Loading...
Back to top
Security & Trust

Subprocessors

Page last updated: July 8, 2026

Registry initially published: October 16, 2025

CoSkip uses carefully selected service providers to deliver, secure, monitor, and improve AI-guided field workflows. This page explains who may support the service, why they are used, what categories of data may be processed, and how customers can review changes.

  • Public registry
  • DPA/SCCs where applicable
  • Security review
  • Purpose-limited processing
  • Minimum data principle
  • Change notifications
How CoSkip uses subprocessors

Purpose-built providers for defined service functions

Subprocessors help CoSkip provide core infrastructure, communication, analytics, diagnostics, support, and internal collaboration functions. CoSkip uses subprocessors only for defined purposes and seeks to limit data access to what is necessary for the relevant service, feature, or customer configuration.

Purpose-limited support

Providers are used to support specific service functions such as hosting, email delivery, diagnostics, analytics, customer support, or operational collaboration.

Written safeguards

CoSkip expects subprocessor relationships to be governed by written terms that address confidentiality, data protection, security, and processing instructions.

Configuration dependent

Actual data flows may vary by enabled features, pilot scope, integrations, region settings, and customer configuration.

Transparent review path

Customers can review this registry, monitor updates, and contact CoSkip with vendor, DPA, region, or procurement questions.

Registry

Subprocessor registry

The registry below summarizes current subprocessors and service providers that may process personal information or customer-related data in connection with CoSkip services. Scope varies by feature, customer configuration, pilot design, and enabled integrations.

Data flow varies by configuration. Admins can request a feature-by-feature data flow during onboarding or vendor review.

Cloud infrastructure Email Analytics Diagnostics Support / CRM Collaboration
Current CoSkip subprocessors, purposes, data categories, regions, safeguards, and scope.
Category Subprocessor Purpose / function Data types processed Region / data location Safeguards Status / scope
Cloud infrastructure Amazon Web Services (AWS) Primary hosting, storage, and compute for backend APIs and services. Customer metadata; job logs; device telemetry (pseudonymized); limited support data. USA; additional regions as configured. SOC 2 / ISO 27001; DPA; SCCs where applicable. Core / configuration-dependent
Cloud infrastructure Google Cloud Platform (GCP) Secondary infrastructure; AI inference pipelines; data processing jobs. Pseudonymized usage data; AI inference logs; aggregated analytics outputs. USA / EU as configured. SOC 2 / ISO 27001; DPA; SCCs. Feature-dependent
Cloud infrastructure Microsoft Azure Edge and AR model deployment; image recognition; on-device sync services. Image frames where enabled; timestamped events; diagnostics. Global regions based on customer/admin selection where available. SOC 2 / ISO 27001; DPA; SCCs. Feature-dependent
Email SendGrid (Twilio) Transactional and pilot-program email delivery. Name; email; message metadata; IP in provider logs. USA. DPA; SCCs; DMARC/SPF/DKIM enforced. Communication-related
Analytics Google Analytics (GA4) Website/app performance and usage analytics. Aggregated usage; device/browser info; IP, anonymized when configured. Global. Consent-based where required; IP anonymization where configured; DPA; SCCs. Optional analytics
Analytics Meta Analytics (Meta Pixel) Conversion measurement and campaign performance. Website interaction events and pseudonymized identifiers. Global. Consent-based where required; limited configuration. Optional marketing
Errors / diagnostics Sentry or equivalent such as Datadog / Rollbar Application error tracking and performance diagnostics. Stack traces; user agent; pseudonymized IDs; limited request metadata. USA / EU vendor region options. DPA; SCCs; data scrubbing rules enabled. Diagnostics
Support / CRM HubSpot, if enabled Waitlist and pilot signup CRM; email newsletters. Name; email; company; role; consent flags. USA / EU. DPA; SCCs; consent management. Optional / if enabled
Collaboration Atlassian Jira/Confluence Internal work tracking and documentation. Project metadata; support ticket references; no customer content stored unless explicitly entered into support workflows. USA / EU cloud. DPA; SCCs; SSO/MFA enforced. Internal operations
Review lifecycle

How subprocessors are reviewed

Subprocessors are evaluated through the lens of purpose, data categories, contractual safeguards, configuration, monitoring, and customer notification. The process is practical, because actual data paths can vary by pilot scope and enabled features.

