Subprocessors
QNOPY engages select third-party service providers (“subprocessors”) to support the delivery, operation, security, and maintenance of our services. These subprocessors may process customer data on QNOPY’s behalf only to the extent necessary to provide their contracted services.
​
QNOPY maintains a vendor management process designed to evaluate the security, privacy, and operational practices of subprocessors prior to engagement and on an ongoing basis, as appropriate. Subprocessors that handle customer data are subject to contractual confidentiality, data protection, and security obligations consistent with the nature of the services they provide.
​
The table below identifies QNOPY’s current subprocessors, their purpose, and the applicable data processing or hosting location.
​
QNOPY may add or replace subprocessors as our services evolve. We maintain this page as our current list of subprocessors and will update it when material changes occur.
Sub-Processor | Service | Location | Data Processed |
|---|---|---|---|
Strikegraph | SOC 2 compliance management and audit evidence | United States | QNOPY internal compliance data only; no Customer Personal Data |
Anthropic | AI language model API (used in QNOPY platform features) | United States | Customer Data (non-personal field data processed via API) |
OpenAI | AI language model API (used in QNOPY platform features) | United States | Customer Data (non-personal field data processed via API) |
Loops | Marketing email delivery | United States | Customer Personal Data (name, email address) |
Mailchimp / Mandrill | Marketing and transactional email delivery | United States | Customer Personal Data (name, email address) |
SendGrid | Transactional email delivery | United States | Customer Personal Data (name, email address) |
Zendesk | Customer support ticketing | United States | Customer Personal Data (name, email, support content) |
Microsoft 365 | Email (Outlook), communication (Teams), file storage (OneDrive, SharePoint) | United States | Customer Personal Data (limited, for support purposes) |
GitHub | Source code version control and repository management | United States | Source code only; no Customer Personal Data |
Amazon Web Services (AWS) | Cloud infrastructure: compute (EC2), database (RDS), object storage (S3), monitoring, audit logging, vulnerability scanning | United States | Customer Personal Data and Customer Data |
