Sub-processors

    The third parties that process Customer Data on Mavenly's behalf.

    Each sub-processor is bound by a written agreement that limits their use of Customer Data to providing services to Mavenly, requires industry-standard protections, and supports our commitments under our Privacy Policy and DPA.

    Last updatedMay 1, 2026
    Version1.0
    Notice period30 days
    6
    Active sub-processors
    2
    Data regions
    100%
    Bound by written DPA
    30d
    Advance notice for changes
    How to read this page

    This is the complete list of sub-processors that handle Customer Data.

    "Sub-processor" is a legal term from GDPR Article 28: a third party engaged by Mavenly to process Customer Data on our behalf, on our customers' instructions. The list below includes every such provider, what they do, what data they receive, where the data is stored, and what attestations they hold.

    Mavenly is the data controller for our own operational data (employee records, billing) and the data processor for Customer Data that nonprofits and foundations upload to the platform. Sub-processors operate one level deeper — they're sub-processors of the customer's data with respect to Mavenly's own processing role.

    If you're an enterprise procurement team evaluating Mavenly, this page is the canonical reference. Anything contradicting what's stated here in marketing materials, sales calls, or other documents should be flagged to privacy@mavenly.ai.

    Category 01

    Infrastructure & AI inference.

    The foundational providers that host the platform and power AI features. Customer Data flows through these providers continuously during normal operation.

    Amazon Web Services, Inc.
    aws.amazon.com
    DPA →
    Cloud infrastructure hosting (compute, storage, database, networking, encryption services). The foundational layer on which Mavenly runs.
    All Customer DataLogsBackups
    US-East-1Primary · N. VirginiaUS-West-2DR · Oregon
    SOC 2ISO 27001FedRAMPHIPAA
    Anthropic, PBC
    anthropic.com
    DPA →
    AI model inference for Compose, Discover ranking, Reporter synthesis, and Evaluation analysis. Configured for zero data retention with contractual no-training commitment.
    AI promptsAI outputs
    United StatesNo data retention beyond inference
    SOC 2ZDR
    Category 02

    Business operations.

    The providers that handle billing, transactional email, and customer support. These receive limited Customer Data necessary for their specific function.

    Stripe, Inc.
    stripe.com
    DPA →
    Payment processing for subscription billing. Handles credit cards and ACH directly; Mavenly never stores or transmits raw payment credentials.
    Payment credentialsBilling addressesOrg names
    United StatesMulti-region · PCI Level 1
    PCI DSSSOC 2ISO 27001
    Postmark (ActiveCampaign LLC)
    postmarkapp.com
    DPA →
    Transactional email delivery — account verifications, password resets, system notifications, report-due reminders. Marketing email is handled separately.
    Email addressesNamesEmail content
    United StatesMulti-region
    SOC 2GDPR
    Plain Software, Inc.
    plain.com
    DPA →
    Customer support ticketing and communications. Handles inbound support requests and the conversation history with our success team.
    Support conversationsNamesOrg context
    United StatesEU residency on request
    SOC 2GDPR
    Category 03

    Product analytics & monitoring.

    The providers that help us understand how the product is used and detect operational issues. We minimize the Customer Data sent to these tools and prefer self-hosted options where available.

    PostHog Inc. (self-hosted)
    posthog.com
    DPA →
    Product analytics — feature usage patterns, performance metrics, error tracking. Self-hosted in our AWS account so Customer Data never leaves Mavenly's infrastructure boundary.
    Usage eventsPerformance metricsUser IDs (hashed)
    US-East-1Self-hosted in our VPC
    SOC 2
    Stay informed

    Get notified before we add a new sub-processor.

    Subscribe to receive an email at least 30 days before any new sub-processor begins processing Customer Data. You'll have time to review the change and object if needed, per Section 5 of our DPA.

    No marketing email. Notifications only when this list changes.
    Sub-processor policy

    How Mavenly evaluates and adds sub-processors.

    Selection criteria

    Before engaging a new sub-processor, Mavenly evaluates the provider against documented criteria. The provider must:

    • Hold an independent security attestation (SOC 2 Type II, ISO 27001, or equivalent)
    • Execute a written Data Processing Addendum that includes Standard Contractual Clauses for international transfers where applicable
    • Demonstrate operational capacity for breach notification within timelines compatible with our 72-hour customer commitment
    • Maintain encryption at rest and in transit at industry-standard levels
    • Implement role-based access controls with documented least-privilege practices
    • Hold sufficient operational maturity (typically 3+ years of operations, demonstrated incident-response history)

    Customer notification

    When Mavenly engages a new sub-processor, customers receive written notice at least 30 days before the sub-processor begins processing Customer Data. Notice includes:

    • Provider name and location
    • Specific purpose for which the sub-processor will be engaged
    • Data categories that will be processed
    • Independent attestations held by the provider
    • Effective date of engagement

    Right to object

    Customers who object to a new sub-processor on reasonable grounds may notify Mavenly within 30 days of the notice. We'll work in good faith to address the objection — typically by offering an alternative provider, additional safeguards, or operational accommodations. If no resolution is reached, the customer may terminate the affected portion of their service with a pro-rata refund of unused fees, as described in Section 11 of our Terms of Service.

    A pre-launch note

    Mavenly is pre-launch. The sub-processor list above represents the production stack at launch. As we scale, we may add sub-processors for capabilities like advanced search indexing, additional regions, or specialized AI infrastructure. Each addition will follow the 30-day notice and right-to-object process described above. Subscribe via the form above to be notified directly.

    What's not on this list

    This list covers sub-processors that handle Customer Data. It does not include:

    • Internal corporate vendors that don't touch Customer Data — payroll, accounting, HR systems, code repositories, productivity tools used by Mavenly employees for their own work.
    • Customer-configured integrations — when you connect Mavenly to your own Salesforce, HubSpot, or other systems, those are integrations under your control, not sub-processors of ours.
    • One-time consultants and auditors who may receive limited information under separate confidentiality agreements (e.g., the firm conducting our SOC 2 audit) but don't process Customer Data on a continuing basis.

    Contact

    For questions about this list, sub-processor evaluations, or to request DPA execution, contact us through the appropriate channel below.

    Privacy questions
    privacy@mavenly.ai
    For sub-processor questions, DPA review, or privacy-related concerns. We respond within 5 business days.
    Procurement & DPA
    enterprise@mavenly.ai
    For Institution and Foundation customers requiring custom DPA terms or SCC negotiation.
    Security inquiries
    security@mavenly.ai
    For sub-processor security questions, attestation requests, or incident-related concerns.