Platforms Inc. | Build features: Isolated cloud sandboxes and previews for building apps | Build instructions, generated or uploaded app source and files, build output, logs, and preview artifacts | Provider infrastructure selected for the Foundable tenant; contact Foundable for account-specific details |
| fal.ai | Creative features: Image and video generation | Creative prompts, reference media, generated outputs, and request metadata | Provider and model infrastructure locations; no single processing region is asserted by Foundable |
| AgentMail, Inc. | Email features: Managed inboxes and customer-directed email outreach | Sender and recipient addresses, subjects, message bodies, attachments, replies, and delivery events | United States and European Union under AgentMail's current subprocessor list |
| ZERNIO SOFTWARE SL | Social features: Connection and publishing to social networks | Connected-account credentials and identifiers, post copy and media, publishing status, and engagement analytics | Spain / European Union and provider subprocessor locations |
| PostHog, Inc. | Product analytics: First-party product analytics, feature flags, and selective session replay for operational debugging and product improvement | Operator and pseudonymous session identifiers, bounded operator role, page and route families, interaction and product events, performance and limited network diagnostic metadata, replay page structure, ordinary interface text outside designated private regions, and Customer Content in submitted chat with Ted replies as displayed. Input values and unsent drafts are masked; media and designated private regions are blocked; recorded URLs are sanitized; request and response header and body contents are omitted. | United States (Foundable uses PostHog Cloud US); provider support and subprocessor processing may occur elsewhere under PostHog's DPA and subprocessor list |
| Functional Software, Inc. (Sentry) | Error monitoring: Error monitoring and performance tracing | Stack traces, request URLs, user identifiers, and diagnostic context. Sensitive headers, URL credentials, known secret fields, and structured PII are redacted, but diagnostic context can still incidentally contain Customer Content. | United States ingestion region |
| Stripe, LLC and applicable Stripe affiliates | Billing: Payment processing and subscription administration where Stripe acts for Foundable | Billing contact and address, payment-method metadata, invoices, subscriptions, transaction history, and fraud or dispute information. Full card numbers are entered directly with Stripe. | Stripe and payment-network locations under the applicable agreement |
| Plus Five Five, Inc. (Resend) | Transactional email: Delivery of login links, notices, and receipts | Recipient addresses, message content, attachments where applicable, and delivery metadata | United States and subprocessor locations under Resend's DPA |
| Vercel, Inc. | Web application: UI hosting and edge delivery | Web requests, IP and device metadata, static assets, and data transmitted through the UI; Customer Content is not intentionally stored in the UI hosting layer | Primary processing in the United States with global edge and support processing |
| Cloudflare, Inc. | Selected infrastructure features: Turnstile bot protection, browser rendering, and DNS management for applicable customer domains | Challenge, device, and network data; rendered page or preview content; and domain names and DNS records for domains managed through Cloudflare | Global network |
| Hunter Web Services, Inc. | Grow email features: Email finding and verification performed on customer-submitted inputs | Names, company domains, email addresses, and verification or lookup inputs. Hunter separately acts as a controller for the professional Profile Data it maintains and returns. | Primary servers in Belgium, with other European Union and United States service providers |
| LoopMessage | Text-message channel: Delivery and receipt of customer-directed iMessage or SMS conversations | Message content, sender and recipient identifiers, replies, thread and delivery metadata, webhooks, and diagnostic records | United States hosting; message and API history may be retained for up to six months under the current public policy |
AI-provider data handling
Claude is the primary model family for Ted's conversational reasoning and build agents. OpenAI and Cohere handle narrower embedding, extraction, transcription, and reranking tasks. fal.ai receives prompts or media only when creative generation is used. Each provider is limited to the feature scope and data categories listed in the table.
- Anthropic's commercial terms prohibit training on Customer Content submitted through its services. Its standard API retention is generally up to 30 days, with longer trust-and-safety or legal retention in documented cases. See its current retention documentation.
- OpenAI states that business/API data is not used to train models by default. Its endpoint-specific retention and abuse-monitoring rules are described in its data-control documentation.
- Agnost receives the projected conversation and tool data described in the table for product-quality analytics. Contact Foundable with account-specific contractual or data-handling requirements.
Operational service providers
These vendors support Foundable's controller-side operations. They are not included in DPA Annex III when they do not process Customer Personal Data on a customer's behalf:
- Better Stack: public endpoint and job-heartbeat availability, status, latency, and incident metadata; it does not intentionally receive Customer Content.
- GitHub: Foundable source code and CI/CD. Customer-report metadata may appear when employees handle an issue, but product Customer Content is not intentionally stored there.
- Slack: Foundable's internal feedback and operational notifications. Feedback submitted to Foundable may be delivered to our internal Slack account.
Recipients acting under their own terms
Some features send data to a recipient that acts as an independent or joint controller, or has a role that varies by activity. Those recipients are not blanket Foundable subprocessors for that activity:
- Connected integrations and social networks receive the data and actions you direct Foundable to send. Their own terms govern their use of it.
- Meta Platforms, Inc. (Meta Ads), Google LLC (Google Ads, including YouTube ads), TikTok (TikTok For Business), and X Corp. (X Ads) may receive advertising-measurement data only when a visitor both arrives from that provider and explicitly allows ad measurement. Foundable uses no browser advertising pixels for this measurement; every provider receives only bounded server-side conversion measurement. The eligible data is an applicable provider click identifier (for Meta, a click identifier derived from fbclid and the first-party time when the ad landing was observed), event type, timestamp, provider-scoped pseudonymous stable event ID, the fixed event-source URL https://foundable.com/ for Meta, TikTok, and X, and an optional actual payment value/currency. The fixed URL has no path, query, or fragment and does not reveal the page viewed. Event type can include a successful refund or payment reversal as a distinct non-purchase event without payment value. Foundable's server payloads do not add the visitor's IP address, browser user agent, email, phone, actual page URL, referrer, provider browser cookie, idea/private-prompt text, form contents, account details, or Customer Content. GPC, DNT, no consent, or conflicting provider signals keep this measurement off. Each provider's own business, advertising, and privacy terms govern its use of received data.
- Meta for operator-approved Foundable Ads separately receives approved creative, campaign and delivery metadata, and eligible conversion events needed to deliver and measure an operator's approved advertising workflow under Meta's business and advertising terms.
- OpenSRS / Tucows, registry operators, ICANN, and escrow providers receive domain, registrant, contact, and transaction data required to register or administer a domain. Registry and legal retention may continue under their own obligations.
- Hunter acts for Foundable when verifying submitted contact data, but independently controls the professional Profile Data in its own database.
- Stripe and Link process some billing operations for Foundable and determine their own purposes for payment-network, fraud, compliance, tax, and merchant-of-record activities.
- Pexels / Canva Germany receives prompt-derived public-image search queries when the stock-photo rail is used.
Changes and objections
We update this registry when a provider or its role changes. Where a countersigned DPA or applicable law requires advance notice, we use the notice method and period stated in that agreement or law.
To ask about a provider, request account-specific processing details, or raise a data-protection objection, email privacy@foundable.com. If an effective DPA gives you a formal objection right, its process and deadline control.
Contract status
The public DPA page is available for review. Foundable and the customer complete an account-specific agreement to activate transfer mechanisms, audit rights, and notice periods.
Questions about this document? privacy@foundable.com
Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.