EvaluatePurpose and data fit
ContractWritten safeguards
ConfigureLeast practical data
DiscloseRegistry and notice
  1. 01

    Identify the purpose

    We identify the business, security, product, or operational purpose for the provider.

  2. 02

    Review data categories

    We evaluate what data may be processed and whether the provider is necessary for the feature or workflow.

  3. 03

    Contractual safeguards

    We seek appropriate written terms for confidentiality, security, data protection, and processing instructions.

  4. 04

    Configure for least data

    We limit data movement where practical through configuration, scoping, retention settings, or feature-level controls.

  5. 05

    Monitor and update

    We review vendors as the product evolves and update this page when relevant changes are made.

  6. 06

    Notify customers

    We provide advance notice for new subprocessors where required by our DPA, terms, or customer commitments.

Data categories

What data may be involved

The exact data categories depend on the customer, pilot scope, enabled features, integrations, and configuration. CoSkip's product direction is to keep data use purposeful and tied to the workflow, proof, support, security, or operational need.

Not every subprocessor receives every data category. Data sharing depends on the provider's role, enabled feature, customer configuration, and processing purpose.

01Technician workflow
02Proof capture
03Scoped provider support
04Admin review and export
Account and contact information Company and role information Workflow metadata Job or asset context when provided Technician notes Photos or visual evidence where enabled Timestamps and step status Device/browser information Usage and diagnostics Support request details Email and communication metadata Aggregated analytics
Regions and safeguards

Regions, transfers, and safeguards

Data location and transfer mechanisms can vary by provider, region settings, customer configuration, and enabled features. Where applicable, CoSkip expects subprocessors to support appropriate contractual, organizational, and technical safeguards.

DPA / written terms

Subprocessor relationships are expected to be governed by written terms where applicable.

SCCs where applicable

Transfer mechanisms are reviewed where international transfer requirements apply.

Security review

Providers are reviewed for their role, data categories, and practical risk profile.

Access control

Access should be limited by purpose, role, configuration, and operational need.

Encryption and secure transport

Secure transport and encryption are expected where applicable and supported.

Logging and diagnostics controls

Diagnostics and logs should be scoped to help operate and secure the service.

Consent-based analytics

Analytics are configured around consent and regional requirements where required.

Data minimization

Data movement is scoped by feature, customer configuration, and processing purpose.

Customer notice

Change notifications and objections

CoSkip will post updates to this page at least 30 days before adding a new subprocessor, unless a shorter period is required for security, availability, legal, or operational reasons. Customers may object on reasonable data-protection grounds by contacting CoSkip.

We will work in good faith to address concerns, which may include clarifying the vendor role, adjusting configuration, identifying an available workaround, or disabling an affected optional feature where practical.

Ask about a subprocessor

Change log

  • Page redesigned for clearer registry review, vendor-review navigation, and customer transparency. No material subprocessor changes.
  • Initial public registry published, including AWS, GCP, Azure, SendGrid, GA4, Meta Pixel, Sentry, optional HubSpot, and Atlassian.
Vendor review

Questions for privacy, procurement, or vendor review?

For DPA questions, region commitments, vendor questionnaires, data-flow requests, or procurement review, contact CoSkip.

Privacy / DPA
[email protected]
Security / vendor review
[email protected]
Legal entity
CoSkip, Inc., a Delaware corporation
Location
Queens / New York City
Pilot review

Start with one workflow. Review the data path before rollout.

CoSkip helps field teams guide work, capture proof, and close out jobs with clearer records. For pilots and enterprise reviews, we help teams understand the workflow, data path, vendor dependencies, and review requirements before expanding.

Apply to Become a Pilot Partner

Tell us a bit about your team. We'll follow up with next steps.

Join the Waitlist

Get launch updates and early access invites.