Effective September 3, 2026
Subprocessors
Prosewire keeps a short public list and gives business customers advance notice before a new provider processes customer personal data.A subprocessor is a provider that Prosewire uses to process customer personal data on Prosewire’s behalf. This list covers Prosewire Cloud and the Prosewire website. It does not cover vendors chosen by an independent self-hosted operator.
Current providers
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Railway Corporation | Cloud application hosting and managed infrastructure | Customer content, account records, authentication data, logs, and service metadata | The configured Railway deployment region, plus locations used for support, security, and Railway’s own subprocessors |
| Cloudflare, Inc. | Authoritative DNS for prosewire.com | DNS queries and limited service metadata. Cloudflare does not host the website or Prosewire Cloud workspace content through this role | Cloudflare’s global network. No Customer Metadata Boundary is promised |
| Vercel Inc. | Build and static hosting for prosewire.com, including these legal pages | Public site source and assets, build metadata, website requests, and limited network logs. Vercel does not host Prosewire Cloud workspace content through this site role | Vercel’s global network and locations used by its subprocessors. No regional boundary is promised |
Railway may use infrastructure and operations providers on its own subprocessor list. Those providers are included through Railway’s processing chain.
Optional services
Google or GitHub may process account data if Prosewire enables that login method and a user chooses it. Neither provider is enabled on Prosewire Cloud as of the effective date. We will move a provider to the current list before enabling it for customer accounts.
No separate SMTP provider is approved for business customer data as of the effective date. Prosewire will identify the provider here and complete the change process before enabling managed invitation delivery for a business customer. No payment processor is enabled.
A customer may direct data to a domain, framework host, embed destination, or other system outside Prosewire Cloud. That recipient is the customer’s provider, not a Prosewire subprocessor.
Changes
The DPA gives business customers general authorization for the listed subprocessors. We will post an update and email the workspace owner at least 15 days before a new subprocessor begins processing customer personal data, unless an urgent security need makes advance notice impractical.
A business customer may object during that notice period on reasonable data-protection grounds. We will discuss a practical alternative. If none is available, the customer may stop using the affected feature or terminate the affected Cloud service before the provider begins processing its data.
Provider names, services, and locations can change. The effective date at the top shows when this list was last reviewed.
Questions
Email privacy@prosewire.com with “Subprocessor question” in the subject.