Service providers that may process data to operate Growth Station and optional integrations enabled by customers.
Public document Version 2026.08 Updated Aug 16, 2026
Português
Last updated: August 16, 2026
Document owner: Petro Liporace Cardoso de Souza
Translation notice: This English version is provided for convenience. If it conflicts with the original Portuguese document, the Portuguese version prevails.
This document forms part of the Data Processing Agreement (DPA) and Privacy Policy. It is publicly available for review by Controllers (customer Projects).
Subprocessor Country/region Purpose Data processed DPA/certifications Amazon Web Services (AWS) United States (us-east-1, us-east-2) / Brazil (sa-east-1) Serverless hosting (Lambda), storage (S3), queues (SQS), cache (Redis/ElastiCache), CDN, and web application firewall (CloudFront, WAF) All Platform data AWS DPA; SOC 1/2/3; ISO 27001; CSA STAR MongoDB Atlas According to plan (United States/Brazil) Primary database All persistent data, including leads, users, projects, communications, and integrations MongoDB DPA; SOC 2; ISO 27001; HIPAA
Subprocessor Country/region Purpose Data processed DPA/certifications Nylas United States Sending, receiving, and synchronizing emails; calendar management Email addresses, email content, signatures, attachments, calendar events, and open/click tracking Nylas DPA; SOC 2
Subprocessor Country/region Purpose Data processed DPA/certifications Twilio United States Sending and receiving WhatsApp messages and status callbacks Telephone numbers, message content (text and media), and delivery status Twilio DPA; SOC 2; ISO 27001; CSA STAR
Subprocessor Country/region Purpose Data processed DPA/certifications TIM Brazil Telephone calls Telephone numbers, call metadata, and recordings Regulated by ANATEL; appointed DPO; listed on B3's Novo Mercado
Subprocessor Country/region Purpose Data processed DPA/certifications OpenAI United States AI prospecting agent, call analysis, transcription, and message generation Lead data (name, title, company), message content, call transcripts, and interaction history OpenAI DPA; SOC 2; API data not used for training Groq United States Natural language processing fallback The same data described above when the fallback is used Groq DPA; SOC 2 Type II DeepInfra United States Document interpretation and description of images received over WhatsApp Images, vCards, and documents sent by Leads in WhatsApp conversations Verify current DPA Langfuse European Union/United States Monitoring and traceability of AI interactions LLM interaction metadata, including prompts, responses, latency, and token usage Langfuse DPA; SOC 2 Type II; ISO 27001
Subprocessor Country/region Purpose Data processed DPA/certifications PostHog United States Product and usage behavior analytics Usage events, session identifiers, and browser technical data PostHog DPA; SOC 2 Sentry United States Error and performance monitoring Error logs, stack traces, technical request data, and IP address Sentry DPA; SOC 2; ISO 27001
Subprocessor Country/region Purpose Data processed DPA/certifications Atlassian (Jira) United States/Australia Support ticket system Issue descriptions and attachments submitted by the User Atlassian DPA; SOC 2; ISO 27001
Subprocessor Country/region Purpose Data processed DPA/certifications Google (Drive) United States Storage and sharing of materials and playbooks Material files, access permissions, and file metadata Google Workspace DPA; SOC 2; ISO 27001 Google (Admin Directory) United States Organizational account and directory management Organizational user data, including name and corporate email address Google Workspace DPA Google (SSO / OAuth 2.0) United States User authentication through Single Sign-On Google profile data (name, email address, profile image) and authentication token Google DPA; SOC 2; ISO 27001
Subprocessor Country/region Purpose Data processed DPA/certifications Microsoft (SSO / Azure AD) United States User authentication through Single Sign-On Microsoft profile data (name and email address) and authentication token Microsoft DPA; SOC 2; ISO 27001
Subprocessor Country/region Purpose Data processed DPA/certifications Redis (AWS ElastiCache) According to AWS region Session cache, WebSocket connection state, and volatile data Session identifiers, connection state, and permission cache Managed by AWS; SOC 2; ISO 27001
Subprocessor Country/region Purpose Data processed DPA/certifications AWS SNS According to AWS region Email notifications, including invitations, alerts, and two-factor authentication codes Recipient email address and email content AWS DPA; SOC 2; ISO 27001
The following third-party services are optionally configured by the Project (Controller) and process Lead data when enabled. Growth Machine acts as a technical intermediary; the Controller is responsible for its contractual relationship with each provider.
Service Country/region Purpose Data shared Pipedrive European Union/United States CRM synchronization of contacts, organizations, deals, and activities Name, email address(es), telephone number(s), company, job title, and activity notes RD Station CRM Brazil CRM synchronization of contacts, organizations, deals, and tasks Name, email address(es), telephone number(s), company, job title, and notes RD Station Marketing Brazil Marketing automation and lead ingestion through webhooks Name, email address, telephone number, company, and mapped fields HubSpot United States CRM synchronization of contacts, organizations, deals, and activities Name, email address(es), telephone number(s), company, job title, and notes Kommo (amoCRM) United States/European Union CRM synchronization of contacts, leads, tasks, and notes Name, email address(es), telephone number(s), company, job title, and notes Salesforce United States CRM synchronization of contacts, accounts, opportunities, and activities Name, email address(es), telephone number(s), company, job title, and notes Bitrix24 European Union CRM synchronization of contacts, organizations, deals, and activities Name, email address(es), telephone number(s), company, job title, and notes Go2Sell Brazil Partner lead import Name, email address, telephone number, company, and mapped data Meetime Brazil Sales cadence and performance metric integration Performance metrics, cadence data, and prospecting activities
Growth Machine assesses the prospective subprocessor's security and privacy practices.
Growth Machine enters into a DPA with the new subprocessor.
This document is updated to include the new subprocessor.
Controllers receive at least 30 (thirty) days' notice before activation.
A Controller may submit a reasoned objection within 15 days.
If a Controller has a reasoned objection to a new subprocessor:
The Controller must submit its objection in writing within 15 (fifteen) days after receiving notice.
Growth Machine will seek a reasonable alternative or mitigating measure.
If the objection cannot be resolved, the Controller may terminate the Main Agreement and DPA without penalty, subject to a 30-day transition period.
For questions about subprocessors:
This document forms part of the Growth Station DPA and Privacy Policy.
Your feedback matters
Did this guide answer your question? It only takes a few seconds and helps us keep the knowledge base useful.
Yes It answered my question No It could be improved