8x · Sales

8x Sub-processor List

Last updated: July 2026


1. About this list

This is the public, versioned list of third-party service providers ("sub-processors") that 8x Social, Inc., a Delaware corporation ("8x", "we") engages to help operate its platform. Each sub-processor receives or has access to personal data that 8x controls, and processes it only on 8x's documented instructions and under contract.

8x is the controller for all personal data described in its privacy notices — both the data of its sales representatives (independent contractors and applicants) and the data of the business prospects whom representatives contact. 8x does not act as a processor for any external business customer, and therefore does not currently owe a data processing agreement (DPA) to customers; the providers below are 8x's own sub-processors. See privacy-notice-reps.md (rep-facing) and privacy-notice-prospects.md (prospect-facing) for the underlying processing descriptions, and dpa-and-transfer-register.md / internal-compliance-artifacts.md for the internal record this table backs.

This list supports:

  • the privacy notices, which reference it for the identity of recipients;
  • the internal DPA register and Record of Processing Activities (RoPA); and
  • 8x's cross-border transfer documentation (see Section 5).

The "Location" column states where the relevant processing/account is configured.


2. Current sub-processors

#Sub-processorService / PurposeCategories of personal data sharedLocation (processing / data residency)Cross-border transfer mechanism (for non-US data subjects → US)
1Twilio Inc.Outbound telephony for cold calls; carrier connectivity; call audio captureProspect phone numbers; call audio (rep + prospect voice); call metadata (timestamps, duration, call status); caller ID / per-rep numberUnited StatesSee Section 5.
2OpenAI, L.L.C.(a) Speech-to-text transcription of call audio (whisper-1); (b) AI evaluation of call transcripts (gpt-4.1) that drives meeting-qualification and rep payCall audio; AI-generated transcripts; rep identifiers tied to a call; prospect identifiers present in transcript contentUnited States. Default API endpoints are in use; no zero-data-retention (ZDR) / enterprise tier has been elected — see Section 4.See Section 5.
3Anthropic, PBCAI evaluation and summarization of call transcripts (Claude models)AI-generated transcripts; rep identifiers tied to a call; prospect identifiers present in transcript contentUnited States. Default API endpoints are in use; no zero-data-retention / enterprise tier has been elected — see Section 4.See Section 5.
4Supabase, Inc.Primary application database (Postgres), authentication, and file storage (Storage buckets) — the system of recordAll categories of rep and prospect personal data, including: account credentials, names, contact details, country, CV files, training/performance records, payout data, IP addresses; prospect names, companies, emails, phone numbers, LinkedIn, firmographics, free-text rep notes; voice recordings, AI transcripts, and AI evaluationsUnited States (us-east-1)See Section 5.
5Vercel Inc.Application hosting, serverless compute, edge/CDN deliveryIP addresses and request metadata in server/access logs; any personal data transiting requests to the applicationUnited States / global edge networkSee Section 5.
6Resend (Plus Five Five, Inc.)Transactional email and rep/prospect outreach email deliveryRep email addresses and names; prospect email addresses, names, and any personal data contained in message contentUnited StatesSee Section 5.
7Cal.com, Inc.Meeting scheduling for booked callsProspect-entered scheduling data (name, email, chosen time, any notes); rep identifier for the hostUnited States / EU (provider-configured)See Section 5.
8PostHog, Inc.Product analytics and privacy-masked session replay to improve the Platform — consent-gated: activated only after the visitor accepts the cookie banner; if the visitor declines, only a privacy-preserving, non-identifying count is kept (no cookies, no device storage)Website-visitor / rep online identifiers, usage and event data, and masked session recordings (all text and form inputs masked — no readable names, emails, phone numbers, or lead data). No prospect personal dataEuropean Union — PostHog Cloud EU (eu.posthog.com); data residency in the EUEU-hosted; no transfer to the US for this processor. For non-EU data subjects, data is processed in the EU.
9Google LLC (Google Analytics)Website analytics (Google Analytics 4) measuring site usage to improve the site — consent-gated: loads only after the visitor accepts the cookie bannerWebsite-visitor / rep online identifiers (GA client-id cookie, IP address — GA4 does not store the full IP), device/browser metadata, and page-interaction events. Visitor browsing data only — no prospect personal dataUnited StatesSee Section 5. (Google is EU-US Data Privacy Framework-certified; per Section 5, default to SCCs + TIA.)

