Every subprocessor
behind any company

Search a domain to walk its declared chain – the vendors it uses, the vendors they use, and the countries your data ends up in. Built from public documents.

Your vendors have vendors.
And those vendors
have more vendors

Venpo maps the entire declared chain, so you can see every organization involved in processing your data.

Notionnotion.so10 declared34 parties in the chain3 countries Open the live graph
Notionnotion.so10
AWS🇺🇸 United States
Cloudflare🇺🇸 United States5
+8
Zendesk🇺🇸 United States6
Greenhouse🇺🇸 United States3
+3
Twilio🇺🇸 United States6
SendGrid🇺🇸 United States5
+4
Cloudflarecloudflare.com
Subprocessors · 5Countries · 1
Amazon Web ServicesCloud infrastructure
SalesforceCRM6
ZendeskSupport6
GreenhouseRecruiting3
DatadogObservability5

Processor, subprocessor, third party – what each word means

ProcessorGDPR Art. 4(8)
A company that handles personal data on your instructions. The vendor you signed the DPA with. (You are the controller.)
SubprocessorGDPR Art. 28(2)
A processor your processor engages for the same data. It needs your written authorisation – usually granted in advance through the DPA, with a right to object to additions.
Third partyGDPR Art. 4(10)
Any external organisation. Broader than subprocessor: it includes recipients that receive data for their own purposes, which a subprocessor by definition does not.
Sub-contractorCommercial term
Not a GDPR one. A sub-contractor is only a subprocessor if it touches personal data. A cleaning company is a sub-contractor; a hosted email provider is a subprocessor.

A subprocessor is your vendor's vendor

You hand data to one company. That company can't run everything itself, so it hands parts of the job to others — and those hand it on again. Every hop is a company holding your data under a contract you never signed.

Level 1 · you
YOUYour companyCustomer, staff and user data
Level 2 · your vendors
Your vendors3 companies you signed a DPA with
Notion
Figma
Ramp
Level 3 · subprocessors
AWS
SendGrid
OpenAI
Zendesk
+6 more named
LEVEL 4 · 24 MORE PARTIES DECLARED
Level 5 · deeper still
Datadog
Snowflake
Twilio
still walking
They need your permissionUnder GDPR Art. 28, a processor can't hand your data to another company without written authorisation — usually granted in advance by the DPA you signed.
The list is the contractMost DPAs point at a published subprocessor page and promise notice before it changes. That page is the only public record, and it moves.
Depth is unboundedA subprocessor has subprocessors. Four or five hops down, your data sits with a company you have never heard of, in a country nobody signed off on.

Every edge has a document behind it

The graph is built from what vendors publish – subprocessor pages, DPAs, terms. Nothing is inferred from traffic, cookies, or page scripts. If an edge is in the chain, there is a public document that declares it, and you can open it.

Notionsubprocessors · DPA · termsWATCHED
VERSIONS KEPT
subprocessorsCURRENTJul 28subprocessorsJun 04dpa-annex-2May 19termsMay 02subprocessorsApr 11dpa-annex-2Mar 22subprocessorsFeb 28termsFeb 04subprocessorsJan 22

Read

Venpo monitors each vendor's subprocessor list, DPA and terms. Every fetch is stored as a version, so the page as it existed on any given date is retained.

RAW NAMES ON THREE VENDOR LISTS SendGridnotion.soTwilio SendGridfigma.comsendgrid.comramp.com
RESOLVED TO
SendGrid (Twilio)sendgrid.com1 NODE
3 raw names · 14 lists reference this entity
chain continues

Resolve

“SendGrid”, “Twilio SendGrid” and “sendgrid.com” are one company. Every raw name on every list is resolved to a single canonical entity – that is what lets chains connect across levels instead of dead-ending on a spelling.

Datadoglevel 4 · declared party
Declared in sendgrid.com/legal
read Jul 24, 2026
subprocessorsJUL 28 vs JUN 04
+AnthropicADDEDMailgunREMOVED+Cloudflare R2ADDEDHerokuREMOVED

Version

Every read is dated. Click any node in the graph and you see the source document and the date it was read. When a list changes, the previous version is kept and the diff is recorded.

Where the graph fits in your work

ONBOARDING

Before you sign

A vendor review that stops at the vendor approves one company. The data goes to the whole set. Walk the declared chain before the signature, not after the incident.

CHANGE NOTICE

When the list moves

Most DPAs promise notice before a new subprocessor is added and give you a window to object (Art. 28(2)). The window only works if you see the change when it lands on the page – Venpo diffs every list the moment it moves.

TRANSFERS

Transfer impact assessments

A TIA needs the set of countries the data can reach. The chain gives you that set per vendor, with the document each country claim came from.

A.5.22

Supplier change management

ISO 27001 A.5.22 asks for evidence that supplier changes are monitored and reviewed. Versioned documents and recorded diffs are that evidence, already dated and sourced.

Mix everything you already have.
Get A.5.22 ready

Drop in the contracts you hold, let Venpo monitor the vendors you depend on, and connect the tools where the rest already lives. One memory, three inputs.

Drag and drop contracts

Your MSAs, DPAs and policies. Dropped in once, parsed into clauses and linked to the controls they satisfy.

DPA_Master.pdfVendor_SLA.pdf
Monitored subprocessors

Venpo watches each vendor's public terms, DPA and subprocessor list, and diffs them the moment they change.

VercelWATCHING
OpenAIWATCHING
Integrations

Pull from where agreements already live — mail, drive, ticketing and your identity provider — so nothing sits outside the graph.

MDJID
A.5.22 READYSupplier monitoring, review & change management
Service delivery monitored12 suppliers
Reports & audits reviewed2026 cycle
Supplier changes managed9 diffs
Evidence retained & versioned4,800 docs

A.5.19 · A.5.20 · A.5.21 · A.5.23 coming next.

FAQs about subprocessors

Is a public subprocessor list legally required?

GDPR does not mandate a public page. It requires processors to inform controllers of intended subprocessor changes and give them the chance to object (Art. 28(2)). A published list plus a notification mechanism is how most SaaS vendors implement that duty – which is why the list, where it exists, is the public record.

Do subprocessors need my consent?

Written authorisation, yes – general or specific (Art. 28(2)). In practice almost all SaaS DPAs use general authorisation: you approve the current list when you sign and retain a right to object to additions.

What happens if I object to a new subprocessor?

It depends on your DPA. Common terms let the vendor propose a workaround, and if none exists, let you terminate the affected service. The objection window is typically short – which is why seeing the change on time matters more than the objection right itself.

Can I see a vendor's subprocessors without being a customer?

Usually yes – that is what this graph is built from. Where a vendor publishes its list, DPA or terms, the chain is public. Search any domain above to check.

What if a vendor doesn't publish a subprocessor list?

Then the graph shows what does exist for that vendor – its DPA, terms, and any parties declared in them. The absence of a list is itself an input to your vendor review: it means the register your DPA relies on is not public.

How deep does the chain go?

Until the documents stop. Venpo walks each declared party's own declarations until a party publishes nothing further. In the corpus, chains typically end at five levels.

Trace your own chain

Every vendor document read, versioned, diffed and explained – so the reference is there when you need it. Free to start, no credit card required.

Notion updated Security PolicyAdded SOC 2 Type II compliance for enterprise plansPositive2 days ago
Stripe updated Terms of ServiceDispute resolution clause now requires mandatory arbitration in all regionsHigh impact2 hours ago
AWS modified Privacy PolicyData retention period extended from 2 years to 5 years for all servicesMedium impact5 hours ago