Skip to main content

๐Ÿ“‹ Sub-processor DPA Tracker

Status of every sub-processor's Data Processing Agreement. Pre-filled where we control both sides, marked "draft โ€” not countersigned" where we are waiting on the vendor.

Each DPA has its own file in this directory with the live status + the next action + the exact email / portal path to execute it.


Live scoreboardโ€‹

Sub-processorRoleDPA formStatusOwnerNext action
Google (Firebase)Hosting, Auth, Firestore, Functions, Storage, FCMGoogle Customer DPA (standard)๐ŸŸก Ready โ€” not yet accepted in consoleOpsClick-accept at Firebase Console โ†’ Project Settings โ†’ Integrations โ†’ Data Processing and Security Terms
Lambda, Inc.GPU inference โ€” the live processor. Every uploaded video is processed on Lambda hardwareVendor template expected๐Ÿ”ด Draft request ready โ€” not sent. Highest-priority gapOps / DPOPopulate the account ID, then dispatch lambda-dpa.md ยง"Outbound request"
RunPod Inc.GPU inference โ€” fallback only, currently receives no traffic (DEFAULT_GPU_PROVIDER_POLICY is Lambda-only)Vendor template expected๐Ÿ”ด Draft request prepared โ€” not sentOpsDispatch runpod-dpa.md ยง"Outbound request"
Resend Inc.Transactional emailVendor template expected๐Ÿ”ด Draft request prepared โ€” not sentOpsDispatch resend-dpa.md ยง"Outbound request"
Apple Inc.App Store Connect, Sign in with Apple, IAPApple Developer Program License + applicable privacy terms๐ŸŸก Account acceptance not reverifiedOpsVerify the current agreement and archive evidence
StripeHosted Checkout/portal, customer and subscription eventsVendor standard DPA๐ŸŸก Available โ€” test account only; acceptance and production readiness not verifiedOps + DPOComplete stripe-dpa.md checklist before live mode
Cloudflare(future, if we front with CDN)Vendor standardโšช N/Aโ€”โ€”

:::danger Corrected 2026-08-19 This table previously named RunPod as the GPU inference sub-processor and did not list Lambda at all. That was backwards: production has been Lambda-only since RunPod sat at 402 Insufficient Balance, so the listed processor handles nothing and the actual processor of every uploaded video was absent from the register.

A sub-processor list that omits a live processor is an Art. 28 / Art. 30 problem rather than a documentation nit, and the public sub-processor notice on the landing page inherits from this table โ€” check it too. :::

Legend: ๐ŸŸข acceptance evidenced + in force ยท ๐ŸŸก available/prepared, awaiting verification or execution ยท ๐Ÿ”ด request/action not started ยท โšช not applicable


How this directory is maintainedโ€‹

  • One file per sub-processor, <vendor>-dpa.md.
  • The file tracks: role, data categories, outbound request text, inbound response, countersigned PDF pointer, and review date.
  • Signed PDFs themselves are not committed here โ€” they live in 1Password / secure drive / iCloud. This file only tracks metadata + pointers.
  • Update the file header status whenever the state changes.
  • Annual review (see compliance/review-schedule.md) re-opens each DPA for re-signature if the vendor's template has revved.