Skip to content

Vendor & Subprocessor Policy

Field Value
Status draft
Owner DIR (vendor selection) / COUNSEL (DPA terms, transfers)
Applies to Every third party that processes Partile data or is critical to the service: Google Cloud, LinkedIn, Apple/EAS, Cloudflare, Anthropic, and future push/analytics/BI vendors.
Review cadence Annual; plus before onboarding any new vendor that touches data, and on any material change to a vendor's role.
Mapped controls GOV-02 (subprocessor register + DPAs), PRIV-11 (international transfers).
Evidence ../registers/subprocessors.md; ../counsel-queue.md C3/C20; READINESS.md Q4/Q5.
Exception handling Onboarding a data-processing vendor without a signed DPA is a dated, time-boxed risk-acceptance pending counsel.

Purpose

Govern how Partile selects, contracts with, and oversees the third parties that handle its data — so the subprocessor register and DPAs are real, not aspirational.

Current honest state

DPAs with all vendors are not started (GOV-02); international transfer mechanism is not started (PRIV-11). GCP production exists, but no real user data has launched; pre-launch seed data is fictional/mock. The register (../registers/subprocessors.md) is the live record.

Current / planned vendors

Vendor Role Data today Note
LinkedIn Identity provider (OIDC) sub, email, name, picture on login API-terms review queued (C3); store minimal, no graph scraping
Google Cloud Production hosting/DB/cache/jobs/secrets/state No real user data yet; mock seed data only Production in europe-west2; DPA/transfer review pending
AWS Superseded staging target No production or real user data Not adopted unless reintroduced
Apple / EAS iOS and Android development-build distribution App metadata; no end-user PII Build/distribution only
Cloudflare Production API edge, data-room Access/Pages, dev tunnel Network metadata; no persisted app DB data Token rotation action open
Anthropic Key-gated AI rationale/interview Minimized prompt context when key set DPA/transfer review pending
Push / Analytics / BI (future) Notifications / analytics Device token / tiered events (future) Gated on consent + DPA before live

Requirements

  1. Register first. No vendor processes Partile data until it is in ../registers/subprocessors.md with purpose, data categories, region, and DPA status.
  2. DPA before production data. A signed Art 28 DPA (Tier 2 — restricted) is required before any real user data flows to a processor. Pre-beta integrations with no real data may proceed with the requirement tracked.
  3. Data minimization to vendors. Share only the minimum categories the vendor needs; never secrets or unnecessary PII.
  4. International transfers (PRIV-11): the transfer mechanism (e.g. IDTA/SCCs) and residency decision are made before multi-country launch (M4), confirmed by counsel (C15).
  5. Security diligence proportionate to the data: prefer vendors with recognized assurance (e.g. SOC 2 / ISO 27001); record the basis.
  6. Offboarding. On vendor exit, ensure data return/deletion and update the register.

Exceptions

Using a data-processing vendor ahead of a signed DPA is permitted only for no-real-data integration or explicit mock seed testing, is time-boxed, and is recorded by DIR with the DPA as a tracked counsel item (C20). Real user data to a vendor without a DPA is not permitted unless counsel explicitly approves the legal basis and transfer mechanism.