# Subprocessor List

> Service providers that may process data to operate Growth Station and optional integrations enabled by customers.

- Canonical URL: https://docs.growthstation.app/docs/legal/en/subprocessors
- Language: en
- Last updated: 2026-08-17T12:49:19.123Z
- Product: Plataforma Growth Station
- Maintained by: Privacy — Growth Machine
- Editorial review: 2026-08-16



Growth Station — Subprocessor List [#growth-station--subprocessor-list]

**Last updated:** August 16, 2026\
**Document owner:** Petro Liporace Cardoso de Souza

> **Translation notice:** This English version is provided for convenience. If it conflicts with the original Portuguese document, the Portuguese version prevails.

> This document forms part of the Data Processing Agreement (DPA) and Privacy Policy. It is publicly available for review by Controllers (customer Projects).

***

1. Current Subprocessors [#1-current-subprocessors]

1.1 Infrastructure and Storage [#11-infrastructure-and-storage]

| Subprocessor                  | Country/region                                            | Purpose                                                                                                                                 | Data processed                                                                          | DPA/certifications                      |
| ----------------------------- | --------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | --------------------------------------- |
| **Amazon Web Services (AWS)** | United States (us-east-1, us-east-2) / Brazil (sa-east-1) | Serverless hosting (Lambda), storage (S3), queues (SQS), cache (Redis/ElastiCache), CDN, and web application firewall (CloudFront, WAF) | All Platform data                                                                       | AWS DPA; SOC 1/2/3; ISO 27001; CSA STAR |
| **MongoDB Atlas**             | According to plan (United States/Brazil)                  | Primary database                                                                                                                        | All persistent data, including leads, users, projects, communications, and integrations | MongoDB DPA; SOC 2; ISO 27001; HIPAA    |

1.2 Communications — Email and Calendar [#12-communications--email-and-calendar]

| Subprocessor | Country/region | Purpose                                                           | Data processed                                                                                    | DPA/certifications |
| ------------ | -------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- | ------------------ |
| **Nylas**    | United States  | Sending, receiving, and synchronizing emails; calendar management | Email addresses, email content, signatures, attachments, calendar events, and open/click tracking | Nylas DPA; SOC 2   |

1.3 Communications — WhatsApp [#13-communications--whatsapp]

| Subprocessor | Country/region | Purpose                                                      | Data processed                                                           | DPA/certifications                     |
| ------------ | -------------- | ------------------------------------------------------------ | ------------------------------------------------------------------------ | -------------------------------------- |
| **Twilio**   | United States  | Sending and receiving WhatsApp messages and status callbacks | Telephone numbers, message content (text and media), and delivery status | Twilio DPA; SOC 2; ISO 27001; CSA STAR |

1.4 Communications — VoIP [#14-communications--voip]

| Subprocessor | Country/region | Purpose         | Data processed                                   | DPA/certifications                                              |
| ------------ | -------------- | --------------- | ------------------------------------------------ | --------------------------------------------------------------- |
| **TIM**      | Brazil         | Telephone calls | Telephone numbers, call metadata, and recordings | Regulated by ANATEL; appointed DPO; listed on B3's Novo Mercado |

1.5 Artificial Intelligence [#15-artificial-intelligence]

| Subprocessor  | Country/region               | Purpose                                                                    | Data processed                                                                               | DPA/certifications                                |
| ------------- | ---------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | ------------------------------------------------- |
| **OpenAI**    | United States                | AI prospecting agent, call analysis, transcription, and message generation | Lead data (name, title, company), message content, call transcripts, and interaction history | OpenAI DPA; SOC 2; API data not used for training |
| **Groq**      | United States                | Natural language processing fallback                                       | The same data described above when the fallback is used                                      | Groq DPA; SOC 2 Type II                           |
| **DeepInfra** | United States                | Document interpretation and description of images received over WhatsApp   | Images, vCards, and documents sent by Leads in WhatsApp conversations                        | Verify current DPA                                |
| **Langfuse**  | European Union/United States | Monitoring and traceability of AI interactions                             | LLM interaction metadata, including prompts, responses, latency, and token usage             | Langfuse DPA; SOC 2 Type II; ISO 27001            |

1.6 Analytics and Monitoring [#16-analytics-and-monitoring]

| Subprocessor | Country/region | Purpose                              | Data processed                                                   | DPA/certifications           |
| ------------ | -------------- | ------------------------------------ | ---------------------------------------------------------------- | ---------------------------- |
| **PostHog**  | United States  | Product and usage behavior analytics | Usage events, session identifiers, and browser technical data    | PostHog DPA; SOC 2           |
| **Sentry**   | United States  | Error and performance monitoring     | Error logs, stack traces, technical request data, and IP address | Sentry DPA; SOC 2; ISO 27001 |

1.7 Support [#17-support]

| Subprocessor         | Country/region          | Purpose               | Data processed                                           | DPA/certifications              |
| -------------------- | ----------------------- | --------------------- | -------------------------------------------------------- | ------------------------------- |
| **Atlassian (Jira)** | United States/Australia | Support ticket system | Issue descriptions and attachments submitted by the User | Atlassian DPA; SOC 2; ISO 27001 |

