Vendor & Subprocessor Policy¶
| Field | Value |
|---|---|
| Status | draft |
| Owner | DIR (vendor selection) / COUNSEL (DPA terms, transfers) |
| Applies to | Every third party that processes Partile data or is critical to the service: Google Cloud, LinkedIn, Apple/EAS, Cloudflare, Anthropic, and future push/analytics/BI vendors. |
| Review cadence | Annual; plus before onboarding any new vendor that touches data, and on any material change to a vendor's role. |
| Mapped controls | GOV-02 (subprocessor register + DPAs), PRIV-11 (international transfers). |
| Evidence | ../registers/subprocessors.md; ../counsel-queue.md C3/C20; READINESS.md Q4/Q5. |
| Exception handling | Onboarding a data-processing vendor without a signed DPA is a dated, time-boxed risk-acceptance pending counsel. |
Purpose¶
Govern how Partile selects, contracts with, and oversees the third parties that handle its data — so the subprocessor register and DPAs are real, not aspirational.
Current honest state¶
DPAs with all vendors are not started (GOV-02); international transfer
mechanism is not started (PRIV-11). GCP production exists, but no real
user data has launched; pre-launch seed data is fictional/mock. The register
(../registers/subprocessors.md) is the live record.
Current / planned vendors¶
| Vendor | Role | Data today | Note |
|---|---|---|---|
| Identity provider (OIDC) | sub, email, name, picture on login |
API-terms review queued (C3); store minimal, no graph scraping | |
| Google Cloud | Production hosting/DB/cache/jobs/secrets/state | No real user data yet; mock seed data only | Production in europe-west2; DPA/transfer review pending |
| AWS | Superseded staging target | No production or real user data | Not adopted unless reintroduced |
| Apple / EAS | iOS and Android development-build distribution | App metadata; no end-user PII | Build/distribution only |
| Cloudflare | Production API edge, data-room Access/Pages, dev tunnel | Network metadata; no persisted app DB data | Token rotation action open |
| Anthropic | Key-gated AI rationale/interview | Minimized prompt context when key set | DPA/transfer review pending |
| Push / Analytics / BI (future) | Notifications / analytics | Device token / tiered events (future) | Gated on consent + DPA before live |
Requirements¶
- Register first. No vendor processes Partile data until it is in
../registers/subprocessors.mdwith purpose, data categories, region, and DPA status. - DPA before production data. A signed Art 28 DPA (Tier 2 — restricted) is required before any real user data flows to a processor. Pre-beta integrations with no real data may proceed with the requirement tracked.
- Data minimization to vendors. Share only the minimum categories the vendor needs; never secrets or unnecessary PII.
- International transfers (PRIV-11): the transfer mechanism (e.g. IDTA/SCCs) and residency decision are made before multi-country launch (M4), confirmed by counsel (C15).
- Security diligence proportionate to the data: prefer vendors with recognized assurance (e.g. SOC 2 / ISO 27001); record the basis.
- Offboarding. On vendor exit, ensure data return/deletion and update the register.
Exceptions¶
Using a data-processing vendor ahead of a signed DPA is permitted only for no-real-data integration or explicit mock seed testing, is time-boxed, and is recorded by DIR with the DPA as a tracked counsel item (C20). Real user data to a vendor without a DPA is not permitted unless counsel explicitly approves the legal basis and transfer mechanism.