What is a Subprocessor?

At Gorilla, we use a small set of trusted third-party service providers to help us operate our platform reliably, securely, and at scale. Some of these partners process customer data in order to provide infrastructure, customer support, analytics, or product functionality. When they do so on our behalf, they qualify as Subprocessors under the GDPR. Each one is contractually bound by obligations that match or exceed those in our Data Processing Agreement (DPA).

Data Location and Safeguards for International Transfers

Where possible, we use EU-based or EU-hosted infrastructure. When data must be processed outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (SCCs) to ensure lawful transfer.

In addition to SCCs, Gorilla performs a risk-based due diligence process before engaging any non-EEA Subprocessor. This includes:

This ensures we only work with vendors who meet our internal standards and customer expectations.

How to Receive Notifications About New Subprocessors

Customers may request notification of new Subprocessors by emailing legal@gorilla.security with the subject line: “Subscribe to Subprocessor Notifications.” Upon such request, Gorilla will notify you prior to onboarding any new Subprocessor and allow ten (10) days to raise a reasonable, good-faith objection.


List of Third-Party Subprocessors

Hosting & Infrastructure Partners

These Subprocessors provide the core infrastructure used to host and store Customer Personal Data.

Subprocessor Purpose of Processing Location
Render Private server and data storage Germany, Frankfurt
Vercel Cloud hosting Germany, Frankfurt
Google Cloud Secrets storage and management via Google Cloud Secret Manager Germany, Frankfurt

Application Services

These Subprocessors support essential platform functionality, observability, and user-facing features.

Subprocessor Purpose of Processing Location
Cloudflare DNS, CDN, network security, DDoS protection EU-hosted
Sentry Application error tracking and diagnostics EU-hosted
OpenAI AI-generated content (in-app only) USA
PostHog In-product analytics and event tracking EU-hosted
Logz.io Log management and monitoring EU-hosted