Legal
Sub-processors
OrgLens processes Salesforce metadata only — object and field API names, labels, descriptions, and relationships — not Customer's end-customer records or field values. This page lists the vetted sub-processors we use to deliver the Service, what each one processes, and where. It is incorporated by reference into our Data Processing Agreement and Privacy Policy.
Current sub-processors
| Sub-processor | Purpose | Data processed | Location / Region |
|---|---|---|---|
| Anthropic, PBC | AI generation of field & object descriptions and configuration-risk findings | Salesforce metadata only (object/field API names, labels, relationships) — no record data | USA |
| Klokk Nettablering (self-hosted infrastructure) | Primary hosting & database — operated by Klokk Nettablering on dedicated infrastructure | Application data, encrypted metadata storage, backups | EU / self-hosted |
| Cloudflare, Inc. | CDN, DNS, WAF/DDoS protection, TLS termination | Request metadata, IP address | Global edge |
| Stripe, Inc. | Subscription billing & payment processing | Billing/account data (name, email, tax ID); card details handled directly by Stripe | USA / global |
| MailWizz (self-hosted) | Transactional & lifecycle email delivery (onboarding, trial, billing notices) | Name, email address, account/lifecycle event data | EU / self-hosted |
We do not use any sub-processor beyond those listed above for processing Customer Data. We do not sell personal data to any sub-processor or third party.
Changes to this list
Before engaging a new sub-processor to process Customer Data, we will update this page and, where Customer has provided a contact for this purpose, send reasonable prior notice by email so Customer may object on reasonable data-protection grounds, consistent with our Data Processing Agreement. This list is effective as of the "Last updated" date above.
To be notified of future changes, email [email protected] with the subject "Sub-processor updates" and we will add you to our notification list.