Subprocessors and residency

Subprocessors and data residency note

Provider categories, data roles, regional assumptions, and what must be confirmed in the final deployment agreement.

Last reviewed: 2026-05-17. Final contractual commitments must be reviewed before signature.

Review status: Subprocessor draft. Final provider list, regions, DPAs, and retention terms must be confirmed for each customer environment.

Provider categories

Exact vendors may vary by deployment, but core categories include hosting, database, object storage, frontend hosting, payments, email, monitoring, AI, and statutory integrations.

  • Cloud host and managed database for backend workloads.
  • Frontend hosting for website and web application delivery.
  • Stripe, email provider, LHDN MyInvois, storage, monitoring, and AI provider where enabled.

Data residency

Regional hosting and data residency should be confirmed per customer contract and cloud configuration.

  • Confirm database region, storage region, and backup region before go-live.
  • Document whether AI and email providers process data outside the primary hosting region.
  • Keep subprocessors and regions updated when infrastructure changes.

Customer review

Buyers should review subprocessors, data roles, retention, export, deletion, and legal obligations before production use.

  • List provider, purpose, data type, region, and retention role.
  • Confirm whether a DPA or enterprise agreement is required.
  • Make customer data export available before cancellation or migration.

Buyer checks

Questions this document should help answer.

Which providers receive production customer data?

Where are database, object storage, and backups located?

Which integrations are optional?

What is the data export path if the buyer leaves?