We engage carefully vetted third‑party processors to deliver our services. This document lists our current sub‑processors, the purposes for which we use them, their processing locations, and the safeguards we apply for any international transfers.

Last updated: October 22, 2025

Data Protection Contact: privacy@atmosphericg2.com

Contractual Basis: Processor obligations under Art. 28 GDPR; SCCs or other safeguards for non‑EEA transfers.

Name of Sub‑ProcessorPurpose of ProcessingProcessing LocationData CategoriesTransfer Mechanism (if outside EEA)Transfer Mechanism (if outside EEA)First ListedLast Reviewed
Amazon Web Services, Inc.Cloud infrastructure (compute, storage, networking)US (Viginia); EU (London); global resiliencyCustomer account dataSCCs; EU Standard Contractual Clauses; DPA in placeISO 27001, SOC 1/2/3, CSA STAROct 25, 2025Oct 25, 2025
SalesforceSales TrackingEU and USContact details;SCCs; supplementary measuresSOC 2 Type II; ISO 27001Oct 25, 2025Oct 25, 2025
SendGrid (Twilio Inc.)Transactional email deliveryEU and USEmail addresses; message metadata; delivery logsSCCsSOC 2 Type IIOct 25, 2025Oct 25, 2025

Oct 25, 2025

Initial Document creation

Document created and reviewed.

AtmosphericG2 follows strict evaluation criteria before engaging any sub‑processor:

  • Data Processing Agreements imposing Article 28 GDPR obligations
  • Transfer impact assessments and supplementary safeguards for international transfers
  • Security reviews (e.g.SOC 2) and penetration testing summaries
  • Principle of data minimization and purpose limitation
  • Annual re‑validation and contractual audits where applicable

This document is provided for transparency under GDPR Articles 13 and 28. For questions or to object to a new sub‑processor, contact our Data Protection Officer at privacy@atmosphericg2.com.

Scroll to Top