Purpose-limited support
Providers are used to support specific service functions such as hosting, email delivery, diagnostics, analytics, customer support, or operational collaboration.
Page last updated: July 8, 2026
Registry initially published: October 16, 2025
CoSkip uses carefully selected service providers to deliver, secure, monitor, and improve AI-guided field workflows. This page explains who may support the service, why they are used, what categories of data may be processed, and how customers can review changes.
Subprocessors help CoSkip provide core infrastructure, communication, analytics, diagnostics, support, and internal collaboration functions. CoSkip uses subprocessors only for defined purposes and seeks to limit data access to what is necessary for the relevant service, feature, or customer configuration.
Providers are used to support specific service functions such as hosting, email delivery, diagnostics, analytics, customer support, or operational collaboration.
CoSkip expects subprocessor relationships to be governed by written terms that address confidentiality, data protection, security, and processing instructions.
Actual data flows may vary by enabled features, pilot scope, integrations, region settings, and customer configuration.
Customers can review this registry, monitor updates, and contact CoSkip with vendor, DPA, region, or procurement questions.
The registry below summarizes current subprocessors and service providers that may process personal information or customer-related data in connection with CoSkip services. Scope varies by feature, customer configuration, pilot design, and enabled integrations.
Data flow varies by configuration. Admins can request a feature-by-feature data flow during onboarding or vendor review.
| Category | Subprocessor | Purpose / function | Data types processed | Region / data location | Safeguards | Status / scope |
|---|---|---|---|---|---|---|
| Cloud infrastructure | Amazon Web Services (AWS) | Primary hosting, storage, and compute for backend APIs and services. | Customer metadata; job logs; device telemetry (pseudonymized); limited support data. | USA; additional regions as configured. | SOC 2 / ISO 27001; DPA; SCCs where applicable. | Core / configuration-dependent |
| Cloud infrastructure | Google Cloud Platform (GCP) | Secondary infrastructure; AI inference pipelines; data processing jobs. | Pseudonymized usage data; AI inference logs; aggregated analytics outputs. | USA / EU as configured. | SOC 2 / ISO 27001; DPA; SCCs. | Feature-dependent |
| Cloud infrastructure | Microsoft Azure | Edge and AR model deployment; image recognition; on-device sync services. | Image frames where enabled; timestamped events; diagnostics. | Global regions based on customer/admin selection where available. | SOC 2 / ISO 27001; DPA; SCCs. | Feature-dependent |
| SendGrid (Twilio) | Transactional and pilot-program email delivery. | Name; email; message metadata; IP in provider logs. | USA. | DPA; SCCs; DMARC/SPF/DKIM enforced. | Communication-related | |
| Analytics | Google Analytics (GA4) | Website/app performance and usage analytics. | Aggregated usage; device/browser info; IP, anonymized when configured. | Global. | Consent-based where required; IP anonymization where configured; DPA; SCCs. | Optional analytics |
| Analytics | Meta Analytics (Meta Pixel) | Conversion measurement and campaign performance. | Website interaction events and pseudonymized identifiers. | Global. | Consent-based where required; limited configuration. | Optional marketing |
| Errors / diagnostics | Sentry or equivalent such as Datadog / Rollbar | Application error tracking and performance diagnostics. | Stack traces; user agent; pseudonymized IDs; limited request metadata. | USA / EU vendor region options. | DPA; SCCs; data scrubbing rules enabled. | Diagnostics |
| Support / CRM | HubSpot, if enabled | Waitlist and pilot signup CRM; email newsletters. | Name; email; company; role; consent flags. | USA / EU. | DPA; SCCs; consent management. | Optional / if enabled |
| Collaboration | Atlassian Jira/Confluence | Internal work tracking and documentation. | Project metadata; support ticket references; no customer content stored unless explicitly entered into support workflows. | USA / EU cloud. | DPA; SCCs; SSO/MFA enforced. | Internal operations |
Subprocessors are evaluated through the lens of purpose, data categories, contractual safeguards, configuration, monitoring, and customer notification. The process is practical, because actual data paths can vary by pilot scope and enabled features.
We identify the business, security, product, or operational purpose for the provider.
We evaluate what data may be processed and whether the provider is necessary for the feature or workflow.
We seek appropriate written terms for confidentiality, security, data protection, and processing instructions.
We limit data movement where practical through configuration, scoping, retention settings, or feature-level controls.
We review vendors as the product evolves and update this page when relevant changes are made.
We provide advance notice for new subprocessors where required by our DPA, terms, or customer commitments.
The exact data categories depend on the customer, pilot scope, enabled features, integrations, and configuration. CoSkip's product direction is to keep data use purposeful and tied to the workflow, proof, support, security, or operational need.
Not every subprocessor receives every data category. Data sharing depends on the provider's role, enabled feature, customer configuration, and processing purpose.
Data location and transfer mechanisms can vary by provider, region settings, customer configuration, and enabled features. Where applicable, CoSkip expects subprocessors to support appropriate contractual, organizational, and technical safeguards.
Subprocessor relationships are expected to be governed by written terms where applicable.
Transfer mechanisms are reviewed where international transfer requirements apply.
Providers are reviewed for their role, data categories, and practical risk profile.
Access should be limited by purpose, role, configuration, and operational need.
Secure transport and encryption are expected where applicable and supported.
Diagnostics and logs should be scoped to help operate and secure the service.
Analytics are configured around consent and regional requirements where required.
Data movement is scoped by feature, customer configuration, and processing purpose.
CoSkip will post updates to this page at least 30 days before adding a new subprocessor, unless a shorter period is required for security, availability, legal, or operational reasons. Customers may object on reasonable data-protection grounds by contacting CoSkip.
We will work in good faith to address concerns, which may include clarifying the vendor role, adjusting configuration, identifying an available workaround, or disabling an affected optional feature where practical.
Ask about a subprocessorProcurement, privacy, legal, and security teams can monitor this page for changes using the available feeds or email updates.
Use the JSON file for internal vendor tracking and procurement review.
RSS feedRegistry update feedMonitor registry change notices through your feed reader or internal system.
Email updatesAsk to be notifiedContact privacy review to request subprocessor change updates.
For DPA questions, region commitments, vendor questionnaires, data-flow requests, or procurement review, contact CoSkip.
CoSkip helps field teams guide work, capture proof, and close out jobs with clearer records. For pilots and enterprise reviews, we help teams understand the workflow, data path, vendor dependencies, and review requirements before expanding.