Sub-processors

Last updated: 25 August 2026

Wytness uses the following categories of third-party sub-processors to deliver the Service. In accordance with our Data Processing Agreement, we will notify customers at least 30 days before engaging any new sub-processor. Each sub-processor receives only the minimum data required for its function.

Microsoft Azure

PurposeApplication hosting, compute, database, blob storage, key management, operational telemetry (Log Analytics, Application Insights)DataAll platform data including account information, audit event metadata, and event payloads stored in shared infrastructureLocationAudit event payloads are homed in Australia East (Sydney). Business and Enterprise customers may request an alternative data region; requests are fulfilled by our support team subject to regional availability. Customer account and database (control-plane) storage is in Australia East (Sydney); customer-hosted storage is configurable on the Business plan. The dashboard and marketing web front-ends are served as static assets from the cloud provider's closest available region (currently East Asia, as the static-hosting service does not yet offer an Australia region); these static-asset surfaces do not store audit event data or organisation records.

Cloudflare

PurposeDomain name resolution, edge firewall, DDoS protection, TLS termination, and rate limitingDataIP addresses and request metadata; no audit event payloadsLocationGlobal edge network

Stripe

PurposeSubscription billing, payment processing, and invoice generation for direct subscriptionsDataBilling contact name, email, payment method tokens, invoice historyLocationUnited States, European Economic Area

Microsoft Commercial Marketplace

PurposeSubscription billing and entitlement for customers procuring through the Microsoft cloud marketplaceDataMarketplace tenant identifier, subscription identifier, billing statusLocationPer Microsoft Marketplace's published regions

AWS Marketplace

PurposeSubscription billing and entitlement for customers procuring through the AWS cloud marketplaceDataMarketplace tenant identifier, subscription identifier, billing statusLocationPer AWS Marketplace's published regions

Resend

PurposeDelivery of account verification codes, password resets, billing notices, and security alertsDataRecipient email address, message contentLocationUnited States

GitHub

PurposeSource code repository hosting and continuous-integration/continuous-deployment workflow execution for the ServiceDataOperator account identifiers, commit metadata, CI run logs; no customer audit data, no event payloads, no end-user PIILocationUnited States, global edge

Anthropic

PurposeLLM provider for internal marketing-CI tasks (drafting posts and changelogs from repository files); no customer audit data passes throughDataRepository content used to draft marketing material; no customer audit data, no end-user PIILocationUnited States

Customer-Hosted Storage (Business Plan)

Customers on the Business plan with customer-hosted storage configured run the audit storage layer in their own cloud tenancy. That storage is operated by the customer and is not a Wytness sub-processor. Wytness signs, verifies, and reports on the events but does not retain a copy of the audit content in shared infrastructure.

Data Minimisation

Audit event payloads are stored only by Microsoft Azure (or, on the Business plan with customer-hosted storage, in the customer's own tenancy). Stripe receives only billing data. Resend receives only the recipient address and message content needed to deliver the email. Cloudflare, GitHub, and the marketplace billing providers do not receive event payloads. Cryptographic signing keys are never shared with any sub-processor; they remain exclusively in your environment.

How Obligations Flow Down to Sub-Processors

Under our Data Processing Agreement and Article 28(4) of the GDPR, we are required to flow our processor obligations down to each sub-processor. The mechanism varies by sub-processor:

  • Direct contractual flow-down: every sub-processor in the list above has a Data Processing Agreement in force with us that incorporates equivalent obligations to those we owe you (security, breach notification, sub-processing controls, deletion or return on termination). Where the sub-processor is established outside Australia or the EEA, Standard Contractual Clauses (or equivalent transfer mechanism) are also in force.
  • Programmatic erasure: where the sub-processor exposes an erasure API (currently: Stripe), our retention reaper invokes it when an organisation is hard-deleted, so the deletion cascade reaches the sub-processor automatically.
  • Log retention policy only: for sub-processors that do not expose a programmatic erasure surface (currently: Cloudflare, GitHub, Resend, and the Microsoft and AWS marketplace billing providers), we rely on the sub-processor's own published log retention policy. Where this applies, the sub-processor receives metadata only (IP addresses, request paths, account identifiers, billing tokens) and never receives audit event payloads.
  • Customer-controlled: on the Business plan with customer-hosted storage, audit content stays in your own cloud tenancy. Your tenancy is not a Wytness sub-processor; we sign and report on the events but do not retain a copy.

We document the flow-down mechanism for each sub-processor in our internal privacy inventory and re-review it on every release that touches sub-processors. If you would like a copy of the specific contractual terms for a sub-processor, contact support.

Subscribe to Change Notifications

To receive email notifications when this list changes, send a message with the subject "Sub-processor updates" to support@wytness.ai from the email address you would like added. We will provide at least 30 days' notice before adding or replacing a sub-processor. If you have concerns about a new sub-processor, you may object during the notice period as set out in the DPA.

