๐ Sub-processor DPA Tracker
Status of every sub-processor's Data Processing Agreement. Pre-filled where we control both sides, marked "draft โ not countersigned" where we are waiting on the vendor.
Each DPA has its own file in this directory with the live status + the next action + the exact email / portal path to execute it.
Live scoreboardโ
| Sub-processor | Role | DPA form | Status | Owner | Next action |
|---|---|---|---|---|---|
| Google (Firebase) | Hosting, Auth, Firestore, Functions, Storage, FCM | Google Customer DPA (standard) | ๐ก Ready โ not yet accepted in console | Ops | Click-accept at Firebase Console โ Project Settings โ Integrations โ Data Processing and Security Terms |
| Lambda, Inc. | GPU inference โ the live processor. Every uploaded video is processed on Lambda hardware | Vendor template expected | ๐ด Draft request ready โ not sent. Highest-priority gap | Ops / DPO | Populate the account ID, then dispatch lambda-dpa.md ยง"Outbound request" |
| RunPod Inc. | GPU inference โ fallback only, currently receives no traffic (DEFAULT_GPU_PROVIDER_POLICY is Lambda-only) | Vendor template expected | ๐ด Draft request prepared โ not sent | Ops | Dispatch runpod-dpa.md ยง"Outbound request" |
| Resend Inc. | Transactional email | Vendor template expected | ๐ด Draft request prepared โ not sent | Ops | Dispatch resend-dpa.md ยง"Outbound request" |
| Apple Inc. | App Store Connect, Sign in with Apple, IAP | Apple Developer Program License + applicable privacy terms | ๐ก Account acceptance not reverified | Ops | Verify the current agreement and archive evidence |
| Stripe | Hosted Checkout/portal, customer and subscription events | Vendor standard DPA | ๐ก Available โ test account only; acceptance and production readiness not verified | Ops + DPO | Complete stripe-dpa.md checklist before live mode |
| Cloudflare | (future, if we front with CDN) | Vendor standard | โช N/A | โ | โ |
:::danger Corrected 2026-08-19
This table previously named RunPod as the GPU inference sub-processor and did
not list Lambda at all. That was backwards: production has been Lambda-only
since RunPod sat at 402 Insufficient Balance, so the listed processor handles
nothing and the actual processor of every uploaded video was absent from the
register.
A sub-processor list that omits a live processor is an Art. 28 / Art. 30 problem rather than a documentation nit, and the public sub-processor notice on the landing page inherits from this table โ check it too. :::
Legend: ๐ข acceptance evidenced + in force ยท ๐ก available/prepared, awaiting verification or execution ยท ๐ด request/action not started ยท โช not applicable
How this directory is maintainedโ
- One file per sub-processor,
<vendor>-dpa.md. - The file tracks: role, data categories, outbound request text, inbound response, countersigned PDF pointer, and review date.
- Signed PDFs themselves are not committed here โ they live in 1Password / secure drive / iCloud. This file only tracks metadata + pointers.
- Update the file header
statuswhenever the state changes. - Annual review (see
compliance/review-schedule.md) re-opens each DPA for re-signature if the vendor's template has revved.