The third parties that process customer data on Quome's behalf to deliver the platform, what each one processes, and where.
Maintained under GDPR Article 28 and referenced by the Quome Business Associate Addendum (ยง5.5, Appendix B) and Privacy Notice. Reviewed quarterly. Last updated 2026-09-11.
30 days
Minimum notice before Quome adds or replaces a subprocessor, sent by email to each organization owner on record.
15 days
Window after notification in which a customer may object. If Quome cannot reasonably accommodate the objection, the customer may terminate under their service terms.
Quarterly
Review cycle for this list. The date at the top of the page is the last review.
Process data as part of core service delivery. Under the Bring Your Own Service Account model the customer's cloud provider has a dual role: it is Quome's subprocessor for the orchestration the control plane performs, and the customer's own direct provider for the resources inside the customer's account. Customer data resides exclusively in the customer's account; the control plane holds orchestration metadata only.
| Subprocessor | Purpose | Data processed | Location | Certifications | PHI access |
|---|---|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure (BYOSA) and hosting of the Quome control plane | Customer data in the customer's own GCP project; control-plane orchestration metadata | Customer-selected region; control plane in the United States | SOC 2, ISO 27001, HIPAA, FedRAMP | Infrastructure-level. Data plane covered by the customer's own cloud BAA; control plane by Quome's cloud BAA |
| Amazon Web Services | Cloud infrastructure (BYOSA) | Customer data in the customer's own AWS account | Customer-selected region | SOC 2, ISO 27001, HIPAA, FedRAMP | Infrastructure-level; covered by the customer's own cloud BAA |
| Microsoft Azure | Cloud infrastructure (BYOSA) | Customer data in the customer's own Azure subscription | Customer-selected region | SOC 2, ISO 27001, HIPAA, FedRAMP | Infrastructure-level; covered by the customer's own cloud BAA |
Provide features within the platform. None of them receives Customer Content or protected health information.
| Subprocessor | Purpose | Data processed | Location | Certifications | PHI access |
|---|---|---|---|---|---|
| Stripe | Payment processing | Email, billing address, payment tokens | United States | PCI DSS Level 1, SOC 2 | None |
| Resend | Transactional email | Email addresses, email content | United States | SOC 2 | None |
| GitHub | OAuth authentication, repository integration | OAuth tokens, repository metadata | United States | SOC 2 | None |
The workflow engine (Temporal) and authorization service (SpiceDB) named in Appendix B of the Business Associate Addendum run as software inside Quome-operated infrastructure in each customer's data plane. No data is sent to Temporal Technologies or AuthZed, and they hold no PHI access.
AI model providers reached through the platform's model gateway use the customer's own API keys; there is no Quome key behind them, so they are the customer's providers rather than Quome subprocessors. The same applies to integrations a customer chooses to connect to their organization.
Contact us for a data processing agreement, an objection, or the list of processing locations for your organization.