Persona added ClickHouse as a required subprocessor

Stani Mihov
Founder & CEO
·

TL;DR
Vendor: Persona
Document: Subprocessors list
Date: June 17, 2026
Key change: ClickHouse, Inc. added as a required subprocessor for database services
Persona added ClickHouse to its list of subprocessors as a required provider, so it now processes customer personal data across every Persona deployment. For the SaaS and fintech teams that rely on Persona for identity verification, a new required subprocessor is a change worth tracking, not a footnote.
The change
On June 17, 2026, Persona updated its public Subprocessors list and added ClickHouse, Inc. as a new entry. ClickHouse is listed as a US-based provider handling database services, and it is marked as required rather than conditional. That single flag matters: a required subprocessor applies to every Persona customer, regardless of which identity verification or age assurance features they run.
No entries were removed in the same update. The list simply grew by one provider, and that provider now sits in the data path by default.
Persona sits in the identity layer of a large share of fintech and SaaS products, so a change to who processes that data reaches well beyond Persona's direct customers.
What changed
Persona's Subprocessors list enumerates the third parties that may process Customer Personal Data on its behalf. The June 17 version adds one row: ClickHouse, Inc., registered in Mountain View, California, performing database services, with the required flag set.
With this addition the list spans 17 subprocessors, and ClickHouse becomes the third required database provider alongside MongoDB and Snowflake. ClickHouse is a real-time, column-oriented analytics database, which points to Persona expanding how it stores or queries data at scale.
What this means for Persona customers
Persona operates as a data processor, and its customers are the controllers. The personal data flowing through Persona is sensitive by nature: government identity documents, selfies and video, facial-geometry data collected with consent, names, contact details, and device signals used for KYC, AML, and age verification.
When a subprocessor is marked required, there is no setting that opts you out of it. Every Persona customer's data now travels through ClickHouse infrastructure as part of the standard service, not as an optional add-on a customer chose to enable.
Why this matters
Under most data processing agreements, and under GDPR Article 28, adding a new subprocessor is not a neutral act. The controller usually has a right to be informed, sometimes a right to object within a defined window, and an obligation to ensure equivalent protections flow down to the new party.
Identity data sits among the highest-sensitivity categories a company handles, so the standard for knowing exactly who processes it is correspondingly high. The difficulty is that subprocessor lists update on the vendor's own schedule and rarely arrive with a notification you will actually see. That gap is the core argument for treating these documents as a live signal, which we cover in our analysis of the hidden risk of vendor legal changes.
Potential impact for SaaS companies
For a team using Persona, a single line in a table can generate a real to-do list. Companies may want to review whether:
their own subprocessor disclosures to customers need to be updated to include the new provider
a vendor risk assessment on ClickHouse is required before the next audit or customer review
the legal basis for any cross-border transfer still holds with a new US-based provider in the chain
their contract with Persona grants an objection period that is now running
There is also a fourth-party dimension, since ClickHouse maintains its own subprocessors, so the data chain extends one step further than Persona's list alone shows. This is exactly the surface that continuous vendor risk monitoring is built to cover.
How Venpo detected it
Venpo continuously monitors vendor legal documents and surfaces material changes as they are published. When Persona's updated Subprocessors list went live, Venpo:
detected the new ClickHouse row and the revised last-updated date of June 17, 2026
classified it as an expansion of who can access customer personal data
separated the new required database provider from the conditional providers already on the list
translated a single table row into clear business impact
The full redline of this change is public on our live feed: Persona Subprocessors, June 17, 2026. The same continuous approach applies to AI subprocessors, which Persona's list also includes on a conditional basis, with OpenAI, Anthropic, and Groq among them, a discipline we cover in our guide to monitoring AI subprocessors.
Business outcome
Continuous detection changes the timeline. Instead of discovering a new required subprocessor during an annual audit or when a customer's security team asks, a Persona customer can:
act on the change while any contractual objection window is still open
update vendor and data-processing records to include ClickHouse
confirm their customer-facing disclosures still match reality
brief security and compliance before the next review, not during it
The difference is acting on a current fact versus reconstructing a change months after it has already taken effect.
