Each sub-processor is bound by a written agreement that limits their use of Customer Data to providing services to Mavenly, requires industry-standard protections, and supports our commitments under our Privacy Policy and DPA.
"Sub-processor" is a legal term from GDPR Article 28: a third party engaged by Mavenly to process Customer Data on our behalf, on our customers' instructions. The list below includes every such provider, what they do, what data they receive, where the data is stored, and what attestations they hold.
Mavenly is the data controller for our own operational data (employee records, billing) and the data processor for Customer Data that nonprofits and foundations upload to the platform. Sub-processors operate one level deeper — they're sub-processors of the customer's data with respect to Mavenly's own processing role.
If you're an enterprise procurement team evaluating Mavenly, this page is the canonical reference. Anything contradicting what's stated here in marketing materials, sales calls, or other documents should be flagged to privacy@mavenly.ai.
The foundational providers that host the platform and power AI features. Customer Data flows through these providers continuously during normal operation.
The providers that handle billing, transactional email, and customer support. These receive limited Customer Data necessary for their specific function.
The providers that help us understand how the product is used and detect operational issues. We minimize the Customer Data sent to these tools and prefer self-hosted options where available.
Subscribe to receive an email at least 30 days before any new sub-processor begins processing Customer Data. You'll have time to review the change and object if needed, per Section 5 of our DPA.
Before engaging a new sub-processor, Mavenly evaluates the provider against documented criteria. The provider must:
When Mavenly engages a new sub-processor, customers receive written notice at least 30 days before the sub-processor begins processing Customer Data. Notice includes:
Customers who object to a new sub-processor on reasonable grounds may notify Mavenly within 30 days of the notice. We'll work in good faith to address the objection — typically by offering an alternative provider, additional safeguards, or operational accommodations. If no resolution is reached, the customer may terminate the affected portion of their service with a pro-rata refund of unused fees, as described in Section 11 of our Terms of Service.
Mavenly is pre-launch. The sub-processor list above represents the production stack at launch. As we scale, we may add sub-processors for capabilities like advanced search indexing, additional regions, or specialized AI infrastructure. Each addition will follow the 30-day notice and right-to-object process described above. Subscribe via the form above to be notified directly.
This list covers sub-processors that handle Customer Data. It does not include:
For questions about this list, sub-processor evaluations, or to request DPA execution, contact us through the appropriate channel below.