Change Log

25 August 2026Legal-pack review sweep across Terms, Privacy, and DPA (no sub-processor changes): corrected the backup-retention disclosure (Postgres point-in-time recovery images age out over 35 days, not 5; storage soft-delete recovery copies 14 days) on Privacy §6/§13 and DPA §11; corrected cookie wording to 'no cookies — essential first-party browser storage only' on the banner and Privacy §8; Terms updated from Public Beta to the launched service, aligned §14 to the subscription-term retention + signed Evidence Pack handover model, and gained an Australian Consumer Law non-exclusion clause; DPA gained the GDPR Article 28(4) sub-processor flow-down clause and accurate rate-limiting wording; Privacy §10 and the GDPR compliance page gained an Article 22 (automated decision-making) position; DSAR wording now describes both the immediate capped export and the complete background export. No new sub-processors added; no changes to scope of data processing.
8 August 2026Withdrew UAE North (Dubai) as an available data region: the region announced on 25 July 2026 has been decommissioned and is not currently offered. All audit event payloads are hosted in Australia East (Sydney). Business and Enterprise customers may request an alternative data region via support, fulfilled subject to regional availability. Corrected the Microsoft Azure location disclosure accordingly. No new sub-processors added; no changes to scope of data processing.
25 July 2026Added UAE North (Dubai) as an available data region for audit event payloads (Business and Enterprise plans; selectable at signup or moved on request via support). Removed 'event streaming' from the Microsoft Azure purpose: the event-streaming component was retired from the platform architecture and ingestion now writes directly to the audit store. Customer account and control-plane database storage remains in Australia East (Sydney). No new sub-processors added; no changes to scope of data processing.
14 June 2026Body content audit and date alignment.
12 June 2026Rewording for clearer customer-facing terminology: replaced 'shared-tenancy customers' with 'Wytness-hosted customers' on the Microsoft Azure data-residency disclosure and on the Privacy Policy primary-processing-region paragraph. No change in scope, region, or processing activity; no new sub-processors added.
2 June 2026Added ABN 16 685 892 513 to the Providence Tech Pty Ltd entity disclosure on Terms, Privacy, DPA, and the marketing footer for Australian-buyer due diligence. Aligned the Privacy Policy erasure paragraph (§13) to the three-mechanism flow-down language used here (programmatic erasure / suppression-list reliance / log-retention rollover) and clarified the platform audit log retention basis (GDPR Article 17(3)(b)) and usage-telemetry retention (aggregate counts, no personal identifiers). No new sub-processors added; no changes to scope of data processing.
27 May 2026Em-dash purge across legal pages copy. No new sub-processors added; no changes to scope of data processing.
25 May 2026Replaced anonymised sub-processor categories with the named vendors that actually receive data: Microsoft Azure, Cloudflare, Stripe, Microsoft Commercial Marketplace, AWS Marketplace, Resend, GitHub, and Anthropic (internal marketing-CI only). Removed the previously listed 'Application Performance Monitoring Provider' category as we do not deploy a separate APM vendor. Operational telemetry runs on Azure Log Analytics and Application Insights, subsumed under Microsoft Azure. No new sub-processors added; no changes to scope of data processing.
20 May 2026Added 'How Obligations Flow Down to Sub-Processors' section explaining the four mechanisms by which our processor obligations cascade to each sub-processor: direct contractual flow-down (every sub-processor), programmatic erasure (where APIs exist), log retention policy only (where they don't), and customer-controlled (Business-plan customer-hosted storage). No new sub-processors added; no changes to scope of data processing.
19 May 2026Added Source Control and CI/CD Provider as a disclosed sub-processor category (operator account identifiers, commit metadata, CI run logs; no customer audit data or event payloads). Clarified Cloud Infrastructure Provider entry to distinguish audit-data residency (Australia East) from static-asset hosting region (currently East Asia for the dashboard and marketing front-ends, as the static-hosting service does not yet offer an Australia region).
10 May 2026Documented sub-processor patch & CVE policy (24h response window on critical CVSS ≥ 9.0 advisories) and a change-notification mechanism (in-app notification to every org owner with a 30-day effective-date window per Section 8 of the DPA). Internal operational reference: docs/sub-processor-patch-policy.md.
5 May 2026Pinned shared-tenancy processing region to Australia East (Sydney). Added entity disclosure: Wytness is a registered business name of Providence Tech Pty Ltd.
2 May 2026Added Cloud Marketplace Billing Partners and Application Performance Monitoring Provider categories. Generalised Cloud Infrastructure Provider description to reflect dual storage models. (Application Performance Monitoring Provider category removed 25 May 2026 — no separate APM vendor is deployed; operational telemetry runs on Azure Log Analytics and Application Insights, subsumed under Microsoft Azure.)
24 April 2026Initial publication.

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy