Subprocessors

At Asanify, we are committed to transparency and privacy. Below is a list of our current subprocessors — third-party service providers who may process personal data on our behalf in connection with the delivery of our products and services.

Each subprocessor is bound by contractual obligations and security standards appropriate to the data it handles, and we assess them against the data protection requirements applicable under laws such as the GDPR, India’s DPDP Act, and SOC 2. Where a provider is engaged under its published standard terms rather than a negotiated data processing agreement, that is noted against its entry below.

Infrastructure & Hosting

Subprocessor Purpose Location Retention
Amazon Web Services (AWS) Cloud hosting (app, DB, media) Global As per internal retention policy
AWS S3 File and media storage Global 1 year after client contract termination

Communication & CRM

Subprocessor Purpose Location Retention
Intercom Customer support chat and ticketing USA Up to 10 years (email logs)
Customer.io Transactional and marketing emails USA Until opt-out or contract end
HubSpot CRM & marketing automation USA Until opt-out or request to delete

Billing & Invoicing

Subprocessor Purpose Location Retention
Zoho Billing Subscription management and invoicing India As per statutory limits

Analytics

Subprocessor Purpose Location Retention
Segment (Twilio) Event tracking and customer data pipeline USA 1 year
Mixpanel Product usage analytics EU 1 year
Microsoft Clarity Product and session analytics (heatmaps, session replay) USA 30 days to 13 months

Application Security

Subprocessor Purpose Location Retention
Talsec (Lynx SFT s.r.o., Czech Republic) Mobile app runtime self-protection (freeRASP SDK). Receives device and app integrity diagnostics from the Asanify mobile app: root/jailbreak, emulator, hooking-framework and tampering signals, device model, and an anonymous app-instance and device identifier. No HR, payroll, employee-record or contact data is sent. USA (AWS) Not published by the vendor

Talsec is engaged under its published freeRASP Fair Usage Policy rather than a negotiated DPA, and also uses the diagnostics it receives for its own product improvement and aggregated security research. It therefore acts as an independent recipient for those purposes, rather than solely as a processor acting on Asanify’s behalf.

AI & LLM Providers

Subprocessor Purpose Location Retention Notes
OpenAI (ChatGPT) AI-powered data enrichment and query automation USA 30 days* No training on client data; enterprise API used where applicable
Anthropic (Claude) AI-powered HR and onboarding assistance USA 30 days* Used for classification and task automation

*Retention may vary based on API configuration. We aim to use zero-data retention modes wherever feasible.

Outbound Sales & Prospecting

Subprocessor Purpose Location Retention
Apollo.io B2B prospect data sourcing (company & contact business data) USA Until opt-out; non-responders purged 3 years after last contact
Instantly.ai Cold-email sending & campaign management USA Until opt-out; non-responders purged 3 years after last contact
Hunter.io Business email discovery (fallback when no direct contact email) USA (EU SCCs) Until opt-out; non-responders purged 3 years after last contact

Compliance & Security

  • All subprocessors are evaluated regularly for their security and compliance practices.

  • Asanify enters into a Data Processing Agreement with equivalent obligations with each subprocessor that processes personal data on Asanify’s behalf. Providers listed under “Application Security” are engaged under their published standard terms and receive device-integrity diagnostics only, not customer or employee records.

  • If you would like to be notified of changes to our subprocessor list, please email: dpo@asanify.com

Last updated: 22 Aug 2026