SoSafe – List of Sub-Processors
Effective September 20, 2026
SoSafe engages the following third-party entities (referred to as “sub-processors”) to process personal data on behalf of its customers. These sub-processors operate under contractual agreements with SoSafe, ensuring adherence to the commitments outlined in the SoSafe Data Processing Agreement.
To maintain compliance, SoSafe conducts annual reviews of its sub-processors and requires them to implement appropriate technical and organisational measures. These measures are designed to safeguard the processing of personal data in accordance with applicable data protection laws.
The list below details the sub-processors supporting SoSafe’s Awareness Building Services.
| Sub-processor | Optional / Non-optional | Purpose of Processing | Measures Taken to Protect Personal Data. Compliance and Security Certificates | Data Storage Location |
| Amazon Web Services EMEA SARL (Amazon Web Services, Inc. as the contractual party of the EU standard contractual clauses) 38 Avenue John F. Kennedy L-1855, Luxemburg Luxemburg | Non-optional | Hosting of all current and future components essential for the operational functionality of the SoSafe Platform, including API interfaces, data storage systems, analytical tools, hosting of (optional) AI chatbots and tools, and communication capabilities. | – Conclusion of a data processing agreement as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021), incl. numerous obligations of AWS on handling and transparency in case of potential authority requests. – Amazon Web Services, Inc., is an active participant in the EU-US Data Privacy Framework. – Storage of and, to the extent made available by AWS to its customers for the respective service, processing of all Controller data in certified data centers in the EU. To ensure low latency and high transfer speeds worldwide, we use Amazon CloudFront, AWS’s global content delivery network (CDN). This is a performance/optimization service that may transmit or cache content globally but does not change the primary data storage location. – Encryption of data with industry-standard encryption products: Encryption at Rest via AES 256 . Encryption in Transit via TLS 1.2+. – AWS EMEA SARL is ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 42001, SOC 2 Type II, SOC 3 and CSA STAR certified. – More information: https://aws.amazon.com/compliance/programs/ | EU |
| Optional | Amazon Bedrock Provision interactive awareness and support and other AI-powered tools. This provider is only required to the extent the Controller enables the usage of AI. | |||
| Zendesk, Inc. 181 Fremont St 17th Floor San Francisco, CA 94105 USA | Non-optional | Provision of customer support and ticketing services, including the management, tracking and resolution of customer inquiries and support requests, and the use of AI and machine learning functionalities to assist with, automate and improve customer support operations. | – Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Zendesk, Inc. is an active participant in the EU-US Data Privacy Framework. – Storage and processing of all Controller data in data centers in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256. Encryption in Transit via TLS 1.2+. – Zendesk Inc. is ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 2 Type II, ISO 42001 and CSA STAR Levels 1 & 2 certified. – More information: https://www.zendesk.com/trust-center/ | EU |
| Atlassian Pty Ltd. Level 6, 341 George Street, Sydney, NSW 2000 Australia | Non-optional | Provision of customer support and ticketing services, including the management, tracking and resolution of customer inquiries and support requests. This provider is only relevant for complex cases. | – Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Storage and processing of all Controller data in data centers in the EU and, to the extent a EU-only solution is not available by Atlassian (according to Atlassian Statement), in Australia. – Encryption of data with industry-standard encryption products: Encryption at Rest via AES 256 Encryption in Transit via TLS 1.2+ with Perfect Forward Secrecy (PFS). – Atlassian Pty Ltd is ISO 27001, and SOC 2 Type II certified. – More information: https://www.atlassian.com/trust – Transfer Impact Assessment (TIA) conducted by Processor’s external Data Protection Officer. | EU and, to the extent an EU-only solution is not available by Atlassian, Australia. |
