Subprocessors

oklido uses third-party services (subprocessors) to provide our service. All subprocessors are bound by data processing agreements and meet our security standards.

Current Subprocessors

Infrastructure

SubprocessorPurposeLocationCompliance
Amazon Web Services (AWS)Cloud hosting, storage, database, emailEU (London, eu-west-2)SOC 2, ISO 27001, GDPR
VercelFrontend hosting, CDNGlobal (EU primary)SOC 2, GDPR

Authentication & Identity

SubprocessorPurposeLocationCompliance
Auth0 (Okta)User authentication, SSO, MFAEUSOC 2, ISO 27001, GDPR

Payments

SubprocessorPurposeLocationCompliance
StripePayment processing, billingEUPCI DSS Level 1, SOC 2, GDPR

Email

SubprocessorPurposeLocationCompliance
Amazon SESTransactional emailEU (London)SOC 2, ISO 27001, GDPR

Monitoring & Analytics

SubprocessorPurposeLocationCompliance
AWS CloudWatchApplication monitoring, loggingEU (London)SOC 2, ISO 27001

Data Processing Details

What Data Each Subprocessor Receives

SubprocessorData Processed
AWSAll data (encrypted)
VercelWeb traffic, anonymous usage
Auth0Email, name, authentication events
StripeBilling information, payment methods
Amazon SESEmail addresses, notification content

Data Protection Measures

All subprocessors:

  • Have signed Data Processing Agreements
  • Meet our security requirements
  • Are regularly reviewed
  • Support GDPR requirements

Subprocessor Changes

Notification

We notify customers of subprocessor changes:

  • New subprocessor: 30 days advance notice
  • Changed purpose: 30 days advance notice
  • Removed subprocessor: No notice required

How We Notify

  • Email to account administrators
  • Update to this page
  • Changelog entry

Objections

If you object to a new subprocessor:

  1. Contact privacy@oklido.com within 30 days
  2. We'll discuss your concerns
  3. If unresolved, you may terminate your subscription

Due Diligence

How We Evaluate Subprocessors

Before engaging a subprocessor:

  1. Security assessment - Review their security practices
  2. Compliance verification - Check certifications
  3. DPA execution - Sign data processing agreement
  4. Ongoing monitoring - Regular reviews

What We Require

All subprocessors must:

  • Implement appropriate security measures
  • Process data only as instructed
  • Assist with data subject requests
  • Notify us of security incidents
  • Delete data when no longer needed

International Transfers

Current Status

All primary data processing occurs in the UK/EU.

Safeguards for Non-EU Processing

When data is processed outside the UK/EU:

  • Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreement
  • Adequacy decisions where applicable

Subprocessors Outside EU

SubprocessorLocationSafeguard
Auth0 (backup)USSCCs
StripeUSSCCs
VercelUS (CDN nodes)SCCs

Primary data always remains in the UK/EU.

Subscribe to Changes

To receive notifications about subprocessor changes:

  1. Ensure you're an account administrator
  2. Notifications sent automatically to admin email
  3. Or check this page periodically

Changelog

January 2026

  • Initial subprocessor list published

Questions

For subprocessor questions:


Last updated: January 2026