Key takeaway
Subprocessor lists are some of the most consequential vendor documents and among the least likely to announce themselves. A required subprocessor is not optional; it touches every customer's data the moment it is added. Treating these lists as a living signal rather than a page you check once a year is the practical line between manual and automated vendor monitoring, and it is what keeps teams from finding out late.
The change
On June 17, 2026, Persona updated its public Subprocessors list and added ClickHouse, Inc. as a new entry. ClickHouse is listed as a US-based provider handling database services, and it is marked as required rather than conditional. That single flag matters: a required subprocessor applies to every Persona customer, regardless of which identity verification or age assurance features they run.
No entries were removed in the same update. The list simply grew by one provider, and that provider now sits in the data path by default.
Persona sits in the identity layer of a large share of fintech and SaaS products, so a change to who processes that data reaches well beyond Persona's direct customers.
What changed
Persona's Subprocessors list enumerates the third parties that may process Customer Personal Data on its behalf. The June 17 version adds one row: ClickHouse, Inc., registered in Mountain View, California, performing database services, with the required flag set.
With this addition the list spans 17 subprocessors, and ClickHouse becomes the third required database provider alongside MongoDB and Snowflake. ClickHouse is a real-time, column-oriented analytics database, which points to Persona expanding how it stores or queries data at scale.
What this means for Persona customers
Persona operates as a data processor, and its customers are the controllers. The personal data flowing through Persona is sensitive by nature: government identity documents, selfies and video, facial-geometry data collected with consent, names, contact details, and device signals used for KYC, AML, and age verification.
When a subprocessor is marked required, there is no setting that opts you out of it. Every Persona customer's data now travels through ClickHouse infrastructure as part of the standard service, not as an optional add-on a customer chose to enable.
Why this matters
Under most data processing agreements, and under GDPR Article 28, adding a new subprocessor is not a neutral act. The controller usually has a right to be informed, sometimes a right to object within a defined window, and an obligation to ensure equivalent protections flow down to the new party.
Identity data sits among the highest-sensitivity categories a company handles, so the standard for knowing exactly who processes it is correspondingly high. The difficulty is that subprocessor lists update on the vendor's own schedule and rarely arrive with a notification you will actually see. That gap is the core argument for treating these documents as a live signal, which we cover in our analysis of the hidden risk of vendor legal changes.
Potential impact for SaaS companies
For a team using Persona, a single line in a table can generate a real to-do list. Companies may want to review whether:
their own subprocessor disclosures to customers need to be updated to include the new provider
a vendor risk assessment on ClickHouse is required before the next audit or customer review
the legal basis for any cross-border transfer still holds with a new US-based provider in the chain
their contract with Persona grants an objection period that is now running
There is also a fourth-party dimension, since ClickHouse maintains its own subprocessors, so the data chain extends one step further than Persona's list alone shows. This is exactly the surface that continuous vendor risk monitoring is built to cover.
How Venpo detected it
Venpo continuously monitors vendor legal documents and surfaces material changes as they are published. When Persona's updated Subprocessors list went live, Venpo:
detected the new ClickHouse row and the revised last-updated date of June 17, 2026
classified it as an expansion of who can access customer personal data
separated the new required database provider from the conditional providers already on the list
translated a single table row into clear business impact
The full redline of this change is public on our live feed: Persona Subprocessors, June 17, 2026. The same continuous approach applies to AI subprocessors, which Persona's list also includes on a conditional basis, with OpenAI, Anthropic, and Groq among them, a discipline we cover in our guide to monitoring AI subprocessors.
Business outcome
Continuous detection changes the timeline. Instead of discovering a new required subprocessor during an annual audit or when a customer's security team asks, a Persona customer can:
act on the change while any contractual objection window is still open
update vendor and data-processing records to include ClickHouse
confirm their customer-facing disclosures still match reality
brief security and compliance before the next review, not during it
The difference is acting on a current fact versus reconstructing a change months after it has already taken effect.
Key takeaway
Subprocessor lists are some of the most consequential vendor documents and among the least likely to announce themselves. A required subprocessor is not optional; it touches every customer's data the moment it is added. Treating these lists as a living signal rather than a page you check once a year is the practical line between manual and automated vendor monitoring, and it is what keeps teams from finding out late.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
