Sub-processors
Effective: July 31, 2026
A "sub-processor" is a third-party service provider that processes Customer Personal Data on behalf of Meridian Vertex LLC, doing business as LicensePulse ("LicensePulse") to deliver the Service. Each sub-processor is bound by a written data-processing contract that imposes obligations at least as protective as our Data Processing Agreement.
We give customers at least 14 days' advance notice of any new sub-processor (subscribe to updates by emailing privacy@licensepulse.app).
Core infrastructure
| Sub-processor | Role | Location | Personal Data processed |
|---|---|---|---|
| Render Services, Inc. (render.com) | Application hosting + PostgreSQL database | USA (Oregon) | All Customer Data (encrypted at rest, AES-256) |
| Anthropic, PBC (anthropic.com) | AI-powered classification of files uploaded via Smart Upload | USA | File metadata + small content samples; not used to train models |
| Stripe, Inc. (stripe.com) | Payment processing for subscriptions | USA | Billing contact, payment instrument metadata (we never see card numbers) |
| Cloudflare, Inc. (cloudflare.com) | DDoS protection, DNS, edge caching | Global anycast | IP addresses, request metadata |
| Resend (Plus Five Five, Inc.) (resend.com) | Transactional email delivery — password resets, invitations, welcome mail, license alerts | USA | Recipient name and email address, message content |
| Cloudflare Email Routing | Inbound routing for our role addresses (hello@, support@) | Global anycast | Message content and sender address of mail you send us |
Authorized when Customer enables an integration
These are sub-processors only when the Customer chooses to connect their corresponding tool via OAuth. They are not used otherwise.
| Sub-processor | When invoked | Personal Data processed |
|---|---|---|
| Microsoft Corporation (Microsoft 365 / Azure AD) | Customer connects M365 | Account assignments, profile attributes, sign-in activity for license seats |
| Salesforce, Inc. | Customer connects Salesforce | Salesforce profile and license assignments |
| Atlassian Pty Ltd (Jira / Atlassian Cloud) | Customer connects Atlassian | Atlassian access records and product entitlements |
| GitHub, Inc. (GitHub Enterprise) | Customer connects GitHub | Committer activity and seat consumption |
| Slack Technologies, LLC | Customer connects Slack | Slack workspace seat activity |
| Google LLC (Google Workspace) | Customer connects Google Workspace | Workspace seat assignments and basic profile attributes |
Communications & ops
| Sub-processor | Role | Location | Personal Data processed |
|---|---|---|---|
What happens with the data
Sub-processors only receive data they need to perform their function. They cannot use Customer Data for their own purposes, and we maintain ownership and control. If a sub-processor experiences a security incident affecting Customer Data, we treat it as our incident under Section 7 of the DPA and notify Customers within 72 hours of confirmation.
Changes
When this list changes, we update the "Effective" date and post the new list at https://licensepulse.app/subprocessors. Material changes (new sub-processor with access to Customer Data) are also announced by email at least 14 days in advance.
Questions: privacy@licensepulse.app.