Legal

Authorized Subprocessor List

This document lists the subprocessors authorized by 37Arc, Inc. ("37Arc") to process Personal Data on behalf of Customers pursuant to the Data Processing Exhibit ("DPA") and applicable data protection laws.

Last updated July 22, 2026 · Version 1.1

Notifications

Get advance notice of subprocessor changes

We email subscribers before a new subprocessor begins processing Customer Data. Operational notices only — never marketing — and you can unsubscribe at any time.

Double opt-in: your subscription starts after you confirm via email.

1. About this list

1.1 Purpose. This list is provided to fulfill 37Arc's obligations under DPA Section 4.4(c) and Annex 3, and to enable Customers to assess our data processing arrangements.

1.2 Updates. 37Arc may update this list as subprocessors are added or removed. Customers subscribed to notifications will receive advance notice as specified in the DPA. The current version is always published at https://www.37arc.com/subprocessors and available upon request to privacy@37arc.com.

1.3 Notification. To receive advance notice of subprocessor changes, subscribe at https://www.37arc.com/subprocessors, or contact privacy@37arc.com with the subject line "Subprocessor Notification Subscription."

2. Authorized subprocessors

2.1 AI and Infrastructure Subprocessors

Each subprocessor is listed once by contracting entity, with all in-scope services for that entity shown in a single row.

Scroll horizontally to view all columns →

AI and Infrastructure Subprocessors
Subprocessor NameService/FunctionLocation(s)Data Processed
Google LLCCloud hosting, storage, compute, and database services (Google Cloud Platform); AI model inference and embeddings (Vertex AI); business email (Google Workspace)US (primary), with regional options availableCustomer Data, application data, usage logs; prompts and content for AI processing; email content
OpenAI, LLCAI model inference, including realtime voice and transcriptionUSPrompts and content for AI processing; audio for transcription
Anthropic, PBCAI model inferenceUSPrompts and content for AI processing
Amazon Web Services, Inc.AI model inference (Amazon Bedrock, fallback routing)USPrompts and content for AI processing

2.2 Operational Subprocessors

Scroll horizontally to view all columns →

Operational Subprocessors
Subprocessor NameService/FunctionLocation(s)Data Processed
Okta, Inc. (Auth0)Authentication and identity management for Customer accessUSCustomer-user names, email addresses, credentials, authentication tokens
Salesforce, Inc. (Slack)Customer engagement communications and notificationsUSCommunications content, contact details, engagement metadata
Twilio Inc. (SendGrid)Transactional email deliveryUSEmail content, recipient addresses
Functional Software, Inc. (Sentry)Error tracking, application monitoring, performance telemetryUSApplication errors, stack traces, performance metrics, limited user identifiers
Hyperdoc Inc. (Recall.ai)Meeting bot, recording, and transcription servicesUSMeeting URLs and metadata; participant names and email addresses; meeting chat messages; audio, video, recordings, and transcripts

2.3 AI Provider Requirements

For Customer Data that 37Arc submits directly to AI model APIs, 37Arc requires enterprise/API tiers that do not train, fine-tune, or develop models on Customer Data and routing only through the services below with zero-data-retention controls enabled. Specialized processing by other authorized subprocessors in Sections 2.1 and 2.2 is governed by Section 4 and the applicable service descriptions.

Scroll horizontally to view all columns →

AI Provider Requirements
ProviderAI ServiceNo TrainingZero Data Retention
OpenAI, LLCOpenAI API (including realtime voice and transcription)RequiredRequired
Anthropic, PBCAnthropic APIRequiredRequired
Google LLCVertex AI onlyRequiredRequired
Amazon Web Services, Inc.Amazon Bedrock onlyRequiredRequired

Inclusion in this table does not by itself establish that a route is active or that the required controls have been verified. 37Arc may route Customer Data to a listed service only after documenting that both requirements are satisfied for the relevant provider account or project and route configuration.

These requirements are scoped to the provider services listed in this table. The direct Google Gemini API (Google AI Studio) is not an approved service in this list and may not be used for Customer Data unless and until it is added to the table after 37Arc has documented paid-service no-training terms, project-level zero-data-retention approval, and route controls that avoid retention-causing features.

3. Categories of processing

The subprocessors listed above may process Customer Data in the following ways, depending on the Services:

  • Hosting and Storage: Storing Customer Data in secure cloud infrastructure
  • Processing and Computation: Running applications, queries, and AI/ML inference workloads
  • Authentication and Identity: Verifying Customer-user identity and controlling access to the Services
  • Communications: Delivering engagement communications, notifications, and transactional email
  • Meeting Capture and Transcription: Recording and transcribing Customer-authorized calls and meetings
  • Monitoring: Error tracking, performance monitoring, and debugging telemetry

4. Data protection measures

4.1 Contractual Protections. 37Arc requires written agreements with each subprocessor that include:

  • Data protection obligations at least as protective as those in the DPA
  • Confidentiality requirements
  • Security measures appropriate to the nature of processing
  • Use limitations (processing only for specified purposes)
  • Data deletion or return upon termination

4.2 International Transfers. Where subprocessors are located outside the EEA, the UK, or Switzerland, 37Arc requires appropriate transfer mechanisms to be in place, such as:

  • Standard Contractual Clauses (SCCs)
  • EU-US Data Privacy Framework certification (where applicable)
  • Other legally recognized transfer mechanisms

4.3 Assessment. 37Arc requires due diligence on subprocessors prior to engagement and periodic review of their data protection practices.

5. Customer objection rights

5.1 As described in the DPA, Customers may object to a new subprocessor by providing written notice within the timeframe specified in the DPA (typically 15-30 days from notification).

5.2 If 37Arc is unable to address Customer's reasonable objection and cannot provide the Services without using the subprocessor, Customer may terminate the affected Services as described in the DPA.

6. Contact

7. Revision history

Scroll horizontally to view all columns →

Revision history
VersionDateChanges
1.0July 15, 2026Initial publication
1.1July 22, 2026Added AWS, Auth0, Slack, SendGrid, and Recall.ai; expanded Google; restated AI and data-protection requirements