Legal documents

Sub-processors (Annex III)

OrgMCP relies on a small set of carefully vetted sub-processors to deliver the Service. Each sub-processor is bound by a written agreement that imposes data-protection obligations no less protective than those set out in our Data Processing Addendum. Customers with notify_subprocessor_changes enabled receive 30-day advance notice of any change.

Effective
23 July 2026
Version
v2.0
Last updated
23 July 2026
Operator
Werkdata OÜ · Tallinn, Estonia
Need the signed PDF? Email legal@orgmcp.io.

Overview

Two distinct categories of third-party services touch Customer Data:

  • Sub-processors — vendors who Process Personal Data on Werkdata OÜ's behalf to deliver the Service. They are bound by our DPA flow- down obligations and are listed in detail below.
  • Independent controllers (Customer-controlled connectors)— external SaaS services where the Customer's administrator has connected the workspace using OAuth. These vendors are independent controllers under GDPR Art. 26 / 28 analysis and are governed by the Customer's direct contracts with them.

Infrastructure

Sub-processorPurposeRegionTransfer mechanism
Amazon Web Services EMEA SARLRDS Postgres, OpenSearch Serverless, S3, ECS, KMS, SESEU (eu-central-1, Frankfurt)EU-only; SCCs Module 2 for cross-border support tickets
Amazon Web Services EMEA SARL — BedrockOn-demand embeddings (Titan Embeddings v2) for retrieval-augmented generation. Inputs are processed transiently and never used to train AWS models (per the AWS service terms for Bedrock).EU (eu-central-1, Frankfurt)EU-only

Authentication & identity

Sub-processorPurposeRegionTransfer mechanism
WorkOS, Inc.AuthKit (sign-in / sign-up), SSO (SAML / OIDC), Directory Sync (SCIM)US (with EU data-residency add-on for SSO Enterprise tenants)SCCs Module 2 + EU-US Data Privacy Framework

Billing & tax

Sub-processorPurposeRegionTransfer mechanism
Stripe Payments Europe, LimitedSubscription billing, payment processing, Stripe Tax, OSS reporting, customer portalEU (Stripe Ireland) with US fail-overSCCs Module 2 + EU-US Data Privacy Framework

Operational telemetry

Sub-processorPurposeRegionTransfer mechanism
Functional Software Sweden AB (Sentry)Error reporting (request bodies scrubbed before transmission)EU (eu.sentry.io)EU-only

Customer-controlled connectors

When a Customer connects an external SaaS source — currently any of GitHub, Google Drive, Slack, Linear, Notion, Atlassian (Jira, Confluence, Bitbucket), GitLab, Sentry, Figma, Vercel, Airtable, Dropbox, Trello— OrgMCP holds the OAuth tokens that the Customer's administrator granted. These upstream services are independent controllers with respect to the data they store; OrgMCP is nota sub-processor of these providers. The data they expose flows through their APIs and is processed under the Customer's direct contract with each provider.

Domain registration is handled through Cloudflare Registrar. The registrar service does not process Personal Data of OrgMCP customers, and is therefore not a sub-processor under this Annex. Authoritative DNS for orgmcp.io is provided by AWS Route 53, which is in scope of the AWS sub-processor row above.

How we notify you of changes

To receive 30-day advance notice of new sub-processors:

  1. Email privacy@orgmcp.io with the subject “Subscribe to sub-processor change notifications” and your workspace slug, or
  2. Enable notify_subprocessor_changes from your workspace Settings (Business and Enterprise plans).

Subscribed customers may object in writing within the notice window; if the objection cannot be resolved, the Customer may terminate the affected processing (see DPA §6.4).

Changelog

  • v2.012 May 2026Removed the misclassified Cloudflare DNS / WAF / edge-proxy row (Cloudflare is the domain registrar only; authoritative DNS is AWS Route 53 and WAF is AWS WAFv2). Added AWS Bedrock as a distinct sub-processor line item so the embeddings path is explicit. Promoted the “How we notify you of changes” protocol from a JSDoc comment to a customer-visible section. Source-of-truth data moved into_constants.ts so the Privacy Policy and this page cannot drift.
  • v1.01 April 2026Initial publication.