erp.io
Pricing
Log inBook a demo
HomeTrustSubprocessors

Trust

Subprocessors

A subprocessor is a third party we engage that may process Customer Data on our behalf. This page lists them, states what each one does and where, and explains how customers are notified before a new one is added. Publishing it is a commitment rather than a courtesy — our Data Processing Addendum requires it.

Effective
August 18, 2026
Last updated
August 18, 2026
Entity
Nead, LLC (d/b/a DEV.co)

Contents

  1. 01What a subprocessor is, and what it is not
  2. 02Infrastructure subprocessors
  3. 03AI model subprocessors
  4. 04Business operations subprocessors
  5. 05How we assess a subprocessor
  6. 06Notification of changes and your right to object
  7. 07Questions and requests

Questions about this policy?

Nead, LLC (d/b/a DEV.co)
1425 Broadway 22689
Seattle, WA 98112
United States

[email protected]

01What a subprocessor is, and what it is not

Under Article 28 of the GDPR and comparable provisions of US state privacy law, a processor that engages another processor must do so under a written contract imposing equivalent obligations, and must tell the controller who those parties are.

In our case: you are the controller of Customer Data, Nead, LLC is the processor, and the parties listed below are subprocessors.

Not every vendor we use is a subprocessor. A vendor that never receives Customer Data — our accounting software, for instance, or the tool we use to write documentation — is not listed here, because listing it would pad the page without telling you anything about where your data goes.

02Infrastructure subprocessors

These parties host or transmit Customer Data as part of running the service.

SubprocessorPurposeData processedLocation
Amazon Web Services, Inc.Primary compute, database, object storage, and backupAll Customer Data, encrypted at rest and in transitUnited States (us-east-1, us-west-2)
Cloudflare, Inc.DNS, TLS termination, CDN, DDoS protection, WAFRequest metadata and content in transit; no persistent storage of Customer DataGlobal edge network
Twilio SendGridTransactional and notification email deliveryRecipient name and address, message content of notificationsUnited States

03AI model subprocessors

These parties receive content in order to generate an output for a feature you have enabled. They are listed separately because the questions customers ask about them differ from the questions they ask about hosting.

SubprocessorPurposeData processedLocation
Anthropic, PBCLanguage model inference for agents and copilot featuresContent submitted to those features — typically document text, transaction detail, and relevant contextUnited States

Contractual position with model providers

  • No training. Our agreement prohibits the use of content submitted through our service to train or fine-tune the provider’s models.
  • Zero or limited retention. Content is retained only as required for abuse monitoring under the terms of our enterprise agreement, and is not used for any other purpose.
  • No onward sharing. The provider may not disclose content to third parties except as required by law.

If you would rather no Customer Data reached an AI model provider, agent and copilot features can be disabled at the tenant level. The rest of the service continues to function without them.

04Business operations subprocessors

These parties may incidentally process personal data relating to your personnel — such as the name and email address of an account contact — in the course of supporting the commercial relationship. They do not receive Customer Data from the service.

SubprocessorPurposeData processedLocation
Google LLCBusiness email, calendaring, document storageCorrespondence and business recordsUnited States
Stripe, Inc.Payment processingBilling contact and transaction detail; card data handled by Stripe, never by usUnited States

05How we assess a subprocessor

Before engaging any subprocessor that will handle Customer Data, we assess:

  • its security posture, including available certifications and audit reports;
  • the terms it offers on data use, retention, and onward transfer, and whether they can be improved by negotiation;
  • the jurisdictions in which it will process data, and whether an appropriate transfer mechanism is available;
  • its incident notification commitments and how quickly it has performed against them historically; and
  • whether the function could reasonably be performed without introducing a third party at all.

The last question is the one we ask first. Every subprocessor is an additional party with access to something, and the smallest defensible list is better than a comprehensive one.

Each subprocessor is engaged under a written agreement imposing data protection obligations at least as protective as those we owe you, and — where the GDPR applies — meeting the requirements of Article 28(3).

06Notification of changes and your right to object

We will give customers at least 30 days’ advance notice before adding a new subprocessor or materially expanding the role of an existing one. Notice is given by email to the account contact and by updating this page with a revised date.

To subscribe to change notifications, write to [email protected]with “Subprocessor notifications” in the subject line and the address you want notified.

Objecting

If you have a reasonable, good-faith objection to a proposed subprocessor on data protection grounds, tell us within the notice period. We will work with you to find an alternative, which may include configuring your tenant so the subprocessor is not used where that is technically feasible.

Where no reasonable alternative exists, you may terminate the affected Services without penalty and receive a pro-rata refund of prepaid unused fees. We would rather lose the subscription than move your data somewhere you have told us you do not want it.

We may engage a replacement subprocessor without advance notice in an emergency — for example where an existing provider fails and continuity is at risk — and will notify you as soon as practicable afterwards, with an explanation.

07Questions and requests

For a copy of our Data Processing Addendum, the Standard Contractual Clauses we rely on for international transfers, or a subprocessor’s current security documentation where we are permitted to share it, write to [email protected].

Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States.

erp.io

ERP software with AI agents inside it — and the implementation, integration, and custom development that make it fit how you already work. We research and compare the rest of the market too, including the products we compete with.

AI
  • AI agents
  • ERP Copilot
  • Governance
  • Authority levels
  • Accuracy method
  • AI in ERP report
Platform
  • General ledger
  • Shadow ledger
  • Close
  • Reporting
  • Customer portals
  • API & MCP
Services
  • Implementation
  • Implementation rescue
  • Integration
  • Migration
  • Custom modules
  • Pricing
Research
  • ERP directory
  • Comparisons
  • Free tools
  • Guides
  • Glossary
  • Methodology
Company
  • About
  • Editorial policy
  • Partners
  • Trust center
  • Careers
  • Contact
© 2026 erp.io — a product of Nead, LLC (d/b/a DEV.co)We rank competitors honestly. No paid placement, ever.LegalPrivacyTermsDPASLACookiesStatus