Subprocessors

Effective date: November 2025 · Last updated: January 2026 · Version: v1.1

This page describes the subprocessors used by SalesGPT.work, owned and operated by BLINK REALTY PRIVATE LIMITED (CIN: U45403UP2019PTC115224), in connection with providing the Service.

Overview & definitions

SalesGPT.work uses certain third-party subprocessors to assist in providing our services. These subprocessors may process Customer Data on our behalf and are contractually subject to data protection obligations consistent with our Data Processing Addendum (“DPA”).

  • “Customer Data” means personal data and other data that a customer uploads, inputs, syncs, generates, or otherwise provides to the Service (including prompts and outputs where they include personal data).
  • “Service Data” means data generated by the Service’s operation (e.g., system logs, security events, performance metrics) that does not constitute Customer Data unless it contains personal data.
  • “Subprocessor” means a third party we engage to process Customer Data on our behalf to provide the Service.
  • “Independent Controller” means a third party (often a payment provider) that determines its own purposes and means for certain processing activities.
Status: This list is current as of Jan 2026. We will update this page when we add or remove subprocessors. Questions or objections: admin@salesgpt.work.

DPO contact: For GDPR-related inquiries or data protection concerns, contact our Data Protection Officer at admin@salesgpt.work.

Governance & vetting

We use subprocessors to deliver infrastructure, email delivery, payments, analytics, support, and AI/LLM capabilities. Before onboarding, we evaluate subprocessors using a risk-based review.

  • Security & privacy review: we evaluate security posture, encryption, access controls, incident history, and privacy commitments.
  • Contractual safeguards: subprocessors must sign agreements with confidentiality, security, breach notification, and deletion/return obligations no less protective than our DPA.
  • Least-privilege access: access is limited to what is necessary for service delivery and support.
  • Ongoing review: subprocessors are reassessed periodically (at least annually or on material change/risk signals).

No model training by AI subprocessors: Our AI/LLM subprocessors are contractually prohibited from using Customer Data to train their foundation models, unless expressly agreed in a separate written agreement.

Data transfer mechanisms & safeguards

Cross-border transfers

Customer Data may be stored and processed in India and the United States (and other regions depending on vendor infrastructure). For subprocessors located outside the EEA/UK, transfers are governed by appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs): European Commission SCCs (Module Two: Controller-to-Processor), as incorporated into our DPA, and the UK Addendum/IDTA where required.
  • Adequacy decisions: where applicable under GDPR Article 45.
  • Other approved mechanisms: as required by applicable law.

Data residency

Customer Data may be stored and processed in India and the United States. For enterprise customers, regional data residency options (e.g., EU-only storage) may be available upon request, subject to commercial feasibility and additional terms.

Foreign access warning (Canada)

Data processed in foreign jurisdictions (e.g., United States, India) may be subject to local laws and access requests. We require subprocessors to notify us of such requests to the extent permitted by law.

Security standards, access control, and incident flow

Security standards

Subprocessors are vetted and contractually required to maintain appropriate technical and organizational measures to protect Customer Data. Controls may include, where applicable:

  • Encryption in transit (e.g., TLS) and at rest (e.g., AES-256 where applicable)
  • Industry security certifications where available (e.g., ISO 27001, SOC 2, PCI DSS for payment environments)
  • Incident notification obligations (subprocessors must notify us promptly of incidents affecting Customer Data)
  • Regular security assessments and compliance audits as required by our DPA

Incident notification flow

If a subprocessor experiences a security incident affecting Customer Data, the expected flow is:

  • Subprocessor → SalesGPT.work: prompt notice per contract/DPA obligations.
  • SalesGPT.work → Customer: notice per our DPA timelines and incident response process.
Important: This page describes governance and process. Detailed security reports (e.g., SOC2) may be provided to enterprise customers upon request under appropriate confidentiality terms.

Current subprocessors

Final subprocessor legal names and vendor details will be published by launch date. Until then, this table lists the categories/types used. All subprocessors are contractually bound by our DPA obligations.

