Subprocessors and service providers
Last updated September 7, 2026
The core-service table identifies providers that may process personal data while Warpix delivers or supports a customer workspace. The website table covers marketing and scheduling tools that do not receive workspace content through the product.
Core service and support
| Provider | Purpose and data | Processing location | Provider information |
|---|---|---|---|
| RackNerd | Primary virtual-server infrastructure for the Warpix API, PostgreSQL databases, self-hosted identity service, encrypted traffic termination, and operational logs. It may host all Customer Data and service metadata. | United States, current primary server region | Privacy policy |
| Cloudflare | Authoritative DNS and global static delivery for the dashboard, widget, and landing site. Cloudflare may process IP addresses and request/security metadata for those static requests. Warpix API and identity traffic currently use DNS-only records and do not pass through Cloudflare's reverse proxy. | Global edge network | DPA and subprocessors |
| Zoho Mail | Customer support, legal, privacy, security, onboarding, and incident email. It processes message content, contact details, delivery metadata, and attachments that a sender chooses to provide. | Provider infrastructure and configured account region; international processing may occur as described by Zoho | Privacy policy and privacy FAQ |
A provider's public privacy policy is transparency information, not proof of an Article 28-compatible subprocessor agreement. Before any customer is activated under the Warpix DPA, Warpix must retain the processor and confidentiality terms required for every core provider that will process that customer's personal data. If the required terms cannot be established, the affected processing will not be activated.
Website and early-access services
| Provider | Purpose and data | Processing location | Provider information |
|---|---|---|---|
| Formspark | Receives early-access form fields, submitter IP address, and request metadata. It is not used for Warpix workspace content. | European Economic Area for primary form storage; disclosed providers may process elsewhere | Privacy policy and subprocessors |
| Cloudflare Turnstile | Detects abusive or automated early-access form submissions using browser, network, and challenge signals. It is not used to profile workspace content. | Global edge network | DPA and privacy policy |
| Calendly | Processes contact and scheduling details a visitor supplies when booking a workflow call. | Provider infrastructure and disclosed subprocessor locations | Privacy notice, DPA, and subprocessors |
| PostHog EU Cloud | Limited landing-site page views and explicit interaction events with a session-scoped identifier. Warpix does not send form values, names, email addresses, company details, session recordings, or workspace content. | EU Cloud endpoint selected; disclosed providers may process internationally | Privacy policy, DPA, and trust center |
Warpix-managed components
ZITADEL and PostgreSQL run as Warpix-managed software on the primary server. They are not separate third-party subprocessors. Open-source libraries used inside Warpix do not receive Customer Data merely because they are part of the software.
Customer-directed services
A service that Customer independently connects to, controls, or asks Warpix to send data to is not a Warpix subprocessor merely because it interoperates with Warpix. Its terms and privacy practices are Customer's responsibility unless the order form says otherwise.
Changes, notice, and objections
Warpix may replace a provider or add one needed to operate the Service. For an active customer, Warpix will provide at least 14 calendar days' advance notice through the designated contact before a new core subprocessor begins processing Customer Personal Data, where reasonably practicable. Emergency security or availability changes may take effect sooner, with notice as soon as reasonably practicable.
Customer may object during the notice period by emailing hello@warpix.io with reasonable data-protection grounds. The parties will try in good faith to resolve the concern, including a commercially reasonable configuration or provider alternative. If they cannot, Customer may terminate the affected Service as provided by the order form and request export and deletion.
Transfer readiness
Provider locations and public policies do not by themselves establish a lawful international-transfer mechanism. Before activating a customer subject to restricted-transfer rules, Warpix and Customer must confirm the relevant provider agreements and execute any required Standard Contractual Clauses, UK Addendum, or other valid mechanism.