Introduction

SuperApp, Inc. and its subsidiaries (“SuperApp”) use subprocessors in providing SuperApp platform products and services (the “SuperApp Service” or “Services”).

What Is a Subprocessor?

A “Subprocessor” is a third-party data processor used by SuperApp while providing the Services to its customers. In some cases, a Subprocessor is a SuperApp subsidiary that receives or processes Customer Data. SuperApp may engage one or more Subprocessors from the lists below based on the customer’s location and the Services provided.

Customer DataThe meaning of “Customer Data” is governed by the applicable agreement between SuperApp and the customer, including any applicable Data Processing Addendum (“DPA”).

Process to Engage New Subprocessors

SuperApp customers may subscribe to receive notifications of new Subprocessors for each applicable SuperApp Service. SuperApp will provide at least 30 days’ notice by email before a new Subprocessor begins processing Customer Data.

Under the applicable agreement with a customer, the customer may have the right to object to the processing of its Personal Data by a new Subprocessor. Please refer to the applicable DPA for additional details.

To subscribe to email notifications for changes to SuperApp Subprocessors, email the following information to compliance@superapp.chat:

To change notification contact information, resubmit the request to compliance@superapp.chat with the subject line “Change in Contact Information.”

Subprocessors

The following entities may process Customer Data to provide the stated services. The location used may depend on customer configuration, deployment region, and the applicable Services.

Entity namePurposeProcessing locationsSecurity and compliance validations
Amazon Web Services, Inc.Cloud Service Provider; Cognitive ServicesUnited States, European Union, and United KingdomISO 9001, ISO 27001, ISO 27017, ISO 27018, SOC 1 / ISAE 3402, SOC 2, SOC 3, FISMA, DIACAP, FedRAMP, and PCI DSS Level 1.Additional details: AWS security and compliance
Google LLCCloud Service Provider; Cognitive ServicesUnited States, European Union, and United KingdomCloud Computing Compliance Controls Catalog (C5); CSA; GSMA SAS-SM; Higher Education Cloud Vendor Assessment Tool (HECVAT); ISO 9001:2015; ISO 22301:2019 and BS EN ISO 22301:2019; ISO 50001:2018; ISO/IEC 27001; ISO/IEC 27017; ISO/IEC 27018; ISO/IEC 27701; PCI 3DS Core Security Standard; PCI DSS; SOC 1; SOC 2; SOC 3; and VPAT (WCAG, U.S. Section 508, EN 301 549).Additional details: Google Cloud compliance
Microsoft CorporationCloud Service Provider; Cognitive ServicesUnited States, European Union, and United KingdomISO 20000, ISO 22301, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 9001, SOC 1, SOC 2 Type 2, and SOC 3.Additional details: Microsoft Azure compliance
OpenAI OpCo LLCCognitive ServicesUnited States and European UnionAdditional details: OpenAI API data usage policies
X.AI LLCCognitive ServicesUnited StatesSOC 2 Type II.Additional details: xAI security and compliance
Anthropic, PBCCognitive ServicesUnited StatesISO 27001:2022; ISO/IEC 42001:2023; SOC 2 Type I and Type II.Additional details: Anthropic certifications
Temporal Technologies, Inc.Workflow OrchestrationUnited StatesSOC 2 Type II; HIPAA; GDPR; CCPA/CPRA; and NIST Cybersecurity Framework.Additional details: Temporal Trust Center
ZendeskCustomer support ticketingUnited StatesISO 27001:2013, ISO 27018:2014, ISO 27701:2019, FedRAMP LI-SaaS, and SOC 2 Type 2.Additional details: Zendesk Trust Center
SendSafelySecurity data exchangeUnited StatesAdditional details: SendSafely security

SuperApp Affiliates

The following corporate affiliates may receive or process Customer Data in connection with the Services.

Entity nameEntity country
Instabase Technologies Canada, Inc.Canada
Instabase Technologies Germany GmbHGermany
Instabase India Private LimitedIndia
Instabase Singapore PTE, LTDSingapore
Instabase UK LimitedUnited Kingdom
QuestionsFor questions about this list or the notification process, contact compliance@superapp.chat.