8x Sub-processor List
Last updated: July 2026
1. About this list
This is the public, versioned list of third-party service providers ("sub-processors") that 8x Social, Inc., a Delaware corporation ("8x", "we") engages to help operate its platform. Each sub-processor receives or has access to personal data that 8x controls, and processes it only on 8x's documented instructions and under contract.
8x is the controller for all personal data described in its privacy notices — both the data of its sales representatives (independent contractors and applicants) and the data of the business prospects whom representatives contact. 8x does not act as a processor for any external business customer, and therefore does not currently owe a data processing agreement (DPA) to customers; the providers below are 8x's own sub-processors. See privacy-notice-reps.md (rep-facing) and privacy-notice-prospects.md (prospect-facing) for the underlying processing descriptions, and dpa-and-transfer-register.md / internal-compliance-artifacts.md for the internal record this table backs.
This list supports:
- the privacy notices, which reference it for the identity of recipients;
- the internal DPA register and Record of Processing Activities (RoPA); and
- 8x's cross-border transfer documentation (see Section 5).
The "Location" column states where the relevant processing/account is configured.
2. Current sub-processors
| # | Sub-processor | Service / Purpose | Categories of personal data shared | Location (processing / data residency) | Cross-border transfer mechanism (for non-US data subjects → US) |
|---|---|---|---|---|---|
| 1 | Twilio Inc. | Outbound telephony for cold calls; carrier connectivity; call audio capture | Prospect phone numbers; call audio (rep + prospect voice); call metadata (timestamps, duration, call status); caller ID / per-rep number | United States | See Section 5. |
| 2 | OpenAI, L.L.C. | (a) Speech-to-text transcription of call audio (whisper-1); (b) AI evaluation of call transcripts (gpt-4.1) that drives meeting-qualification and rep pay | Call audio; AI-generated transcripts; rep identifiers tied to a call; prospect identifiers present in transcript content | United States. Default API endpoints are in use; no zero-data-retention (ZDR) / enterprise tier has been elected — see Section 4. | See Section 5. |
| 3 | Anthropic, PBC | AI evaluation and summarization of call transcripts (Claude models) | AI-generated transcripts; rep identifiers tied to a call; prospect identifiers present in transcript content | United States. Default API endpoints are in use; no zero-data-retention / enterprise tier has been elected — see Section 4. | See Section 5. |
| 4 | Supabase, Inc. | Primary application database (Postgres), authentication, and file storage (Storage buckets) — the system of record | All categories of rep and prospect personal data, including: account credentials, names, contact details, country, CV files, training/performance records, payout data, IP addresses; prospect names, companies, emails, phone numbers, LinkedIn, firmographics, free-text rep notes; voice recordings, AI transcripts, and AI evaluations | United States (us-east-1) | See Section 5. |
| 5 | Vercel Inc. | Application hosting, serverless compute, edge/CDN delivery | IP addresses and request metadata in server/access logs; any personal data transiting requests to the application | United States / global edge network | See Section 5. |
| 6 | Resend (Plus Five Five, Inc.) | Transactional email and rep/prospect outreach email delivery | Rep email addresses and names; prospect email addresses, names, and any personal data contained in message content | United States | See Section 5. |
| 7 | Cal.com, Inc. | Meeting scheduling for booked calls | Prospect-entered scheduling data (name, email, chosen time, any notes); rep identifier for the host | United States / EU (provider-configured) | See Section 5. |
| 8 | PostHog, Inc. | Product analytics and privacy-masked session replay to improve the Platform — consent-gated: activated only after the visitor accepts the cookie banner; if the visitor declines, only a privacy-preserving, non-identifying count is kept (no cookies, no device storage) | Website-visitor / rep online identifiers, usage and event data, and masked session recordings (all text and form inputs masked — no readable names, emails, phone numbers, or lead data). No prospect personal data | European Union — PostHog Cloud EU (eu.posthog.com); data residency in the EU | EU-hosted; no transfer to the US for this processor. For non-EU data subjects, data is processed in the EU. |
| 9 | Google LLC (Google Analytics) | Website analytics (Google Analytics 4) measuring site usage to improve the site — consent-gated: loads only after the visitor accepts the cookie banner | Website-visitor / rep online identifiers (GA client-id cookie, IP address — GA4 does not store the full IP), device/browser metadata, and page-interaction events. Visitor browsing data only — no prospect personal data | United States | See Section 5. (Google is EU-US Data Privacy Framework-certified; per Section 5, default to SCCs + TIA.) |
3. Intended sub-processors (not yet live)
| # | Sub-processor | Service / Purpose | Categories of personal data shared | Status |
|---|---|---|---|---|
| 10 | LinkedIn (LinkedIn Corporation / Microsoft) | Identity verification of representatives via OAuth / OpenID Connect (OIDC) — verified profile fields | Rep-authorized LinkedIn OIDC fields (e.g. verified name, profile identifier) | NOT YET LIVE. The integration exists in schema only; the OAuth flow is a non-functional stub (returns HTTP 501) and is not enabled in production. Listed here for transparency. This list will be updated, and notice given (Section 6), before the integration goes live and any data is shared. |
4. AI provider data-retention posture
OpenAI (#2) and Anthropic (#3) are currently used through their default API endpoints, with no zero-data-retention (ZDR) or enterprise tier elected. Under default API terms these providers may retain submitted content for a limited period (e.g. for abuse monitoring) before deletion, per the provider's then-current policy.
