Last Updated: August 1, 2023

To support the delivery of our Services, RiskOptics, Inc. (“RiskOptics”) (or one of its Affiliates listed below) uses services providers (each, a “Subprocessor”) that may store or process Customer Data which may contain personal data.

RiskOptics requires its subprocessors to satisfy equivalent obligations as those required from RiskOptics (as a Data Processor) as outlined in RiskOptics’ Data Processing Agreement (DPA), including but not limited to the requirements to:

  • process personal data following data controller’s (i.e., Customer’s) documented instructions (as communicated in writing to the relevant subprocessor by RiskOptics);
  • in connection with the subprocessing activities, use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable, under applicable data protection laws;
  • promptly inform RiskOptics about any security breach; and
  • cooperate with RiskOptics to address requests from data controllers, data subjects, or data protection authorities, as applicable.

The following table describes the legal entities acting as a subprocessor for RiskOptics, the service that subprocessor relates to, the function that subprocessor performs on behalf of RiskOptics, the categories of personal data processed by that subprocessor on behalf of RiskOptics, the location of the processing, the adequacy mechanism utilized between that subprocessor and RiskOptics, and a link to the public DPA that subprocessor offers.

Third Party Risk Management is conducted annually on all subprocessors.

Name Service Service Provided by Subprocessor Category of PII Processed Location of Processing Adequacy Safeguards Public DPA Link
Auth0
  • ROAR
Identity Authentication Provider Contact information; technical identifiers. United States Standard Contractual Clauses Auth0 DPA (Public)
AWS
  • ROAR
  • ZenGRC
Cloud Service Provider Contact information; technical identifiers. United States Standard Contractual Clauses AWS DPA (Public)
Census
  • ROAR
  • ZenGRC
Data warehouse synchronization Contact information; technical identifiers. United States Standard Contractual Clauses Census DPA (Public)
Datadog
  • ROAR
  • ZenGRC
Infrastructure and cloud application monitoring Contact information; technical identifiers. United States Standard Contractual Clauses Datadog DPA (Public)
Elastic
  • ROAR
  • ZenGRC
Data alerting and reporting platform Technical identifiers United States Standard Contractual Clauses Elastic DPA (Public)
Fivetran
  • ROAR
Data warehouse transportation Contact information; technical identifiers. United States Standard Contractual Clauses Fivetran DPA (Public)
Gong.io
  • ROAR
  • ZenGRC
Business intelligence Contact information; screen and voice recordings. United States Standard Contractual Clauses Gong.io DPA (Public)
Google Workspace
  • ROAR
  • ZenGRC
Business Productivity Contact information; technical identifiers. United States Standard Contractual Clauses Google Workspace DPA (Public)
Insided B.V.
  • ROAR
  • ZenGRC
Community infrastructure platform Contact information; technical identifiers. United States Standard Contractual Clauses Insided B.V. DPA (Public)
Lightbeam.ai
  • ROAR
  • ZenGRC
Security and compliance automation Contact information; technical identifiers; other personal information submitted by the user. United States Standard Contractual Clauses Not publically available; e-mail [email protected] for inquiries regarding Lightbeam’s DPA.
Marketo
  • ROAR
  • ZenGRC
E-mail automation Contact information United States Standard Contractual Clauses Marketo DPA (Public)
Merge API, Inc.
  • ROAR
API Integrations Contact information, technical identifiers United States Standard Contractual Clauses Merge API DPA (Public)
Momentive, Inc. (GetFeedback)
  • ZenGRC
Surveys Contact information United States Standard Contractual Clauses Momentive, Inc. DPA (Public)
Pendo.io
  • ROAR
Platform usage analytics, communication Contact information; technical identifiers. United States Standard Contractual Clauses Pendo.io DPA (Public)
Salesforce.com, Inc.
  • ROAR
  • ZenGRC
Customer relations management and customer service Contact information; technical identifiers. United States Standard Contractual Clauses Salesforce.com, Inc. DPA (Public)
Segment.io, Inc.
  • ROAR
  • ZenGRC
Customer data infrastructure platform Contact information; technical identifiers. United States Standard Contractual Clauses Segment.io, Inc. DPA (Public)
Sisense, Inc.
  • ROAR
  • ZenGRC
Business intelligence Contact information; technical identifiers. United States Standard Contractual Clauses Sisense, Inc. DPA (Public)
Skilljar
  • ROAR
  • ZenGRC
Product training Contact information; technical identifiers. United States Standard Contractual Clauses Skilljar DPA (Public)
Slack Technologies
  • ZenGRC
  • ROAR
  • Corporate
Collaboration and Communications Contact information; technical identifiers. United States Standard Contractual Clauses Slack Technologies DPA (Public)
Splunk
  • ROAR
Data alerting and reporting platform Contact information; technical identifiers. United States Standard Contractual Clauses Splunk DPA (Public)
Twilio
  • ROAR
  • ZenGRC
Customer communication facilitation Contact information; technical identifiers. United States Standard Contractual Clauses Sendgrid DPA (Public)

RiskOptics Subsidiaries

Depending on the geographic location of a Customer or their authorized users, and the nature of the Services provided, RiskOptics may also engage our subsidiary to deliver some or all of the Services to a Customer.

Entity Name Country
Reciprocity, d.o.o. Slovenia