Growth Station

Subprocessor List

Service providers that may process data to operate Growth Station and optional integrations enabled by customers.

Public documentVersion 2026.10.2Updated Oct 1, 2026
Português

Growth Station — Subprocessor List

Last updated: October 1, 2026

Document owner: Petro Liporace Cardoso de Souza

Translation notice: This English version is provided for convenience. If it conflicts with the original Portuguese document, the Portuguese version prevails.

This document forms part of the Data Processing Agreement (DPA) and Privacy Policy. It is publicly available for review by Controllers (customer Projects).

This list covers the Growth Station / GS Engage platform and its features, including Prospct.AI. All customers are subject to international data transfers in the operation of the platform; the providers involved in each data flow depend on the features and integrations used.

The countries and regions below describe the intended processing environments and do not guarantee exclusive data residency. The scope of each DPA depends on the applicable service and agreement. Security certifications and the existence of a DPA do not, by themselves, demonstrate adoption of ANPD standard contractual clauses; see section 1.12.

Companies covered

This document applies to both legal entities below, referred to as "Growth Machine", within their activities related to the platform:

  • Growth Machine Editora e Aceleração Ltda. — Brazilian company registry (CNPJ) 26.324.112/0001-91.
  • Growth Machine Serviços e Editora Ltda. — Brazilian company registry (CNPJ) 41.485.584/0001-10.

In customer relationships, the service provider is the legal entity identified in the agreement, accepted commercial proposal, or service order. Each company must comply with this document's obligations in the activities it performs, according to its role in processing the data and applicable law.


1. Current Subprocessors

1.1 Infrastructure and Storage

SubprocessorCountry/regionPurposeData processedDPA/certifications
Amazon Web Services (AWS)United States (us-east-1, us-east-2) / Brazil (sa-east-1)Serverless hosting (Lambda), storage (S3), queues (SQS), cache (Redis/ElastiCache), CDN, and web application firewall (CloudFront, WAF)All Platform dataAWS DPA; SOC 1/2/3; ISO 27001; CSA STAR
MongoDB AtlasAccording to plan (United States/Brazil)Primary databaseAll persistent data, including leads, users, projects, communications, and integrationsMongoDB DPA; SOC 2; ISO 27001; HIPAA

1.2 Communications — Email and Calendar

SubprocessorCountry/regionPurposeData processedDPA/certifications
NylasUnited StatesSending, receiving, and synchronizing emails; calendar managementEmail addresses, email content, signatures, attachments, calendar events, and open/click trackingNylas DPA; SOC 2

1.3 Communications — WhatsApp

SubprocessorCountry/regionPurposeData processedDPA/certifications
TwilioUnited StatesSending and receiving WhatsApp messages and status callbacksTelephone numbers, message content (text and media), and delivery statusTwilio DPA; SOC 2; ISO 27001; CSA STAR

1.4 Communications — VoIP

SubprocessorCountry/regionPurposeData processedDPA/certifications
TIMBrazilTelephone callsTelephone numbers, call metadata, and recordingsRegulated by ANATEL; appointed DPO; listed on B3's Novo Mercado
Twilio (voice)United StatesMaking and receiving voice calls, when used as the telephony providerTelephone numbers, call audio, metadata, and call status; recordings when enabledTwilio DPA; SOC 2; ISO 27001; CSA STAR

1.5 Artificial Intelligence

SubprocessorCountry/regionPurposeData processedDPA/certifications
OpenAIUnited StatesAI prospecting agent, voice agent, call analysis, transcription, and message generationLead data (name, title, company), messages, audio, transcripts, and interaction history, depending on the featureOpenAI DPA; SOC 2; API data not used for training by default
GroqUnited StatesNatural language processing fallbackLead data, message content, transcripts, and interaction history when the fallback is usedGroq DPA; SOC 2 Type II
DeepInfraUnited StatesDocument interpretation and description of images received over WhatsAppImages, vCards, and documents sent by Leads in WhatsApp conversationsVerify current DPA
ElevenLabs (voice)United StatesVoice processing in AI agent calls and speech synthesis, when usedConversation audio, transcripts, agent instructions, and lead data made available for the callElevenLabs DPA; applicability depends on the service agreement

Langfuse — self-hosted on AWS in Ohio, United States (us-east-2): Growth operates its own instance to record prompts, responses, and metadata from AI interactions. AWS is the subprocessor hosting these records; this processing and the corresponding international transfers fall within the AWS scope described in section 1.1.

