Legal · Subprocessors & Data Partners

Subprocessors & Data Partners

The third-party services Torbi works with — split into two clear groups: Subprocessors who process data on Torbi's behalf under our DPA, and Data Partners who are independent controllers we license data from. Different legal roles; different opt-out paths.

Last updated: 15 May 2026Notification policy: 30 days before any addition or replacement

Infrastructure & hosting

Where the application runs, where data sits at rest, and how we keep it resilient.

ProviderPurposeLocationCertifications
Amazon Web ServicesApplication hosting, primary database, object storage, backupsap-south-1 (Mumbai) · eu-west-1 (Ireland)SOC 2ISO 27001GDPR
CloudflareCDN, DNS, DDoS protection, WAFGlobalSOC 2ISO 27001
VercelMarketing website hostingGlobal edge · US data planeSOC 2

AI & inference

Foundation-model providers used to draft outreach, classify signals, and run matching. All operate under zero-retention API agreements — your content is not retained beyond the inference request and is not used to train their models.

ProviderPurposeLocationCertifications
AnthropicLLM inference — outreach drafting, classification, summarisationUSSOC 2 Type IIZero retention
OpenAILLM inference (fallback) and embeddingsUSSOC 2 Type IIZero retention
PineconeVector search for matchingeu-west-1 (Ireland)SOC 2 Type II

Email, calling & messaging

Used to send service messages to customers and, where customers route outreach through Torbi's relay, to deliver authenticated email on the customer's domain.

ProviderPurposeLocationCertifications
Postmark (ActiveCampaign)Transactional email (receipts, alerts, password resets)USSOC 2
Twilio SendGridCustomer-domain outreach relay (opt-in)US · EUSOC 2 Type IIGDPR
TwilioSMS & WhatsApp Business for opt-in 2FAUSSOC 2 Type IIGDPR

Payments & billing

Card data is tokenised by these providers — Torbi never receives or stores raw card numbers.

ProviderPurposeLocationCertifications
StripeCard & SEPA payment processing (USD, EUR, GBP, etc.)US · IEPCI DSS L1SOC 2 Type II
RazorpayCard, UPI, NetBanking payments (INR)IndiaPCI DSS L1ISO 27001
Zoho BooksInvoicing, tax records, GST filing (India)IndiaSOC 2 Type IIISO 27001

Customer support & product analytics

Internal tooling that touches customer account metadata. None of these process Prospect Data.

ProviderPurposeLocationCertifications
IntercomIn-product help chat and customer messagingUS · EU (Dublin)SOC 2 Type IIGDPR
LinearBug & feedback tracking (issues created from support)USSOC 2 Type II
PostHog (Cloud EU)First-party product analytics & session replay (opt-in)eu-central-1 (Frankfurt)SOC 2 Type IIGDPR
DatadogApplication logging & performance monitoringeu-west-1 (Ireland)SOC 2 Type IIISO 27001
SentryError reporting (scrubbed of PII at capture)USSOC 2 Type II

Data Partners — independent controllers

These are not our subprocessors. They are independent third-party services we license data from. Each one is the controller of the data it supplies to Torbi, operates under its own published privacy policy and lawful basis, and runs its own opt-out path. Torbi orchestrates queries through them — it does not maintain its own scraped contact database.

Why this distinction matters. Under GDPR Article 28, a "subprocessor" processes personal data on our instructions, on our behalf. The companies below do not. They collected the data under their own programmes, hold it as their own controllers, and supply records to us in response to queries. If you want a record they hold removed, the most effective route is to use their opt-out — we will also propagate the suppression on our end (see Privacy Policy §11).

Data PartnerWhat they supplyHQOpt-out / privacy
Apollo.ioB2B contact records (work email, phone, title, employer, LinkedIn URL where supplied)USapollo.io/privacy
apollo.io/opt-out
Clearbit (HubSpot)Company firmographics, technographic enrichmentUSclearbit.com/privacy
HubSpot Trust Center
Hunter.ioEmail-pattern discovery and verificationFrance · EUhunter.io/privacy
hunter.io/claim
LeadMagicEmail verification, work-email finder fallbackUSleadmagic.io/privacy
OpenCorporatesGlobal company-registry records (public data)UKopencorporates.com/info/legal
BuiltWithPublic technology-stack detection on company websitesAustralia · USbuiltwith.com/privacy

What Torbi does not access or hold

  • LinkedIn, Facebook, Instagram, X/Twitter, Reddit, TikTok — Torbi has no direct data-sharing or scraping relationship with any social network. Where a Data Partner above provides a LinkedIn (or similar) profile URL alongside a record, that URL is a deep-link to the platform; clicking it takes you to the platform under the platform's own terms.
  • Consumer datasets — Torbi does not buy, license, or integrate consumer-grade data (voter rolls, marketing lists, demographic profiles, location pings).
  • Credentialed actions on third-party services — Torbi does not log into LinkedIn or any other service on your behalf using stored credentials, and does not run scripted browser sessions ("phantoms") under user credentials.

Get notified of subprocessor changes

We give at least 30 days' notice before adding or replacing a subprocessor. Subscribe with a work email to receive change alerts — useful for procurement and compliance teams.

Changelog

15 May 2026
Initial public publication of subprocessor list.
08 May 2026
Added PostHog (Cloud EU) for first-party product analytics, replacing prior client-side analytics. Notice issued to active customers.
22 Apr 2026
Removed Mixpanel — replaced by PostHog (EU). Customer data migrated and deleted from Mixpanel within 30 days.
10 Mar 2026
Updated AWS region scope to include eu-west-1 (Ireland) for EU customers requesting EU-resident processing.