Subprocessor List
Service providers that may process data to operate Growth Station and optional integrations enabled by customers.
Growth Station — Subprocessor List
Last updated: October 1, 2026
Document owner: Petro Liporace Cardoso de Souza
Translation notice: This English version is provided for convenience. If it conflicts with the original Portuguese document, the Portuguese version prevails.
This document forms part of the Data Processing Agreement (DPA) and Privacy Policy. It is publicly available for review by Controllers (customer Projects).
This list covers the Growth Station / GS Engage platform and its features, including Prospct.AI. All customers are subject to international data transfers in the operation of the platform; the providers involved in each data flow depend on the features and integrations used.
The countries and regions below describe the intended processing environments and do not guarantee exclusive data residency. The scope of each DPA depends on the applicable service and agreement. Security certifications and the existence of a DPA do not, by themselves, demonstrate adoption of ANPD standard contractual clauses; see section 1.12.
Companies covered
This document applies to both legal entities below, referred to as "Growth Machine", within their activities related to the platform:
- Growth Machine Editora e Aceleração Ltda. — Brazilian company registry (CNPJ) 26.324.112/0001-91.
- Growth Machine Serviços e Editora Ltda. — Brazilian company registry (CNPJ) 41.485.584/0001-10.
In customer relationships, the service provider is the legal entity identified in the agreement, accepted commercial proposal, or service order. Each company must comply with this document's obligations in the activities it performs, according to its role in processing the data and applicable law.
1. Current Subprocessors
1.1 Infrastructure and Storage
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Amazon Web Services (AWS) | United States (us-east-1, us-east-2) / Brazil (sa-east-1) | Serverless hosting (Lambda), storage (S3), queues (SQS), cache (Redis/ElastiCache), CDN, and web application firewall (CloudFront, WAF) | All Platform data | AWS DPA; SOC 1/2/3; ISO 27001; CSA STAR |
| MongoDB Atlas | According to plan (United States/Brazil) | Primary database | All persistent data, including leads, users, projects, communications, and integrations | MongoDB DPA; SOC 2; ISO 27001; HIPAA |
1.2 Communications — Email and Calendar
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Nylas | United States | Sending, receiving, and synchronizing emails; calendar management | Email addresses, email content, signatures, attachments, calendar events, and open/click tracking | Nylas DPA; SOC 2 |
1.3 Communications — WhatsApp
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Twilio | United States | Sending and receiving WhatsApp messages and status callbacks | Telephone numbers, message content (text and media), and delivery status | Twilio DPA; SOC 2; ISO 27001; CSA STAR |
1.4 Communications — VoIP
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| TIM | Brazil | Telephone calls | Telephone numbers, call metadata, and recordings | Regulated by ANATEL; appointed DPO; listed on B3's Novo Mercado |
| Twilio (voice) | United States | Making and receiving voice calls, when used as the telephony provider | Telephone numbers, call audio, metadata, and call status; recordings when enabled | Twilio DPA; SOC 2; ISO 27001; CSA STAR |
1.5 Artificial Intelligence
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| OpenAI | United States | AI prospecting agent, voice agent, call analysis, transcription, and message generation | Lead data (name, title, company), messages, audio, transcripts, and interaction history, depending on the feature | OpenAI DPA; SOC 2; API data not used for training by default |
| Groq | United States | Natural language processing fallback | Lead data, message content, transcripts, and interaction history when the fallback is used | Groq DPA; SOC 2 Type II |
| DeepInfra | United States | Document interpretation and description of images received over WhatsApp | Images, vCards, and documents sent by Leads in WhatsApp conversations | Verify current DPA |
| ElevenLabs (voice) | United States | Voice processing in AI agent calls and speech synthesis, when used | Conversation audio, transcripts, agent instructions, and lead data made available for the call | ElevenLabs DPA; applicability depends on the service agreement |
Langfuse — self-hosted on AWS in Ohio, United States (us-east-2): Growth operates its own instance to record prompts, responses, and metadata from AI interactions. AWS is the subprocessor hosting these records; this processing and the corresponding international transfers fall within the AWS scope described in section 1.1.
