Overview
Two distinct categories of third-party services touch Customer Data:
- Sub-processors — vendors who Process Personal Data on Werkdata OÜ's behalf to deliver the Service. They are bound by our DPA flow- down obligations and are listed in detail below.
- Independent controllers (Customer-controlled connectors)— external SaaS services where the Customer's administrator has connected the workspace using OAuth. These vendors are independent controllers under GDPR Art. 26 / 28 analysis and are governed by the Customer's direct contracts with them.
Infrastructure
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL | RDS Postgres, OpenSearch Serverless, S3, ECS, KMS, SES | EU (eu-central-1, Frankfurt) | EU-only; SCCs Module 2 for cross-border support tickets |
| Amazon Web Services EMEA SARL — Bedrock | On-demand embeddings (Titan Embeddings v2) for retrieval-augmented generation. Inputs are processed transiently and never used to train AWS models (per the AWS service terms for Bedrock). | EU (eu-central-1, Frankfurt) | EU-only |
Authentication & identity
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| WorkOS, Inc. | AuthKit (sign-in / sign-up), SSO (SAML / OIDC), Directory Sync (SCIM) | US (with EU data-residency add-on for SSO Enterprise tenants) | SCCs Module 2 + EU-US Data Privacy Framework |
Billing & tax
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Stripe Payments Europe, Limited | Subscription billing, payment processing, Stripe Tax, OSS reporting, customer portal | EU (Stripe Ireland) with US fail-over | SCCs Module 2 + EU-US Data Privacy Framework |
Operational telemetry
| Sub-processor | Purpose | Region | Transfer mechanism |
|---|---|---|---|
| Functional Software Sweden AB (Sentry) | Error reporting (request bodies scrubbed before transmission) | EU (eu.sentry.io) | EU-only |
Customer-controlled connectors
When a Customer connects an external SaaS source — currently any of GitHub, Google Drive, Slack, Linear, Notion, Atlassian (Jira, Confluence, Bitbucket), GitLab, Sentry, Figma, Vercel, Airtable, Dropbox, Trello— OrgMCP holds the OAuth tokens that the Customer's administrator granted. These upstream services are independent controllers with respect to the data they store; OrgMCP is nota sub-processor of these providers. The data they expose flows through their APIs and is processed under the Customer's direct contract with each provider.
Domain registration is handled through Cloudflare Registrar. The registrar service does not process Personal Data of OrgMCP customers, and is therefore not a sub-processor under this Annex. Authoritative DNS for orgmcp.io is provided by AWS Route 53, which is in scope of the AWS sub-processor row above.
How we notify you of changes
To receive 30-day advance notice of new sub-processors:
- Email privacy@orgmcp.io with the subject “Subscribe to sub-processor change notifications” and your workspace slug, or
- Enable
notify_subprocessor_changesfrom your workspace Settings (Business and Enterprise plans).
Subscribed customers may object in writing within the notice window; if the objection cannot be resolved, the Customer may terminate the affected processing (see DPA §6.4).
Changelog
- v2.0 — 12 May 2026 — Removed the misclassified Cloudflare DNS / WAF / edge-proxy row (Cloudflare is the domain registrar only; authoritative DNS is AWS Route 53 and WAF is AWS WAFv2). Added AWS Bedrock as a distinct sub-processor line item so the embeddings path is explicit. Promoted the “How we notify you of changes” protocol from a JSDoc comment to a customer-visible section. Source-of-truth data moved into
_constants.tsso the Privacy Policy and this page cannot drift. - v1.0 — 1 April 2026 — Initial publication.