DPA Schedule A

Authorized Subprocessor Register

This Schedule A forms an integral part of the MarketMind AI Data Processing Addendum (DPA) and lists all third-party subprocessors authorized to process Customer Personal Data and operational payloads.

Last updated: August 2026

Google LLC (Google Cloud Platform)

Processing Activity & Scope

Core infrastructure hosting, serverless compute (Cloud Run), relational & vector database storage (pgvector on Cloud SQL), in-memory caching and rate-limiting (Memorystore / Valkey), asynchronous messaging (Pub/Sub), secrets injection (Secret Manager), and audit logging.

Corporate Location / Data Transfer Mechanism

United States / Multi-Region

  • •EU-U.S. Data Privacy Framework
  • •Standard Contractual Clauses (SCCs)
Security Certifications & Safeguards
  • •SOC 1, SOC 2 Type II, SOC 3
  • •ISO/IEC 27001, 27017, 27018
  • •HIPAA BAA Eligible
  • •PCI-DSS Level 1
  • •AES-256 Encryption at Rest

Google LLC (Google Vertex AI)

Processing Activity & Scope

Foundational LLM inference, embedding generation, and multi-agent reasoning workloads.

Corporate Location / Data Transfer Mechanism

United States / Multi-Region

  • •EU-U.S. Data Privacy Framework
  • •Standard Contractual Clauses (SCCs)
Security Certifications & Safeguards
  • •SOC 1/2/3, ISO/IEC 27001
  • •Contractual Zero Data Retention (ZDR)
  • •Enforced Zero Model Training Covenants

Google LLC (Cloud Identity / Firebase)

Processing Activity & Scope

End-user authentication, identity lifecycle management, JWT issuance, and multi-factor authentication (MFA).

Corporate Location / Data Transfer Mechanism

United States / Global

  • •EU-U.S. Data Privacy Framework
  • •Standard Contractual Clauses (SCCs)
Security Certifications & Safeguards
  • •SOC 1/2/3
  • •ISO/IEC 27001, 27018
  • •TLS 1.3 in Transit

WorkOS, Inc.

Processing Activity & Scope

Enterprise Single Sign-On (SAML 2.0 / OIDC) and directory synchronization (SCIM) for enterprise customer onboarding.

Corporate Location / Data Transfer Mechanism

United States

  • •EU-U.S. Data Privacy Framework
  • •Standard Contractual Clauses (SCCs)
Security Certifications & Safeguards
  • •SOC 2 Type II
  • •AES-256 Encryption at Rest
  • •End-to-End TLS Encryption

Cloudflare, Inc.

Processing Activity & Scope

Web Application Firewall (WAF), Distributed Denial of Service (DDoS) mitigation, edge DNS routing, and TLS 1.3 termination.

Corporate Location / Data Transfer Mechanism

Global Distributed Network

  • •EU-U.S. Data Privacy Framework
  • •Standard Contractual Clauses (SCCs)
Security Certifications & Safeguards
  • •SOC 2 Type II, ISO/IEC 27001
  • •PCI-DSS Level 1
  • •Transient Egress (No Data Storage)

Subprocessor Management & Compliance Rules

Zero-Training & Zero-Retention Enforceability

All inference subprocessors (Google Vertex AI) are bound by enterprise-tier agreements ensuring prompts, system contexts, database schemas, and vector embeddings are discarded immediately post-inference and never utilized for model training, fine-tuning, or alignment.

Notification of Subprocessor Changes

MarketMind AI maintains an updated register at marketmindai.cloud/legal/subprocessors. Subscribers receive minimum thirty (30) days' advance written notice via email prior to the activation of any new subprocessor.

Data Locality Control

Enterprise customers may request dedicated regional pinning (e.g., EU-only or US-only compute and storage boundaries within GCP) via an Enterprise Order Form.

Subscribe to Subprocessor Updates

Receive advance notice (minimum 30 days) before any new subprocessor is activated. Enter your email to subscribe to subprocessor change notifications.

This register is provided for informational purposes and forms a summary of authorized subprocessors. In the event of any conflict with the executed DPA, the signed agreement controls. Enterprise customers may request the current register at legal@marketmindai.cloud.