Wakemark

Legal

Subprocessors

Last updated: 2026-07-13

The categories of service provider that process data on Wakemark's behalf, by function and region. A current itemized list naming the specific providers is available to customers under the DPA on request; we give notice before a new or replaced subprocessor begins processing customer data.

Subprocessor categories

CategoryPurposeData processedRegion
Cloud object storageByte-exact custody of generated outputs (and mirrored inputs) when you do not bring your own bucket.Generated media bytes and provenance sidecars, subject to per-project retention (see the Privacy Policy).European Union.
Managed databaseAccount, project, and the job/event audit ledger.Account identifiers, project metadata, the job/event ledger (including prompts, subject to your retention policy), and encrypted credential ciphertext — never plaintext keys.European Union.
Key management (KMS)Envelope encryption — the root key that wraps the per-secret data keys protecting the credentials you bring.Key-wrapping operations only; the provider never receives plaintext keys or customer content.European Union (Frankfurt region).
Application & compute hostingRuns the Wakemark control plane (routing, custody, ledger, provenance).In-transit request/response payloads during job execution; not a durable store of customer media.European Union.
Error monitoring / application diagnosticsAlerts operators when the service crashes or fails unexpectedly (server panics and 5xx), so incidents are detected and fixed.Content-blind diagnostics only: an opaque tenant identifier, a per-request identifier, the API route pattern, the HTTP status and error classification, the software release, and server-side stack traces. Never prompts, generation inputs or outputs, media, output or presigned URLs, provider or Wakemark credentials, webhook secrets, session tokens, email addresses, or IP addresses.European Union (error-tracking provider's EU data region).
AuthenticationSign-in, sessions, and identity.Email address, authentication identifiers, session metadata.United States.
Transactional emailAccount notices such as the account-deletion confirmation.Email address and message content for transactional mail.United States.
Web hosting & cookieless analyticsMarketing and app delivery, plus cookieless, privacy-friendly aggregate page-view analytics.HTTP request metadata and aggregate, non-identifying page-view analytics; no advertising cookies, no customer media stored at rest here.United States / global edge.

Media custody, database, key management, and compute run in the EU; authentication, transactional email, and web hosting run in the US — the basis for the SCC section of the DPA.

Engaged by you, not by Wakemark

Not engaged today

Billing is not built and nothing is charged today, so no billing or payment vendor processes customer data in this build. If usage-based billing launches, the responsible payment provider will be engaged with notice before it processes any customer data.

Change notification

We give at least 30 days' notice before a new or replaced subprocessor begins processing customer data, so customers may review and object under the DPA.

See also the DPA for the contractual basis on which subprocessors are engaged, and the Privacy Policy for what each category of data is used for.