| Amplitude Inc. 201 3rd Street, Suite 200, San Francisco, CA 94103 USA | Non-optional | Provision of product analytics services for tracking and analysing user interactions within the SoSafe Platform, enabling measurement of feature adoption, analysis of user journeys, and data-driven product improvements | – Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Amplitude, Inc. is an active participant in the EU-US Data Privacy Framework. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES 256 Encryption in Transit via TLS 1.2+ – Amplitude, Inc. is ISO 27001, ISO 27017, ISO 27018 and SOC 2 Type II certified. – More information: https://amplitude.com/security-and-privacy and https://trust.amplitude.com/?tab=overview | EU |
| Planhat AB Malmskillnadsgatan 13, 111 57 Stockholm Sweden | Non-optional | Provision of customer success management and account management services. This provider is only relevant if the Controller uses Processor’s customer support or interacts with Processor for other operational purposes related to the services. | – Conclusion of a data processing agreement. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256 Encryption in Transit via TLS 1.2+ – Planhat AB is ISO 27001 and SOC 2 Type II certified. – More information: https://www.planhat.com/security-statement/ | EU |
| Datadog Inc. 620 8th Ave., 45th Fl., New York, NY 10018 USA | Non-optional | Provision of technical monitoring service for hybrid cloud applications provided on a SaaS-based data analytics platform. | – Conclusion of a data processing agreement as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Datadog, Inc. is an active participant in the EU-US Data Privacy Framework. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products:: Encryption at Rest via AES 256 Encryption in Transit via TLS and HSTS If encrypted communication is interrupted the Datadog application is inaccessible. – Datadog Inc. is ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001 and SOC 2 Type II certified. – More information: https://trust.datadoghq.com/ | EU |
| Functional Software, Inc. dba “Sentry” 45 Fremont Street, 8th Floor San Francisco, CA 94105-2250 USA | Non-optional | Product error tracking and performance monitoring | – Conclusion of a data processing agreement as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Sentry.io is an active participant in the EU-US Data Privacy Framework. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES 256 Encryption in Transit via AES 256 and TLS – Sentry is ISO 27001 and SOC 2 Type II certified. – More information: https://sentry.io/security/ | EU |
| Sub-processor | Optional / Non-optional | Purpose of Processing | Measures Taken to Protect Personal Data. Compliance and Security Certificates | Data Storage Location |
| Lingo.dev (Replexica, Inc.) 2261 Market Street STE 46186, San Francisco, California 94114 USA | Optional | AI-driven localization of product UI strings and content at build time, including processing of translation APIs, glossaries, and brand voice guidelines. This provider is only required to the extent the Controller enables the usage of AI. | – Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES 256 Encryption in Transit via TLS 1.2+ – Lingo.dev is SOC Type II certified. – More information: https://trust.delve.co/lingo.dev – Transfer Impact Assessment (TIA) conducted by SoSafe’s external Data Protection Officer. | EU |
| Kombo Technologies GmbH, Lohmühlenstraße 65, 12435 Berlin Germany | Optional | Integration of Controller Active Directory. This provider is only required to the extent the Controller requests Active Directory integration for automated uploading and regular updating of end-user data on the Processor platform. | – Conclusion of a data processing agreement. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256, including backup copies. Encryption in Transit : All outgoing traffic (to integration APIs) uses the highest TLS version available by the respective integration’s API (e.g., Google Workspace). All incoming traffic via the Kombo API is enforced to use TLS 1.3. Connections from Kombo’s application workloads to Kombo’s database also use TLS 1.3 with an AES-256 cipher. – Kombo Technologies GmbH is ISO 27001 and SOC 2 Type II certified. – More information: https://security.kombo.dev/ | EU |
