Legal
Sub-processor List
Effective / last updated: July 14, 2026· Connectivo, Inc.
To deliver our service, Connectivo engages a small number of trusted sub-processors. A sub-processor is a third party that processes personal or institutional data on our behalf. We publish this list for transparency and keep it current.
Infrastructure sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Primary cloud hosting, storage, and processing. | Account & administrator data; accessibility scan results and remediation records; transiently processed web page content; document and multimedia files undergoing remediation and their remediated versions. | United States (US regions by default; EU regions on request). |
| Google Cloud Platform (GCP) | Disaster recovery, backup, and secondary processing capacity. | Encrypted backups and the same categories as above during failover. | United States (US regions by default; EU regions on request). |
Service sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Twilio SendGrid | Transactional email (e.g., account, security, and notification messages). | Recipient name and email address; message metadata. | United States. |
| IBM Accessibility Checker | Accessibility validation — independent rule-based checking used to verify scan results and remediations against WCAG. | Page structure/content evaluated transiently for accessibility; no persistent storage of customer content. | United States. |
Optional / configurable services
The following service is used only when enabled by the customer and can be disabled without loss of core functionality:
| Service | Purpose | Data processed | Location |
|---|---|---|---|
| Google Cloud Vision (optional) | Supplementary visual analysis to support image and visual-content accessibility. Disabled by default unless the customer opts in. | Images/visual content evaluated transiently; no persistent storage of customer content. | United States. |
Connectivo’s core AI models are proprietary and privately hosted. Institutional data is not sent to public or consumer AI services. See our Responsible AI & Transparency Statement.
How we manage sub-processors
- Assessment of security and privacy posture before engagement, and periodically thereafter.
- Contractual controls via data-processing agreements, including breach-notification and liability terms and, where relevant, Standard Contractual Clauses.
- Least datashared — only what each provider needs for its function.
- Ongoing monitoring and periodic review of continued compliance.
Notification of changes
Before adding or replacing a sub-processor that processes personal or institutional data, we provide customers with advance notice (generally at least 30 days), giving customers the opportunity to review and, where their agreement allows, object. To receive notifications, or to ask questions about this list, contact [email protected].
This list is maintained by Connectivo and reflects sub-processors as of the date shown above.