Subprocessors

Short version: Below is the working list of third-party services that may process client data when we deliver work, grouped by purpose. Not every service is used on every engagement — the applicable set is confirmed in your DPA schedule. Engaged clients get 30 days’ notice before we add a new subprocessor with access to their personal data.

List current as of 11 August 2026. Ask us for the version applicable to your contract.

Advertising and media platforms

  • Google (Google Ads, Google Analytics, Google Tag Manager, Merchant Center, Search Console) — campaign delivery, measurement, and tag management. Not BAA-covered; excluded from PHI processing.
  • Meta Platforms (Facebook and Instagram ads) — paid social delivery and measurement. Not BAA-covered; excluded from PHI processing.
  • TikTok, Snap, LinkedIn, Microsoft Advertising — paid delivery where the engagement includes those channels.

Websites, hosting and delivery

  • Webflow — CMS and hosting for sites we build on it, including webtonic.io.
  • Cloudflare — DNS, CDN, and edge security for domains under our management.
  • Cloudways / managed WordPress hosting — hosting for WordPress client properties.
  • Shopify — where the engagement includes a Shopify storefront.

Collaboration, storage and project delivery

  • Google Workspace — email, documents, and file storage for deliverables.
  • Slack — internal and client communication. Not used for credentials or regulated data.
  • Teamwork — project and task management.
  • Notion and Airtable — internal documentation and structured working data.
  • Shade — digital asset management and creative approval.

Analytics, SEO and reporting

  • Ahrefs, Semrush, DataForSEO — keyword, backlink and SERP data. Public web data; no client personal data supplied.
  • AgencyAnalytics — client reporting dashboards.
  • CallRail — call tracking where the engagement includes it. Call recordings are configured off or restricted on regulated accounts.

CRM, marketing automation and social publishing

  • GoHighLevel — CRM, pipeline and marketing automation for engagements that use it.
  • Brevo — email delivery where we run campaigns.
  • Vista Social and Metricool — social scheduling, publishing and analytics.

Business operations

  • Zoho (Books, CRM) — invoicing and internal commercial records.
  • Stripe and PayPal — payment processing for client invoices. Card data is handled by the processor; we never store it.
  • Calendly — meeting scheduling.

AI and automation

  • OpenAI and Anthropic — research, drafting and analysis under business terms that exclude training on our inputs. Client personal data and PHI are excluded from these tools.

Our obligations to you

  • Written data protection terms with every subprocessor before access.
  • 30 days’ notice before adding a subprocessor that will process your personal data, with a right to object.
  • Purpose limitation — a subprocessor is used only for the function listed above.
  • Removal on request where the function is not essential to the service you bought.

Questions we get about this list

What is a subprocessor?

A third-party service we engage that may process personal data on a client’s behalf while we deliver the work — the ad platforms we buy media on, the storage where deliverables live, the project system where work is tracked. Under GDPR Article 28 we must have the controller’s authorization to use them and must impose equivalent data protection obligations on each one.

Will you notify us before adding one?

Yes. Engaged clients receive at least 30 days’ notice before a new subprocessor with access to their personal data is added, with a right to object. Emergency substitutions for continuity are notified as soon as practicable.

Is every subprocessor used on every engagement?

No. The actual set depends on the services you buy. An SEO-only engagement never touches ad platforms; a paid media engagement never touches your CMS. We will confirm the applicable list for your scope in the DPA schedule.

Are any of these covered by a BAA for PHI?

The major advertising platforms will not sign a BAA for standard ad products, which is exactly why our healthcare architecture keeps protected health information out of them. Where an engagement requires PHI processing, we confirm in writing which specific systems are BAA-covered before any data moves, and no others are used.

Need the contract version?

Request the subprocessor schedule that attaches to your DPA at [email protected]. Related: Trust & Compliance · HIPAA & healthcare data · Security program · Data processing & GDPR.