1.6 Analytics and Monitoring
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| PostHog | United States | Product and usage behavior analytics | Usage events, session identifiers, and browser technical data | PostHog DPA; SOC 2 |
| Sentry | United States | Error and performance monitoring | Error logs, stack traces, technical request data, and IP address | Sentry DPA; SOC 2; ISO 27001 |
1.7 Support
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Atlassian (Jira) | United States/Australia | Support ticket system | Issue descriptions and attachments submitted by the User | Atlassian DPA; SOC 2; ISO 27001 |
1.8 Google — Workspace and Authentication
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Google (Drive) | United States | Storage and sharing of materials and playbooks | Material files, access permissions, and file metadata | Google Workspace DPA; SOC 2; ISO 27001 |
| Google (Admin Directory) | United States | Organizational account and directory management | Organizational user data, including name and corporate email address | Google Workspace DPA |
| Google (SSO / OAuth 2.0) | United States | User authentication through Single Sign-On | Google profile data (name, email address, profile image) and authentication token | Terms of the authentication service used; coverage by the Workspace DPA is not automatic |
The Cloud Data Processing Addendum (CDPA) applies to services covered by the corresponding agreement. A Google account, OAuth access, or a personal Gmail account does not establish coverage under the Google Workspace or Google Cloud CDPA.
1.9 Microsoft
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Microsoft (SSO / Azure AD) | United States | User authentication through Single Sign-On | Microsoft profile data (name and email address) and authentication token | Microsoft DPA; SOC 2; ISO 27001 |
1.10 Cache and Connection State
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| Redis (AWS ElastiCache) | According to AWS region | Session cache, WebSocket connection state, and volatile data | Session identifiers, connection state, and permission cache | Managed by AWS; SOC 2; ISO 27001 |
1.11 Notifications
| Subprocessor | Country/region | Purpose | Data processed | DPA/certifications |
|---|---|---|---|---|
| AWS SNS | According to AWS region | Email notifications, including invitations, alerts, and two-factor authentication codes | Recipient email address and email content | AWS DPA; SOC 2; ISO 27001 |
Redis/ElastiCache and SNS are AWS services, not additional subprocessors.
1.12 International Transfers — ANPD Standard Contractual Clauses
Document review: October 1, 2026. The table indicates whether the public documents reviewed include the standard contractual clauses issued by ANPD (Resolution CD/ANPD No. 19/2024), also known as Brazil SCCs.
“Included” means the public document expressly provides for these clauses, subject to its conditions. It is not proof of acceptance for Growth's account. “Not identified” means the clauses were not found in the documents reviewed, without implying that the provider cannot offer a separate addendum. “Not established” means the available documentation does not establish their inclusion.
| Provider | ANPD clauses status | Reason and reference document |
|---|---|---|
| AWS | Not identified | The Service Terms, section 1.14, incorporate the DPA and European, UK, and Swiss clauses. Incorporation of ANPD clauses was not identified in these documents. |
| MongoDB Atlas | Not identified | The DPA, section 9.3 and Schedule 1, addresses European Union, UK, and Swiss mechanisms, without expressly providing for ANPD clauses. |
| Twilio | Included | The DPA, Schedule 3, section 2.7, provides for Brazil SCCs and their incorporation by reference for covered transfers. |
| OpenAI | Not identified | The DPA defines SCCs as the European clauses. No express provision for ANPD clauses was identified. |
| ElevenLabs | Included | The DPA, sections 11.1 and 11.5, includes Brazil SCCs. Applicability depends on this DPA forming part of the service agreement; enterprise contracts may have their own terms. |
| Groq | Not identified | The DPA, section 8, provides international transfer mechanisms but does not expressly incorporate ANPD clauses. |
| Nylas | Not established | The official DPA guidance refers to the agreement and order form. This guidance does not establish that the contracted instrument includes Brazil SCCs. |
| PostHog | Not identified | The public DPA does not expressly provide for ANPD clauses. |
| Sentry | Not identified | The public DPA addresses European, UK, and Swiss mechanisms, without expressly providing for ANPD clauses. |
| Atlassian (Jira) | Included | The DPA, Schedule 2, section 4 — Brazil, incorporates Brazilian clauses and deems the parties to have signed them in the circumstances specified. |
| Included | The CDPA, Appendix 3 — Brazil, section 3, provides for BR SCCs according to the contracting entity, the parties' roles, and the transfer flow. Coverage depends on the applicable product and agreement. |
Establishing contractual coverage requires identifying the agreement applicable to the account and service, the DPA version and how it was incorporated or accepted, and any separate addendum containing ANPD standard contractual clauses. This list does not replace those instruments or establish coverage for every account. The analysis above is limited to the eleven listed providers; it does not establish ANPD clause coverage for DeepInfra, Microsoft, or the integrations in section 2.
