Legal
Authorized Subprocessor List
This document lists the subprocessors authorized by 37Arc, Inc. ("37Arc") to process Personal Data on behalf of Customers pursuant to the Data Processing Exhibit ("DPA") and applicable data protection laws.
Last updated July 22, 2026 · Version 1.1
Notifications
Get advance notice of subprocessor changes
We email subscribers before a new subprocessor begins processing Customer Data. Operational notices only — never marketing — and you can unsubscribe at any time.
1. About this list
1.1 Purpose. This list is provided to fulfill 37Arc's obligations under DPA Section 4.4(c) and Annex 3, and to enable Customers to assess our data processing arrangements.
1.2 Updates. 37Arc may update this list as subprocessors are added or removed. Customers subscribed to notifications will receive advance notice as specified in the DPA. The current version is always published at https://www.37arc.com/subprocessors and available upon request to privacy@37arc.com.
1.3 Notification. To receive advance notice of subprocessor changes, subscribe at https://www.37arc.com/subprocessors, or contact privacy@37arc.com with the subject line "Subprocessor Notification Subscription."
2. Authorized subprocessors
2.1 AI and Infrastructure Subprocessors
Each subprocessor is listed once by contracting entity, with all in-scope services for that entity shown in a single row.
Scroll horizontally to view all columns →
| Subprocessor Name | Service/Function | Location(s) | Data Processed |
|---|---|---|---|
| Google LLC | Cloud hosting, storage, compute, and database services (Google Cloud Platform); AI model inference and embeddings (Vertex AI); business email (Google Workspace) | US (primary), with regional options available | Customer Data, application data, usage logs; prompts and content for AI processing; email content |
| OpenAI, LLC | AI model inference, including realtime voice and transcription | US | Prompts and content for AI processing; audio for transcription |
| Anthropic, PBC | AI model inference | US | Prompts and content for AI processing |
| Amazon Web Services, Inc. | AI model inference (Amazon Bedrock, fallback routing) | US | Prompts and content for AI processing |
2.2 Operational Subprocessors
Scroll horizontally to view all columns →
| Subprocessor Name | Service/Function | Location(s) | Data Processed |
|---|---|---|---|
| Okta, Inc. (Auth0) | Authentication and identity management for Customer access | US | Customer-user names, email addresses, credentials, authentication tokens |
| Salesforce, Inc. (Slack) | Customer engagement communications and notifications | US | Communications content, contact details, engagement metadata |
| Twilio Inc. (SendGrid) | Transactional email delivery | US | Email content, recipient addresses |
| Functional Software, Inc. (Sentry) | Error tracking, application monitoring, performance telemetry | US | Application errors, stack traces, performance metrics, limited user identifiers |
| Hyperdoc Inc. (Recall.ai) | Meeting bot, recording, and transcription services | US | Meeting URLs and metadata; participant names and email addresses; meeting chat messages; audio, video, recordings, and transcripts |
2.3 AI Provider Requirements
For Customer Data that 37Arc submits directly to AI model APIs, 37Arc requires enterprise/API tiers that do not train, fine-tune, or develop models on Customer Data and routing only through the services below with zero-data-retention controls enabled. Specialized processing by other authorized subprocessors in Sections 2.1 and 2.2 is governed by Section 4 and the applicable service descriptions.
Scroll horizontally to view all columns →
| Provider | AI Service | No Training | Zero Data Retention |
|---|---|---|---|
| OpenAI, LLC | OpenAI API (including realtime voice and transcription) | Required | Required |
| Anthropic, PBC | Anthropic API | Required | Required |
| Google LLC | Vertex AI only | Required | Required |
| Amazon Web Services, Inc. | Amazon Bedrock only | Required | Required |
Inclusion in this table does not by itself establish that a route is active or that the required controls have been verified. 37Arc may route Customer Data to a listed service only after documenting that both requirements are satisfied for the relevant provider account or project and route configuration.
These requirements are scoped to the provider services listed in this table. The direct Google Gemini API (Google AI Studio) is not an approved service in this list and may not be used for Customer Data unless and until it is added to the table after 37Arc has documented paid-service no-training terms, project-level zero-data-retention approval, and route controls that avoid retention-causing features.
3. Categories of processing
The subprocessors listed above may process Customer Data in the following ways, depending on the Services:
- Hosting and Storage: Storing Customer Data in secure cloud infrastructure
- Processing and Computation: Running applications, queries, and AI/ML inference workloads
- Authentication and Identity: Verifying Customer-user identity and controlling access to the Services
- Communications: Delivering engagement communications, notifications, and transactional email
- Meeting Capture and Transcription: Recording and transcribing Customer-authorized calls and meetings
- Monitoring: Error tracking, performance monitoring, and debugging telemetry
4. Data protection measures
4.1 Contractual Protections. 37Arc requires written agreements with each subprocessor that include:
- Data protection obligations at least as protective as those in the DPA
- Confidentiality requirements
- Security measures appropriate to the nature of processing
- Use limitations (processing only for specified purposes)
- Data deletion or return upon termination
4.2 International Transfers. Where subprocessors are located outside the EEA, the UK, or Switzerland, 37Arc requires appropriate transfer mechanisms to be in place, such as:
- Standard Contractual Clauses (SCCs)
- EU-US Data Privacy Framework certification (where applicable)
- Other legally recognized transfer mechanisms
4.3 Assessment. 37Arc requires due diligence on subprocessors prior to engagement and periodic review of their data protection practices.
5. Customer objection rights
5.1 As described in the DPA, Customers may object to a new subprocessor by providing written notice within the timeframe specified in the DPA (typically 15-30 days from notification).
5.2 If 37Arc is unable to address Customer's reasonable objection and cannot provide the Services without using the subprocessor, Customer may terminate the affected Services as described in the DPA.
6. Contact
- Email: privacy@37arc.com
- Subject: "Subprocessor Inquiry"
7. Revision history
Scroll horizontally to view all columns →
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 15, 2026 | Initial publication |
| 1.1 | July 22, 2026 | Added AWS, Auth0, Slack, SendGrid, and Recall.ai; expanded Google; restated AI and data-protection requirements |