Subprocessors

Effective: 10 May 2026 · Last updated: 10 May 2026

These third-party services process Proparion customer data on our behalf. Each is governed by a Data Processing Agreement and processes only the data needed for its specific purpose.

We give 30 days written notice via email + this page before adding any new subprocessor that processes customer content. To be notified, email hello@proparion.com with subject "Subprocessor notifications".

SubprocessorPurposeData accessedRegionCertifications
SupabasePostgres database, authentication, file storageAll customer content (proposals, RFPs, drafts, embeddings), account metadata, files, audit logsAP-South-1 (Mumbai, India)SOC 2 Type II, HIPAA-eligible, ISO 27001
VercelWeb hosting, edge functions, CDNRequest metadata (IP, headers, paths), no persistent customer contentGlobal edge; primary BOM1 (Mumbai) for Indian usersSOC 2 Type II, ISO 27001
OpenAILLM drafting, embeddings, extractionRFP question text + retrieved past-proposal chunks at draft timeUnited States (data may transit globally)SOC 2 Type II, CCPA/GDPR aligned. Enterprise zero-retention terms — we do not allow training on customer content.
InngestBackground job orchestration (deadline reminders, ingestion)Job metadata only — no document contentsUnited StatesSOC 2 Type II
Dodo PaymentsPayments (Merchant of Record for India + global)Customer billing email, name, billing address, payment instrument metadata. Card numbers held by Dodo only — never reach Proparion.India + globalPCI-DSS Level 1, ISO 27001
Google Workspace (Gmail SMTP)Transactional email delivery (welcome, drafts-ready, alerts)Recipient email + email bodyGlobalISO 27001, SOC 2/3, FedRAMP
Google Analytics 4Anonymised website usage analyticsIP-anonymised pageviews, screen size, browser, country, referrer. No proposal/RFP content. We honour Do-Not-Track signals.GlobalISO 27001
SentryApplication error tracking and performance monitoringServer + browser error stacks, request URL, user-agent, internal user/org ID hashes. We scrub raw request bodies; no proposal/RFP content is sent to Sentry.United States / European UnionSOC 2 Type II, ISO 27001
LlamaCloudPDF parsing for uploaded proposals (when enabled)Uploaded PDF/DOCX during parsing only. Documents deleted within 24 hours of parsing per LlamaCloud policy.United StatesSOC 2 Type II

Related policies