Trust
Subprocessors
This page lists the subprocessor categories used to operate AssetLed. A provider is used only when the corresponding deployment, feature, or customer-authorized integration is configured.
Subprocessor categories
| Category | Purpose | Data categories | Region or transfer notes | When used |
|---|---|---|---|---|
| Dedicated Windows hosting and IIS | Hosts the Blazor Web App, API, worker services, and operational files for the production deployment. | Account data, website data, reports, logs, support metadata, and configuration needed to operate the service. | Depends on the dedicated Windows server location and configured backup process. | Always used for the hosted AssetLed deployment. |
| Microsoft SQL Server | Primary application, Hangfire, audit, log, compliance, billing, outreach, and reporting storage. | Account records, tenant data, workflow records, job state, audit events, product email logs, and retention records. | Co-located with the production deployment unless a different SQL Server is configured. | Always used when the app is running. |
| Mailgun product email | Sends product transactional email and optional product marketing email for AssetLed itself. | Email addresses, message metadata, delivery events, bounce events, complaint events, unsubscribe events, and template context. | Mailgun region is configured through product email settings and secret configuration. | Used for account, billing, security, privacy, report, product workflow, and optional marketing email. |
| Customer or admin outreach mailbox providers | Sends customer-approved outreach and monitors replies through configured SMTP/IMAP mailboxes. | Outreach recipients, message bodies, replies, bounce metadata, suppression links, mailbox health, and deliverability metadata. | Depends on the mailbox provider selected by the customer or administrator. | Only used when outreach mailboxes are configured and outreach workflows are enabled. |
| Stripe | Checkout, trials, subscriptions, invoices, customer portal, payment-state webhooks, and abuse-prevention signals. | Billing contact data, customer ids, subscription ids, invoice state, checkout sessions, payment-method fingerprints, and webhook metadata. | Stripe processes billing data according to the Stripe account configuration and Stripe transfer terms. | Used for card-required trial signup, package purchase, renewal, cancellation, upgrade, and billing recovery. |
| Google Analytics and Search Console | Connects authorized Google properties and imports impact snapshots for reporting. | OAuth metadata, protected refresh tokens, property identifiers, analytics metrics, search metrics, and derived report snapshots. | Google processing follows Google account, API, and workspace settings controlled by the authorizing user. | Only used after an authorized user connects Google data for a website. |
| Anthropic and configured AI engines | Analysis, drafting, reactive PR matching, AI visibility checks, and quality review where LLM judgment is required. | Prompts, responses, website context, asset context, prospect context, draft content, model metadata, token counts, and cost records. | Depends on the configured model provider and region. Prompts should avoid unnecessary personal data. | Used when AI-assisted analysis, drafting, matching, visibility, or review workflows run. |
| DataForSEO | SEO metrics, SERP data, keyword or domain enrichment, and prospect-quality context. | Submitted domains, URLs, keywords, target domains, enrichment requests, and returned SEO metrics. | Processed according to the configured DataForSEO account and service region. | Used when enrichment jobs run for websites, assets, prospects, or reports. |
| Logging and monitoring | Operational diagnostics, error investigation, alerting, performance review, and security event review. | Application logs, error details, request metadata, job metadata, integration status, and redacted diagnostic context. | Depends on the configured log storage, file storage, and monitoring deployment. | Used when the application records operational logs, error logs, audit logs, or monitoring events. |
| GitHub source control | Private source control, issue or code review workflows, and release coordination. | Source code, configuration templates, workflow metadata, commits, pull-request metadata, and CI logs. | GitHub processing follows the configured private repository and GitHub account terms. | Used for engineering, deployment preparation, and private repository operations. |
| GitHub Actions and self-hosted runner CI | Restore, build, tests, package workflows, deployment automation, and release verification. | Build logs, test logs, workflow metadata, package artifacts, deployment logs, and repository metadata. | Hosted or self-hosted runner location depends on the workflow configuration. | Used when CI, test, package, or deployment workflows run. |
Product email and outreach email are separate
Mailgun is the product-email provider for AssetLed transactional email and optional product marketing email. Mailgun is not used for customer outreach email. Outreach uses customer-configured or admin-configured SMTP/IMAP mailboxes managed in the admin area.
Subprocessor changes
Material subprocessor changes should be reflected on this page and in the privacy or DPA documents when the change affects customer personal data, data categories, processing purpose, or transfer posture.