3. Intended sub-processors (not yet live)

#Sub-processorService / PurposeCategories of personal data sharedStatus
10LinkedIn (LinkedIn Corporation / Microsoft)Identity verification of representatives via OAuth / OpenID Connect (OIDC) — verified profile fieldsRep-authorized LinkedIn OIDC fields (e.g. verified name, profile identifier)NOT YET LIVE. The integration exists in schema only; the OAuth flow is a non-functional stub (returns HTTP 501) and is not enabled in production. Listed here for transparency. This list will be updated, and notice given (Section 6), before the integration goes live and any data is shared.

4. AI provider data-retention posture

OpenAI (#2) and Anthropic (#3) are currently used through their default API endpoints, with no zero-data-retention (ZDR) or enterprise tier elected. Under default API terms these providers may retain submitted content for a limited period (e.g. for abuse monitoring) before deletion, per the provider's then-current policy.

Because the data sent to these providers includes call audio and transcripts of real prospects, 8x's default posture is to elect a zero-data-retention / enterprise arrangement (and an EU/regional endpoint where offered) to minimize provider-side retention and tighten the transfer posture. 8x is evaluating electing such an arrangement for OpenAI and Anthropic and will update this Section and the transfer documentation accordingly.


5. Cross-border transfers

All current sub-processors except PostHog (#8, hosted in the EU) process data in, or transfer data to, the United States. Personal data of prospects and representatives in Brazil, Mexico, India, and the EU/UK (EU/UK is in scope — see dpa-and-transfer-register.md) therefore flows from those jurisdictions to US-based processors, which engages cross-border transfer obligations:

  • Brazil (LGPD): International transfers to US processors require ANPD Standard Contractual Clauses (Resolution CD/ANPD No. 19/2024). 8x is putting the ANPD Standard Contractual Clauses in place with its US sub-processors for these transfers.
  • Mexico (Federal Law on Protection of Personal Data Held by Private Parties, in force 21 March 2025): Transfers to US sub-processors must be disclosed in the Spanish aviso de privacidad under Art. 35 (transfer disclosure is still required even though Art. 15's express enumeration changed). Contractual transfer safeguards with each recipient are recommended.
  • India (DPDP Act 2023 + DPDP Rules 2025): Transfers are permitted except to countries restricted by the Central Government. Separately, under the DPDP Act cold outreach generally requires consent and a notice is not a substitute for consent; 8x is aligning its India outreach to a consent-first approach, honors all opt-out and do-not-contact requests, and treats India activity as subject to Indian-counsel review before scaling. See privacy-notice-prospects.md and dpa-and-transfer-register.md.
  • EU/UK (in scope): EU/UK IS in scope — GDPR and the ePrivacy Directive apply (no EU-exclusion gate). Chapter V transfers to US sub-processors require SCCs (Module 2) plus a documented Transfer Impact Assessment (TIA); treat the EU-US Data Privacy Framework as unstable (pending the Latombe appeal) and default to SCCs + TIA. ePrivacy Art. 13 prior consent also applies to electronic/automated direct marketing to EU prospects (outreach email via Resend, automated calls). See dpa-and-transfer-register.md.

For each sub-processor above, 8x maintains the applicable provider DPA and transfer instrument (SCCs / regional equivalent) in the DPA register (dpa-and-transfer-register.md).


6. Changes to this list and advance notice

8x maintains this list as the authoritative, versioned record of its sub-processors. When 8x intends to add a new sub-processor, change the purpose for which an existing one is used, or bring an intended sub-processor (Section 3) live, 8x will:

  1. update this list and increment the document version (Section header), and
  2. provide advance notice of the change before the new processing begins.

8x will provide at least 30 days' advance notice before the change takes effect, except where a faster change is required to maintain security or service continuity, in which case notice will be given as soon as reasonably practicable.

Questions or updates: to ask about this list or 8x's use of any sub-processor, or to request notice of changes, contact our Privacy Team at privacy@8x.social.


7. Document control

FieldValue
Controller8x Social, Inc., a Delaware corporation
Registered address1111B S Governors Ave STE 47647, Dover, DE 19904, United States
Privacy contactour Privacy Team, privacy@8x.social
Governing lawDelaware, United States
Version1.0 — June 2026
Related documentsprivacy-notice-reps.md, privacy-notice-prospects.md, dpa-and-transfer-register.md, internal-compliance-artifacts.md