Sub-processors

Last updated: June 9, 2026

SaasDash.ai (operated by Pmc Negocios Digitais Ltda) uses the third-party sub-processors listed below to deliver the service. Each sub-processor is bound by a written agreement with confidentiality and security obligations consistent with our Privacy Policy and Data Processing Agreement.

For each sub-processor we list the purpose, the categories of personal data they receive, the country where data is processed, and the transfer mechanism we rely on for personal data originating in the EEA, the United Kingdom, or Switzerland — either the EU-US Data Privacy Framework (DPF) where the vendor self-certifies, or the EU Standard Contractual Clauses (SCCs, Decision 2021/914) with the UK International Data Transfer Addendum where applicable.

Authentication & Identity

ServicePurposeData receivedRegionTransfer mechanism
Google LLC (OAuth)Google sign-inEmail, name, profile picture, OAuth tokensUnited StatesEU-US DPF + SCCs
GitHub, Inc. (OAuth)GitHub sign-inEmail, username, profile picture, OAuth tokensUnited StatesSCCs (Microsoft DPF certification)
Resend, Inc.Email magic-link deliveryEmail address, magic-link tokenUnited StatesSCCs

Payments

ServicePurposeData receivedRegionTransfer mechanism
Stripe, Inc.Subscription billing, Customer Portal, Stripe Connect for affiliate payoutsName, email, billing address, payment-method token, subscription metadataUnited States, with EU sub-processingEU-US DPF + SCCs

Email & Communications

ServicePurposeData receivedRegionTransfer mechanism
Resend, Inc.Transactional and marketing email delivery (onboarding bumpers, dunning, alerts, newsletters)Recipient email and name, template variables (metrics summaries, invitation tokens)United StatesSCCs
Google LLC (Gmail API)Inbound email ingestion for the Executive AssistantFull email content (subject, body, headers, attachments) sent by senders to our support aliasesUnited StatesEU-US DPF + SCCs
Telegram FZ-LLCInternal-only strategic founder alerts (security & billing incidents)Incident metadata; no customer personal data is sent in these alertsUnited Arab Emirates / GlobalSCCs (no customer personal data transferred)

AI & Machine Learning

ServicePurposeData receivedRegionTransfer mechanism
Anthropic, PBC (Claude API)AI insights, Ask Science, Activation Advisor, Executive Assistant triageConversation messages, metrics context, company profile, inbound email content when triagedUnited StatesEU-US DPF + SCCs. Anthropic does not train its foundation models on commercial API inputs or outputs.

Analytics & Product Telemetry

ServicePurposeData receivedRegionTransfer mechanism
PostHog, Inc.Product analytics, feature usage, exception telemetryPseudonymous user/visitor ID (on consent), event properties, page views, plan, role, stack traces and request context for unhandled errorsUnited States (US Cloud) — EU Cloud available on requestSCCs. Session recording is disabled.
Google LLC (Google Analytics 4)Web analytics (production only, consent-gated)Pseudonymous client ID, page views, event properties, plan, roleUnited StatesEU-US DPF + SCCs. IP anonymization on by default in GA4.

Advertising & Attribution

ServicePurposeData receivedRegionTransfer mechanism
Meta Platforms, Inc. (Meta Pixel + Conversions API)Conversion attribution, ad audience optimizationSHA-256 hashed email and phone, event metadata (event name, value, currency, event ID, URL, user agent). Sent only when marketing-cookie consent is given.United StatesEU-US DPF + SCCs. First-party Meta cookies (_fbp, _fbc) are stripped server-side after each event.

Hosting & Infrastructure

ServicePurposeData receivedRegionTransfer mechanism
Vercel, Inc.Application hosting, serverless compute, edge middlewareAll application data in transit; request logs (IP, user agent, URL, timestamp)United States (with global edge)SCCs
Neon, Inc.PostgreSQL database hostingAll application data (account, metrics, AI conversations, etc.), encrypted at restConfigurable per project (currently US East)SCCs
Upstash, Inc.Redis-based rate limitingRequest identifiers, counters, time windows (no customer personal data)Configurable per database (currently US East)SCCs

Change Notice

When we add a new sub-processor that handles personal data, or materially change the role of an existing one, we will update this page at least 30 days in advance. Business customers may subscribe to change notifications by emailing legal@saasdash.ai with the subject line "Sub-processor notifications".

For questions about any sub-processor listed here, contact privacy@saasdash.ai.