Back to Home

Sub-processors

Service providers acting on our instructions under written data protection terms.

Last updated: 16 May 2026

The processors below act under our instructions and under written data-protection terms. "Scope" indicates whether the processor handles the desktop app, the marketing site, or both.

Auth0 / Okta

app + landing

Authentication and identity management

Data: Email, user ID, access tokens

Location: United States

Transfer mechanism: EU-US Data Privacy Framework (Okta certified) and SCCs Module 2

DPA / Privacy terms

Stripe

app + landing checkout flow

Billing, subscription management, and fraud prevention

Data: Email, limited billing details, transaction IDs

Location: United States

Transfer mechanism: SCCs Module 2 (and DPF where certified)

DPA / Privacy terms

OpenAI

app

LLM inference for AI sorting, entity extraction, and chat

Data: Filenames, folder paths, prompts, and (only with content sorting enabled) extracted text

Location: United States

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Anthropic

Optional (BYOK)app

LLM inference when selected via Bring-Your-Own-Key

Data: Filenames, folder paths, prompts, and (only with content sorting enabled) extracted text

Location: United States

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Postmark

app

Transactional email delivery

Data: Email address, message content

Location: United States

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Sentry

app + landing

Error monitoring and crash diagnostics

Data: App version, platform, stack traces, error context, timestamps

Location: United States (with EU region available)

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Neon (Postgres hosting)

app

Managed Postgres for application data

Data: Account data, sorting metadata, classifier prompts (30-day window)

Location: United States (primary region)

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Google Cloud Run (compute)

app

Compute hosting for Sortio API services

Data: All service-side data processed by our API

Location: United States (us-east1)

Transfer mechanism: EU-US Data Privacy Framework (Google certified) and SCCs Module 2

DPA / Privacy terms

Cloudinary

If usedlanding

Media hosting and delivery (testimonials, marketing imagery)

Data: Uploaded media assets

Location: United States

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Microsoft Clarity

landing

Session analytics (clicks, scrolls, replays) on the marketing site

Data: Anonymized pointer events, page-render snapshots; loads only with analytics consent

Location: United States

Transfer mechanism: EU-US Data Privacy Framework (Microsoft certified) and SCCs Module 2

DPA / Privacy terms

Google Analytics 4

landing

Web analytics on the marketing site

Data: Page views, IP address (truncated), device and browser metadata; loads only with analytics consent

Location: United States

Transfer mechanism: EU-US Data Privacy Framework (Google certified) and SCCs Module 2

DPA / Privacy terms

Vercel

landing

Landing site hosting plus Analytics and Speed Insights

Data: Edge logs, page views, Core Web Vitals; analytics products load only with analytics consent

Location: United States (Edge presence worldwide)

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

Rewardful

landing + checkout

Affiliate referral tracking

Data: Referral codes, anonymized click identifiers; loads only with marketing consent

Location: United States

Transfer mechanism: SCCs Module 2

DPA / Privacy terms

International transfers. For transfers of EEA, Swiss, or UK personal data to the United States or other third countries, we rely on the EU-US Data Privacy Framework (and its UK and Swiss extensions) where the processor is certified, and Standard Contractual Clauses (Module 2, Controller to Processor) in all other cases, with supplementary measures described in our DPA.

Notification of changes. We give at least 30 days' notice before adding or replacing a sub-processor by updating this page. Subscribe to changes by emailing marcus@getsortio.com.

Questions about a specific processor or our data protection practices? Email marcus@getsortio.com.