SubprocessorCategory / ServicePurposeLocationsData categoriesRole
[Cloud Hosting Provider]
(e.g., AWS / GCP / Azure)
Infrastructure & hostingCore compute and storageUnited States, India, Ireland (EU)Account data, usage data, enrichment data, prompts/outputs (as submitted), service logs (as applicable)Subprocessor
[AI/LLM Provider]
(e.g., OpenAI / Anthropic)
AI Model ProcessingGenerate AI outputs based on promptsUnited StatesPrompt inputs, lead data included in prompts, AI-generated outputsSubprocessor
[Email Delivery Service]
(e.g., SendGrid / Postmark / SES)
Email ServicesTransactional + campaign deliveryUnited StatesEmail addresses, outreach content, delivery metadata (opens/clicks/bounces)Subprocessor
[Payment Processor]
(e.g., Stripe / Paddle)
PaymentsSubscription & payment processingUnited StatesBilling info, payment method metadata, transaction IDs (we do not store full card numbers)Independent Controller (payment data) / Subprocessor (billing metadata)
[Analytics Provider]
(e.g., GA / PostHog / Mixpanel)
AnalyticsUsage analytics & performanceUnited StatesUsage patterns, device info, IP addresses (minimized/anonymized where possible)Subprocessor
[Customer Support Tools]
(e.g., Zendesk / Intercom)
SupportSupport tickets & communicationsUnited StatesSupport tickets, customer communications, account info (as needed)Subprocessor

Subprocessor compliance commitments

  • Purpose limitation: subprocessors process data only to provide services on our behalf.
  • No sale/sharing: subprocessors are contractually prohibited from “selling” or “sharing” personal information for cross-context behavioral advertising (as applicable under CPRA).
  • Deletion/return: subprocessors must delete Customer Data within 30 days of our instruction, unless retention is required by law.
  • Sub-subprocessors: subprocessors may engage sub-subprocessors only under equivalent protections; material changes follow the notice process below.

Subprocessor changes, notice, and objections

Advance notice

We will provide at least 30 days’ advance notice of material changes to this list (addition or replacement of a subprocessor), where feasible. Notice may be provided via email to the account admin, in-product notifications, and updates to this page.

Objection process

You may object on reasonable data protection grounds by emailing admin@salesgpt.work within 30 days of notice. Please include sufficient detail to evaluate the concern.

Resolution and remedy

We will attempt to address the objection in good faith (e.g., by providing additional information, offering a configuration alternative, or using a different vendor where commercially reasonable). If we cannot resolve within 30 days of receiving the objection, you may terminate the affected portion of the Service without penalty, consistent with the DPA and any enterprise agreement.

Emergency subprocessors

In rare cases (security incidents, service continuity, legal compliance), we may add or replace a subprocessor immediately. In such case, we will notify you as soon as reasonably practicable.

Enterprise notes

  • Enterprise customers may request additional documentation (audit summaries, certifications, residency options) subject to appropriate confidentiality terms.
  • For enterprise execution, SCC text and transfer documentation may be provided as part of the DPA package where required.
  • Quarterly subprocessor change summaries may be available upon request.
Email: admin@salesgpt.work (suggested subject: "Subprocessor inquiry / diligence")

Change log

  • Nov 2025: Initial subprocessor list published (v1.0)
  • Jan 2026: Hardened disclosure, governance, incident flow, and consistent 30-day objection process (v1.1)

For detailed historical changes, contact admin@salesgpt.work.

Contact

General inquiries: admin@salesgpt.work

DPO (GDPR inquiries): admin@salesgpt.work

Subprocessor objections: admin@salesgpt.work

Registered Office: BLINK REALTY PRIVATE LIMITED, FIRST FLOOR, 10, SHIVAM, OPPOSITE NARSINGH MANDIR, AGRASEN BAZAR, BEAWAR, Ajmer, Rajasthan, 305901, India.

This page is informational and does not override the DPA. The DPA governs subprocessor obligations and international transfer safeguards.