| Vonage B.V. Radarweg 29A, Office 10.42, 1043 NX Amsterdam The Netherlands | Optional | Provision of mobile services for conducting Smishing Simulations. This provider is only required to the extent the Controller activated Smishing features. | – Conclusion of a data processing agreement. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256. Encryption in Transit via TLS 1.2+ for API, and SRTP for actual voice and video data transmitted during a VoIP call. – Vonage B.V. is ISO 27001 and SOC 2 Type II certified. – More information: https://www.vonage.com/security/. and https://www.vonage.com/legal/technical-organizational-security-practices/ | EU |
| Eleven Labs Inc. 169 Madison Ave #2484 New York, NY 10016 USA | Optional | Provision of AI-powered generative voice technology used to conduct vishing simulations via AI voice agents and to generate cloned voices from audio samples that replicate an individual’s vocal characteristics (subject to the individual’s explicit consent) This provider is only required to the extent the Controller activated Vishing features. | — Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Eleven Labs Inc. is an active participant in the EU-US Data Privacy Framework. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256. Encryption in Transit viaTLS 1.2+. – Eleven Labs Inc. is ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 2 Type II and CSA Star Level 1 certified. – More information: https://compliance.elevenlabs.io/ | EU |
| Leen, Inc. (dba Leen.dev) Delaware 52 2nd Street, Floor 3, San Francisco CA 94105 USA | Optional | Scalable security tool integrations, enabling the ingestion and processing of third-party security signals. This provider is only required to the extent the Controller requests security stack integration. | – Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256 and key management is handled via AWS KMS. Encryption in Transit via TLS 1.2+ – Leen.dev is SOC 2 Type II certified. – More information : https://www.leen.dev/ – Transfer Impact Assessment (TIA) conducted by SoSafe’s external Data Protection Officer. | EU |
| Google Cloud EMEA Ltd 70 Sir John Rogerson’s Quay Dublin 2 Ireland | Optional | Provision of interactive support, text creation and analysis, and other AI-powered tools. This provider is only required to the extent the Controller enables the usage of AI. | — Conclusion of a data processing agreement. – Storage and processing of all Controller data in data centers located in the EU. – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES-256 Encryption in Transit via TLS 1.3 – Google Cloud is ISO 27001, ISO 42001, SOC 2 and SOC 3 certified. – More information: https://cloud.google.com/compliance?hl=en | EU |
| Anthropic Ireland, Ltd 6th Floor South Bank House, Barrow Street, Dublin 4, Dublin Ireland | Optional | Provision of interactive support, text creation and analysis, and other AI-powered tools. This provider is only required to the extent the Controller enables the usage of AI. | – Conclusion of a data processing agreement, as well as the conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Encryption of all data with industry-standard encryption products : Encryption at Rest via AES-256 GCM Encryption in Transit via TLS 1.2+ – Anthropic Ireland, Ltd is ISO27001, ISO 42001, SOC 2 Type II and CSA STAR Level 2 certified. – More information: https://trust.anthropic.com/ – Transfer Impact Assessment (TIA) conducted by SoSafe’s external Data Protection Officer. | US |
| OpenAI Ireland Ltd. (OpenAI OpCo, LLC as the contractual party of the DPA), 1st Floor, The Liffey Trust Centre 117-126 Sheriff Street Upper Dublin 1, D01 YC43 Ireland | Optional | Provision of interactive awareness and support and other AI-powered tools. This provider is only required to the extent the Controller enables the usage of AI.. | – Conclusion of a data processing agreement as well as conclusion of the EU standard contractual clauses ((EU) 2021/914, 4.6.2021). – Encryption of all data with industry-standard encryption products: Encryption at Rest via AES 256. Encryption in Transit via TLS 1.2+ – Open AI Ireland Ltd. is ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 42001, SOC 2 Type II, SOC 3 and CSA STAR Level 1 certified. – More information: https://trust.openai.com/ – Transfer Impact Assessment (TIA) conducted by SoSafe’s external Data Protection Officer. | EU, and, to the extent an EU-only solution is not available, the US. |
If you are contracting with another entity than SoSafe SE, SoSafe SE will be a sub-processor, as well.
Further details regarding privacy and security are available on the SoSafe Trust Center.