1.6 Analytics and Monitoring

SubprocessorCountry/regionPurposeData processedDPA/certifications
PostHogUnited StatesProduct and usage behavior analyticsUsage events, session identifiers, and browser technical dataPostHog DPA; SOC 2
SentryUnited StatesError and performance monitoringError logs, stack traces, technical request data, and IP addressSentry DPA; SOC 2; ISO 27001

1.7 Support

SubprocessorCountry/regionPurposeData processedDPA/certifications
Atlassian (Jira)United States/AustraliaSupport ticket systemIssue descriptions and attachments submitted by the UserAtlassian DPA; SOC 2; ISO 27001

1.8 Google — Workspace and Authentication

SubprocessorCountry/regionPurposeData processedDPA/certifications
Google (Drive)United StatesStorage and sharing of materials and playbooksMaterial files, access permissions, and file metadataGoogle Workspace DPA; SOC 2; ISO 27001
Google (Admin Directory)United StatesOrganizational account and directory managementOrganizational user data, including name and corporate email addressGoogle Workspace DPA
Google (SSO / OAuth 2.0)United StatesUser authentication through Single Sign-OnGoogle profile data (name, email address, profile image) and authentication tokenTerms of the authentication service used; coverage by the Workspace DPA is not automatic

The Cloud Data Processing Addendum (CDPA) applies to services covered by the corresponding agreement. A Google account, OAuth access, or a personal Gmail account does not establish coverage under the Google Workspace or Google Cloud CDPA.

1.9 Microsoft

SubprocessorCountry/regionPurposeData processedDPA/certifications
Microsoft (SSO / Azure AD)United StatesUser authentication through Single Sign-OnMicrosoft profile data (name and email address) and authentication tokenMicrosoft DPA; SOC 2; ISO 27001

1.10 Cache and Connection State

SubprocessorCountry/regionPurposeData processedDPA/certifications
Redis (AWS ElastiCache)According to AWS regionSession cache, WebSocket connection state, and volatile dataSession identifiers, connection state, and permission cacheManaged by AWS; SOC 2; ISO 27001

1.11 Notifications

SubprocessorCountry/regionPurposeData processedDPA/certifications
AWS SNSAccording to AWS regionEmail notifications, including invitations, alerts, and two-factor authentication codesRecipient email address and email contentAWS DPA; SOC 2; ISO 27001

Redis/ElastiCache and SNS are AWS services, not additional subprocessors.

1.12 International Transfers — ANPD Standard Contractual Clauses

Document review: October 1, 2026. The table indicates whether the public documents reviewed include the standard contractual clauses issued by ANPD (Resolution CD/ANPD No. 19/2024), also known as Brazil SCCs.

“Included” means the public document expressly provides for these clauses, subject to its conditions. It is not proof of acceptance for Growth's account. “Not identified” means the clauses were not found in the documents reviewed, without implying that the provider cannot offer a separate addendum. “Not established” means the available documentation does not establish their inclusion.

ProviderANPD clauses statusReason and reference document
AWSNot identifiedThe Service Terms, section 1.14, incorporate the DPA and European, UK, and Swiss clauses. Incorporation of ANPD clauses was not identified in these documents.
MongoDB AtlasNot identifiedThe DPA, section 9.3 and Schedule 1, addresses European Union, UK, and Swiss mechanisms, without expressly providing for ANPD clauses.
TwilioIncludedThe DPA, Schedule 3, section 2.7, provides for Brazil SCCs and their incorporation by reference for covered transfers.
OpenAINot identifiedThe DPA defines SCCs as the European clauses. No express provision for ANPD clauses was identified.
ElevenLabsIncludedThe DPA, sections 11.1 and 11.5, includes Brazil SCCs. Applicability depends on this DPA forming part of the service agreement; enterprise contracts may have their own terms.
GroqNot identifiedThe DPA, section 8, provides international transfer mechanisms but does not expressly incorporate ANPD clauses.
NylasNot establishedThe official DPA guidance refers to the agreement and order form. This guidance does not establish that the contracted instrument includes Brazil SCCs.
PostHogNot identifiedThe public DPA does not expressly provide for ANPD clauses.
SentryNot identifiedThe public DPA addresses European, UK, and Swiss mechanisms, without expressly providing for ANPD clauses.
Atlassian (Jira)IncludedThe DPA, Schedule 2, section 4 — Brazil, incorporates Brazilian clauses and deems the parties to have signed them in the circumstances specified.
GoogleIncludedThe CDPA, Appendix 3 — Brazil, section 3, provides for BR SCCs according to the contracting entity, the parties' roles, and the transfer flow. Coverage depends on the applicable product and agreement.

