CopyLoop Sub-processor List
Last Updated: July 23, 2026
Member Loop, LLC d/b/a CopyLoop ("CopyLoop") uses the third parties below to process Customer Personal Data on behalf of customers when providing the Services. Capitalized terms have the meanings given in the CopyLoop Data Processing Agreement ("DPA").
This is the authoritative public list referenced by Section 5 and Schedule 3 of the DPA. A provider processes only the data needed for the relevant service and, where a service is optional, only when the customer enables or uses it.
Current Sub-processors
| Sub-processor | Service and processing purpose | Customer Personal Data that may be processed | Processing location |
|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Primary cloud infrastructure, including compute, database, cache, object storage, content delivery, transactional and marketing email delivery, secrets management, backups, and infrastructure monitoring | Customer Personal Data processed through the Services | United States |
| Anthropic, PBC | Optional AI content generation and analysis through Claude models | Prompts, instructions, content excerpts, retrieved context, and generated outputs | United States |
| OpenAI OpCo, LLC and applicable OpenAI affiliates | Optional AI content generation and analysis through the OpenAI API | Prompts, instructions, content excerpts, retrieved context, and generated outputs | United States and other locations identified in OpenAI's current sub-processor list |
| Voyage AI Innovations, Inc. | Text embeddings for semantic search, content similarity, and retrieval-augmented generation | Customer-provided document text and content excerpts | United States |
| Qdrant Solutions GmbH | Vector database used for semantic search, content similarity, and retrieval-augmented generation | Vector representations, associated workspace identifiers, and limited retrieval metadata | Germany / United States |
| Functional Software, Inc. (Sentry) | Application error, performance, and security monitoring | Error and diagnostic data, request metadata, device data, and limited Customer Personal Data if included in an error path | United States |
| Tinybird Inc. | Customer-directed application and website event ingestion, attribution and commerce analytics, query processing, retrieval for customer-facing dashboards and reports, and CopyLoop product analytics | Workspace, user, visitor, session, and event identifiers; event properties; attribution and commerce metadata; product usage and diagnostic metadata | United States |
| Cloudflare, Inc. | Certificate issuance, DNS and request proxying for configured customer email-tracking domains | IP addresses, request metadata, and email click or tracking-domain request data | United States and globally distributed infrastructure |
| Firecrawl, Inc. | Customer-requested crawling and extraction of web pages for document and content processing | Customer-supplied URLs, extracted page content, and related request metadata | United States |
Proposed Changes
There are no proposed additions or replacements at this time.
Other Account, Operations, and Billing Providers
The following providers process CopyLoop account, operational, or billing information for CopyLoop's own business purposes and do not ordinarily process Customer Personal Data on Customer's behalf:
| Provider | Purpose | Data |
|---|---|---|
| Evidence Technologies, Inc. | Hosted internal business-intelligence dashboards for CopyLoop product and operational analytics | CopyLoop account and product-usage analytics, pseudonymous user and workspace identifiers, operational metrics, and aggregated query results |
| Stripe, Inc. | Subscription billing and payment processing | Billing contacts, subscription records, payment status, and payment information supplied directly to Stripe |
CopyLoop's processing of account, operational, and billing information is described in the Privacy Policy. Evidence Cloud is not connected to the separate customer-telemetry data store and is not used to render customer-facing analytics. If CopyLoop later authorizes Evidence to process Customer Personal Data, CopyLoop will first treat Evidence as a Sub-processor under the DPA, update the Current Sub-processors table, and provide the notice required by the DPA.
International Transfers and Provider Terms
CopyLoop requires Sub-processors to be subject to written data-protection obligations appropriate to their processing. Where Customer Personal Data is transferred from Europe to a country that is not covered by an applicable adequacy decision, CopyLoop uses a lawful transfer mechanism such as the European Commission's Standard Contractual Clauses and, for UK transfers, the UK Addendum, as described in the DPA.
Provider locations may change as a provider changes its infrastructure or published sub-processor list. The table above identifies the locations CopyLoop currently expects based on the Services and provider information available to CopyLoop; a provider's current contractual list controls the detail of its own onward processing.
Changes to this List
CopyLoop will provide at least fifteen (15) days' advance notice before authorizing a new or replacement Sub-processor to process Customer Personal Data, as described in Section 5 of the DPA. CopyLoop provides that notice automatically by email to the customer's notice address, primary account owner, or designated privacy contact and by updating this page; a separate email-notice subscription is not required.
CopyLoop may update corrections, descriptive details about an existing provider, or disclosures about providers that do not process Customer Personal Data on a customer's behalf at any time. Those updates do not authorize a new or replacement Sub-processor.
Questions or objections regarding a Sub-processor may be sent to privacy@copyloop.com.
Member Loop, LLC d/b/a CopyLoop
439 US Route 1, Suite A, York, ME
03909, USA
https://copyloop.com/legal/subprocessors