Because the data sent to these providers includes call audio and transcripts of real prospects, 8x's default posture is to elect a zero-data-retention / enterprise arrangement (and an EU/regional endpoint where offered) to minimize provider-side retention and tighten the transfer posture. 8x is evaluating electing such an arrangement for OpenAI and Anthropic and will update this Section and the transfer documentation accordingly.
5. Cross-border transfers
All current sub-processors except PostHog (#8, hosted in the EU) process data in, or transfer data to, the United States. Personal data of prospects and representatives in Brazil, Mexico, India, and the EU/UK (EU/UK is in scope — see dpa-and-transfer-register.md) therefore flows from those jurisdictions to US-based processors, which engages cross-border transfer obligations:
- Brazil (LGPD): International transfers to US processors require ANPD Standard Contractual Clauses (Resolution CD/ANPD No. 19/2024). 8x is putting the ANPD Standard Contractual Clauses in place with its US sub-processors for these transfers.
- Mexico (Federal Law on Protection of Personal Data Held by Private Parties, in force 21 March 2025): Transfers to US sub-processors must be disclosed in the Spanish
aviso de privacidadunder Art. 35 (transfer disclosure is still required even though Art. 15's express enumeration changed). Contractual transfer safeguards with each recipient are recommended. - India (DPDP Act 2023 + DPDP Rules 2025): Transfers are permitted except to countries restricted by the Central Government. Separately, under the DPDP Act cold outreach generally requires consent and a notice is not a substitute for consent; 8x is aligning its India outreach to a consent-first approach, honors all opt-out and do-not-contact requests, and treats India activity as subject to Indian-counsel review before scaling. See
privacy-notice-prospects.mdanddpa-and-transfer-register.md. - EU/UK (in scope): EU/UK IS in scope — GDPR and the ePrivacy Directive apply (no EU-exclusion gate). Chapter V transfers to US sub-processors require SCCs (Module 2) plus a documented Transfer Impact Assessment (TIA); treat the EU-US Data Privacy Framework as unstable (pending the Latombe appeal) and default to SCCs + TIA. ePrivacy Art. 13 prior consent also applies to electronic/automated direct marketing to EU prospects (outreach email via Resend, automated calls). See
dpa-and-transfer-register.md.
For each sub-processor above, 8x maintains the applicable provider DPA and transfer instrument (SCCs / regional equivalent) in the DPA register (dpa-and-transfer-register.md).
6. Changes to this list and advance notice
8x maintains this list as the authoritative, versioned record of its sub-processors. When 8x intends to add a new sub-processor, change the purpose for which an existing one is used, or bring an intended sub-processor (Section 3) live, 8x will:
- update this list and increment the document version (Section header), and
- provide advance notice of the change before the new processing begins.
8x will provide at least 30 days' advance notice before the change takes effect, except where a faster change is required to maintain security or service continuity, in which case notice will be given as soon as reasonably practicable.
Questions or updates: to ask about this list or 8x's use of any sub-processor, or to request notice of changes, contact our Privacy Team at privacy@8x.social.
7. Document control
| Field | Value |
|---|---|
| Controller | 8x Social, Inc., a Delaware corporation |
| Registered address | 1111B S Governors Ave STE 47647, Dover, DE 19904, United States |
| Privacy contact | our Privacy Team, privacy@8x.social |
| Governing law | Delaware, United States |
| Version | 1.0 — June 2026 |
| Related documents | privacy-notice-reps.md, privacy-notice-prospects.md, dpa-and-transfer-register.md, internal-compliance-artifacts.md |