Establishing contractual coverage requires identifying the agreement applicable to the account and service, the DPA version and how it was incorporated or accepted, and any separate addendum containing ANPD standard contractual clauses. This list does not replace those instruments or establish coverage for every account. The analysis above is limited to the eleven listed providers; it does not establish ANPD clause coverage for DeepInfra, Microsoft, or the integrations in section 2.

Coverage of both CNPJs: reviewing supplier agreements must establish which Growth Machine company is covered. Listing both companies here does not automatically extend a DPA or transfer clauses entered into by one company to the other; coverage must follow from the applicable agreement, an affiliate provision, or a corresponding instrument.

European clauses, security certifications, and general references to the LGPD do not automatically equate to ANPD standard contractual clauses. Other transfer mechanisms require their own applicable basis under ANPD guidance on international transfers.


2. Controller-Enabled Integrations

The following third-party services are optionally configured by the Project (Controller) and process Lead data when enabled. Growth Machine acts as a technical intermediary; the Controller is responsible for its contractual relationship with each provider.

ServiceCountry/regionPurposeData shared
PipedriveEuropean Union/United StatesCRM synchronization of contacts, organizations, deals, and activitiesName, email address(es), telephone number(s), company, job title, and activity notes
RD Station CRMBrazilCRM synchronization of contacts, organizations, deals, and tasksName, email address(es), telephone number(s), company, job title, and notes
RD Station MarketingBrazilMarketing automation and lead ingestion through webhooksName, email address, telephone number, company, and mapped fields
HubSpotUnited StatesCRM synchronization of contacts, organizations, deals, and activitiesName, email address(es), telephone number(s), company, job title, and notes
Kommo (amoCRM)United States/European UnionCRM synchronization of contacts, leads, tasks, and notesName, email address(es), telephone number(s), company, job title, and notes
SalesforceUnited StatesCRM synchronization of contacts, accounts, opportunities, and activitiesName, email address(es), telephone number(s), company, job title, and notes
Bitrix24European UnionCRM synchronization of contacts, organizations, deals, and activitiesName, email address(es), telephone number(s), company, job title, and notes
Go2SellBrazilPartner lead importName, email address, telephone number, company, and mapped data
MeetimeBrazilSales cadence and performance metric integrationPerformance metrics, cadence data, and prospecting activities

3. Adding New Subprocessors

  1. Growth Machine assesses the prospective subprocessor's security and privacy practices.
  2. Growth Machine enters into a DPA with the new subprocessor.
  3. This document is updated to include the new subprocessor.
  4. Controllers receive at least 30 (thirty) days' notice before activation.
  5. A Controller may submit a reasoned objection within 15 days.

4. Objection Procedure

If a Controller has a reasoned objection to a new subprocessor:

  1. The Controller must submit its objection in writing within 15 (fifteen) days after receiving notice.
  2. Growth Machine will seek a reasonable alternative or mitigating measure.
  3. If the objection cannot be resolved, the Controller may terminate the Main Agreement and DPA without penalty, subject to a 30-day transition period.

5. Contact

For questions about subprocessors:


This document forms part of the Growth Station DPA and Privacy Policy.

Your feedback matters

Did this guide answer your question?

It only takes a few seconds and helps us keep the knowledge base useful.

Nesta página

Reviewed Oct 1, 2026

Content maintained by Privacy — Growth Machine