1.8 Google Workspace [#18-google-workspace]

| Subprocessor                 | Country/region | Purpose                                         | Data processed                                                                    | DPA/certifications                     |
| ---------------------------- | -------------- | ----------------------------------------------- | --------------------------------------------------------------------------------- | -------------------------------------- |
| **Google (Drive)**           | United States  | Storage and sharing of materials and playbooks  | Material files, access permissions, and file metadata                             | Google Workspace DPA; SOC 2; ISO 27001 |
| **Google (Admin Directory)** | United States  | Organizational account and directory management | Organizational user data, including name and corporate email address              | Google Workspace DPA                   |
| **Google (SSO / OAuth 2.0)** | United States  | User authentication through Single Sign-On      | Google profile data (name, email address, profile image) and authentication token | Google DPA; SOC 2; ISO 27001           |

1.9 Microsoft [#19-microsoft]

| Subprocessor                   | Country/region | Purpose                                    | Data processed                                                           | DPA/certifications              |
| ------------------------------ | -------------- | ------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------- |
| **Microsoft (SSO / Azure AD)** | United States  | User authentication through Single Sign-On | Microsoft profile data (name and email address) and authentication token | Microsoft DPA; SOC 2; ISO 27001 |

1.10 Cache and Connection State [#110-cache-and-connection-state]

| Subprocessor                | Country/region          | Purpose                                                      | Data processed                                              | DPA/certifications               |
| --------------------------- | ----------------------- | ------------------------------------------------------------ | ----------------------------------------------------------- | -------------------------------- |
| **Redis (AWS ElastiCache)** | According to AWS region | Session cache, WebSocket connection state, and volatile data | Session identifiers, connection state, and permission cache | Managed by AWS; SOC 2; ISO 27001 |

1.11 Notifications [#111-notifications]

| Subprocessor | Country/region          | Purpose                                                                                 | Data processed                            | DPA/certifications        |
| ------------ | ----------------------- | --------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------- |
| **AWS SNS**  | According to AWS region | Email notifications, including invitations, alerts, and two-factor authentication codes | Recipient email address and email content | AWS DPA; SOC 2; ISO 27001 |

***

2. Controller-Enabled Integrations [#2-controller-enabled-integrations]

The following third-party services are **optionally configured by the Project (Controller)** and process Lead data when enabled. Growth Machine acts as a technical intermediary; the Controller is responsible for its contractual relationship with each provider.

| Service                  | Country/region               | Purpose                                                                  | Data shared                                                                          |
| ------------------------ | ---------------------------- | ------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ |
| **Pipedrive**            | European Union/United States | CRM synchronization of contacts, organizations, deals, and activities    | Name, email address(es), telephone number(s), company, job title, and activity notes |
| **RD Station CRM**       | Brazil                       | CRM synchronization of contacts, organizations, deals, and tasks         | Name, email address(es), telephone number(s), company, job title, and notes          |
| **RD Station Marketing** | Brazil                       | Marketing automation and lead ingestion through webhooks                 | Name, email address, telephone number, company, and mapped fields                    |
| **HubSpot**              | United States                | CRM synchronization of contacts, organizations, deals, and activities    | Name, email address(es), telephone number(s), company, job title, and notes          |
| **Kommo (amoCRM)**       | United States/European Union | CRM synchronization of contacts, leads, tasks, and notes                 | Name, email address(es), telephone number(s), company, job title, and notes          |
| **Salesforce**           | United States                | CRM synchronization of contacts, accounts, opportunities, and activities | Name, email address(es), telephone number(s), company, job title, and notes          |
| **Bitrix24**             | European Union               | CRM synchronization of contacts, organizations, deals, and activities    | Name, email address(es), telephone number(s), company, job title, and notes          |
| **Go2Sell**              | Brazil                       | Partner lead import                                                      | Name, email address, telephone number, company, and mapped data                      |
| **Meetime**              | Brazil                       | Sales cadence and performance metric integration                         | Performance metrics, cadence data, and prospecting activities                        |

***

3. Adding New Subprocessors [#3-adding-new-subprocessors]

1. Growth Machine assesses the prospective subprocessor's security and privacy practices.
2. Growth Machine enters into a DPA with the new subprocessor.
3. This document is updated to include the new subprocessor.
4. Controllers receive at least **30 (thirty) days'** notice before activation.
5. A Controller may submit a reasoned objection within 15 days.

***

4. Objection Procedure [#4-objection-procedure]

If a Controller has a reasoned objection to a new subprocessor:

1. The Controller must submit its objection in writing within **15 (fifteen) days** after receiving notice.
2. Growth Machine will seek a reasonable alternative or mitigating measure.
3. If the objection cannot be resolved, the Controller may terminate the Main Agreement and DPA without penalty, subject to a 30-day transition period.

***

5. Contact [#5-contact]

For questions about subprocessors:

* **Email:** [privacidade@growthedge.com.br](mailto:privacidade@growthedge.com.br)
* **Data Protection Officer (DPO):** Natália Caroline Batista

***

*This document forms part of the Growth Station DPA and Privacy Policy.*
