/ Legal / Sub-processors

CopyLoop Sub-processor List

Last Updated: July 23, 2026

Member Loop, LLC d/b/a CopyLoop ("CopyLoop") uses the third parties below to process Customer Personal Data on behalf of customers when providing the Services. Capitalized terms have the meanings given in the CopyLoop Data Processing Agreement ("DPA").

This is the authoritative public list referenced by Section 5 and Schedule 3 of the DPA. A provider processes only the data needed for the relevant service and, where a service is optional, only when the customer enables or uses it.

Current Sub-processors

Sub-processor Service and processing purpose Customer Personal Data that may be processed Processing location
Amazon Web Services, Inc. (AWS) Primary cloud infrastructure, including compute, database, cache, object storage, content delivery, transactional and marketing email delivery, secrets management, backups, and infrastructure monitoring Customer Personal Data processed through the Services United States
Anthropic, PBC Optional AI content generation and analysis through Claude models Prompts, instructions, content excerpts, retrieved context, and generated outputs United States
OpenAI OpCo, LLC and applicable OpenAI affiliates Optional AI content generation and analysis through the OpenAI API Prompts, instructions, content excerpts, retrieved context, and generated outputs United States and other locations identified in OpenAI's current sub-processor list
Voyage AI Innovations, Inc. Text embeddings for semantic search, content similarity, and retrieval-augmented generation Customer-provided document text and content excerpts United States
Qdrant Solutions GmbH Vector database used for semantic search, content similarity, and retrieval-augmented generation Vector representations, associated workspace identifiers, and limited retrieval metadata Germany / United States
Functional Software, Inc. (Sentry) Application error, performance, and security monitoring Error and diagnostic data, request metadata, device data, and limited Customer Personal Data if included in an error path United States
Tinybird Inc. Customer-directed application and website event ingestion, attribution and commerce analytics, query processing, retrieval for customer-facing dashboards and reports, and CopyLoop product analytics Workspace, user, visitor, session, and event identifiers; event properties; attribution and commerce metadata; product usage and diagnostic metadata United States
Cloudflare, Inc. Certificate issuance, DNS and request proxying for configured customer email-tracking domains IP addresses, request metadata, and email click or tracking-domain request data United States and globally distributed infrastructure
Firecrawl, Inc. Customer-requested crawling and extraction of web pages for document and content processing Customer-supplied URLs, extracted page content, and related request metadata United States

Proposed Changes

There are no proposed additions or replacements at this time.

Other Account, Operations, and Billing Providers

The following providers process CopyLoop account, operational, or billing information for CopyLoop's own business purposes and do not ordinarily process Customer Personal Data on Customer's behalf:

Provider Purpose Data
Evidence Technologies, Inc. Hosted internal business-intelligence dashboards for CopyLoop product and operational analytics CopyLoop account and product-usage analytics, pseudonymous user and workspace identifiers, operational metrics, and aggregated query results
Stripe, Inc. Subscription billing and payment processing Billing contacts, subscription records, payment status, and payment information supplied directly to Stripe

CopyLoop's processing of account, operational, and billing information is described in the Privacy Policy. Evidence Cloud is not connected to the separate customer-telemetry data store and is not used to render customer-facing analytics. If CopyLoop later authorizes Evidence to process Customer Personal Data, CopyLoop will first treat Evidence as a Sub-processor under the DPA, update the Current Sub-processors table, and provide the notice required by the DPA.

International Transfers and Provider Terms

CopyLoop requires Sub-processors to be subject to written data-protection obligations appropriate to their processing. Where Customer Personal Data is transferred from Europe to a country that is not covered by an applicable adequacy decision, CopyLoop uses a lawful transfer mechanism such as the European Commission's Standard Contractual Clauses and, for UK transfers, the UK Addendum, as described in the DPA.

Provider locations may change as a provider changes its infrastructure or published sub-processor list. The table above identifies the locations CopyLoop currently expects based on the Services and provider information available to CopyLoop; a provider's current contractual list controls the detail of its own onward processing.

Changes to this List

CopyLoop will provide at least fifteen (15) days' advance notice before authorizing a new or replacement Sub-processor to process Customer Personal Data, as described in Section 5 of the DPA. CopyLoop provides that notice automatically by email to the customer's notice address, primary account owner, or designated privacy contact and by updating this page; a separate email-notice subscription is not required.

CopyLoop may update corrections, descriptive details about an existing provider, or disclosures about providers that do not process Customer Personal Data on a customer's behalf at any time. Those updates do not authorize a new or replacement Sub-processor.

Questions or objections regarding a Sub-processor may be sent to privacy@copyloop.com.


Member Loop, LLC d/b/a CopyLoop
439 US Route 1, Suite A, York, ME 03909, USA
https://copyloop.com/legal/subprocessors