Coverage of both CNPJs: reviewing supplier agreements must establish which Growth Machine company is covered. Listing both companies here does not automatically extend a DPA or transfer clauses entered into by one company to the other; coverage must follow from the applicable agreement, an affiliate provision, or a corresponding instrument.
European clauses, security certifications, and general references to the LGPD do not automatically equate to ANPD standard contractual clauses. Other transfer mechanisms require their own applicable basis under ANPD guidance on international transfers.
2. Controller-Enabled Integrations
The following third-party services are optionally configured by the Project (Controller) and process Lead data when enabled. Growth Machine acts as a technical intermediary; the Controller is responsible for its contractual relationship with each provider.
| Service | Country/region | Purpose | Data shared |
|---|---|---|---|
| Pipedrive | European Union/United States | CRM synchronization of contacts, organizations, deals, and activities | Name, email address(es), telephone number(s), company, job title, and activity notes |
| RD Station CRM | Brazil | CRM synchronization of contacts, organizations, deals, and tasks | Name, email address(es), telephone number(s), company, job title, and notes |
| RD Station Marketing | Brazil | Marketing automation and lead ingestion through webhooks | Name, email address, telephone number, company, and mapped fields |
| HubSpot | United States | CRM synchronization of contacts, organizations, deals, and activities | Name, email address(es), telephone number(s), company, job title, and notes |
| Kommo (amoCRM) | United States/European Union | CRM synchronization of contacts, leads, tasks, and notes | Name, email address(es), telephone number(s), company, job title, and notes |
| Salesforce | United States | CRM synchronization of contacts, accounts, opportunities, and activities | Name, email address(es), telephone number(s), company, job title, and notes |
| Bitrix24 | European Union | CRM synchronization of contacts, organizations, deals, and activities | Name, email address(es), telephone number(s), company, job title, and notes |
| Go2Sell | Brazil | Partner lead import | Name, email address, telephone number, company, and mapped data |
| Meetime | Brazil | Sales cadence and performance metric integration | Performance metrics, cadence data, and prospecting activities |
3. Adding New Subprocessors
- Growth Machine assesses the prospective subprocessor's security and privacy practices.
- Growth Machine enters into a DPA with the new subprocessor.
- This document is updated to include the new subprocessor.
- Controllers receive at least 30 (thirty) days' notice before activation.
- A Controller may submit a reasoned objection within 15 days.
4. Objection Procedure
If a Controller has a reasoned objection to a new subprocessor:
- The Controller must submit its objection in writing within 15 (fifteen) days after receiving notice.
- Growth Machine will seek a reasonable alternative or mitigating measure.
- If the objection cannot be resolved, the Controller may terminate the Main Agreement and DPA without penalty, subject to a 30-day transition period.
5. Contact
For questions about subprocessors:
- Email: privacidade@growthedge.com.br
- Data Protection Officer (DPO): Natália Caroline Batista
This document forms part of the Growth Station DPA and Privacy Policy.
Your feedback matters
Did this guide answer your question?
It only takes a few seconds and helps us keep the knowledge base useful.