Sub-processors
Every third party that touches data
The complete list for the Quicklead application and for this website, with what each one receives, where it sits and what covers the transfer. Changes are notified 30 days in advance.
Application list: published 30 days’ change notice
Last reviewed September 2026
The application
Sub-processors for the Quicklead product
These process customer and prospect data. Where a row says the feature is optional, disabling the feature removes that sub-processor from your data flow.
| Provider | Purpose | Data it receives | Location | Transfer basis |
|---|---|---|---|---|
| DigitalOcean | Application hosting, managed MySQL and MongoDB, object storage | All customer and prospect data | United States | SCCs |
| OpenAI | AI message personalisation (GPT-3.5-turbo) and reply sentiment classification (GPT-4) | For personalisation: prospect name, headline, company, role, summary. For sentiment: the text of an inbound reply. Sent at generation time | United States | SCCs, no training on submitted data |
| OpenRouter | AI ICP scoring and LinkedIn post/comment intent classification (Llama 3.3 70B) | For scoring: prospect profile fields and the customer’s ICP description. For intent: the text of a public post or comment and the author’s headline | United States | SCCs |
| Stripe | Subscription billing and payment processing | Customer billing contact and payment metadata. Card data goes to Stripe directly and never touches Quicklead. | United States and EU | SCCs, PCI DSS Level 1 |
| Crisp | In-app support chat and help centre | Customer name, email, support conversation history | European Union (France) | Within the EEA |
| Pusher | Real-time in-app notifications | Account identifiers and event metadata, no prospect content | United States and EU | SCCs |
| Google Cloud / Workspace APIs | Sign in with Google, Google Sheets export, reCAPTCHA | Customer identity; exported rows where the customer enables Sheets export | United States and EU | SCCs |
| Webshare | Dedicated proxy IPs for cloud LinkedIn sessions | Session traffic in transit, TLS terminated at LinkedIn not at the proxy | Regional, matched to the customer’s country | SCCs |
| ProxyJet | Residential proxy IPs for cloud LinkedIn sessions | Session traffic in transit, TLS terminated at LinkedIn not at the proxy | Regional, matched to the customer’s country | SCCs |
| Meta (WhatsApp Business Cloud API) | WhatsApp channel, only where a customer enables it | Contact phone number and message content for that channel | United States and EU | SCCs |
The website
Sub-processors for quicklead.io
These serve the marketing site only and never receive customer or prospect data.
| Provider | Purpose | Data it receives | Location | When it runs |
|---|---|---|---|---|
| Cloudflare | CDN, DDoS protection and bot management for quicklead.io | Visitor IP and request metadata | Global | Necessary |
| DigitalOcean | Hosting for the marketing website | Server logs | Regional data centre | Necessary |
| Google (Analytics 4, Ads, Tag Manager) | Website analytics and campaign measurement | Consented analytics identifiers | United States and EU | Only with consent |
| Calendly | Demo booking, opens in a new tab | Name, email, meeting details | United States | When you book |
| YouTube (privacy-enhanced) | Product videos, loaded only on play | Playback request data | United States and EU | When you play a video |
| ipwho.is | Country lookup on the pricing page to select currency | Visitor IP, not stored | European Union | Necessary, no cookie |
Change control
How this list changes
Every new vendor is security-reviewed before it processes any data
A written data processing agreement is in place with each sub-processor
Customers on a signed DPA get 30 days’ notice before a new sub-processor starts
You may object on reasonable data protection grounds, and terminate the affected service without penalty if we cannot resolve it
This page is the authoritative list and is dated at the top
Subscribe
Get notified of changes
Email us and we will add your security or privacy contact to the sub-processor change notification list. No marketing goes to that address.
FAQ
Sub-processor questions
Yes. Customers with a signed DPA get at least 30 days’ notice by email before a new sub-processor starts processing, and may object on reasonable data protection grounds. If we cannot resolve the objection you may terminate the affected service without penalty.
No. Prompts are sent to the AI sub-processor to generate one output and are not contributed to model training, for us or for anyone else.
They route the connection between our cloud session and LinkedIn. The session is TLS-encrypted end to end and terminates at LinkedIn, not at the proxy, so the provider sees connection metadata rather than message content.
Partly. Hosting and billing are structural. The AI features, the WhatsApp channel and the Sheets export are optional and can be disabled for your workspace, which removes those sub-processors from your data flow entirely.