PrivacyPublic guide
Review subprocessors
Understand how relevant service providers are disclosed and evaluated for the product you intend to use.
Purpose and scope
Understand how relevant service providers are disclosed and evaluated for the product you intend to use.
Use this guide as orientation, then rely on the signed agreement, current policy or named support response where those sources set a more specific obligation.
Prepare the right information
- The product and processing scope.
- Current subprocessor list and locations.
- Contractual notification requirements.
Follow the controlled process
- Frame the needState the desired outcome, affected product and accountable contact. For review subprocessors, avoid assumptions that have not been confirmed in writing.
- Review and decideUse the current governed source, record material questions and obtain approval from the person who owns the decision.
- Retain evidenceKeep the final reference, date, decision and any follow-up action together so a later reviewer can reconstruct what happened.
Expected record
- A reviewed provider list.
- Questions or objections recorded.
- A decision linked to the current version.
Security and disclosure boundary
- Never send passwords, authentication codes, private keys or recovery codes to Obedience staff.
- Share the minimum customer, project and commercial information needed for the stated purpose.
- Public documentation explains controls and responsibilities without publishing exploitable topology, credentials or confidential implementation detail.
Did this guide help?
Only your answer, guide slug and version are recorded.