help and policies: Reorganize GDPR compliance documentation.

Also add reference links.
This commit is contained in:
Alya Abbott
2025-01-10 15:39:08 -08:00
committed by Tim Abbott
parent 5a40755357
commit 126d76db50
3 changed files with 130 additions and 113 deletions

View File

@@ -6,6 +6,7 @@
* [Rules of Use](/policies/rules)
* [Age of consent](/policies/age-of-consent)
* [Data Processing Addendum](/static/images/policies/Zulip-Data-Processing-Addendum.pdf)
* [Subprocessors for Zulip Cloud](/policies/subprocessors)
## Archive
* [Terms of Service in 2021](/policies/terms-before-2022)

View File

@@ -0,0 +1,42 @@
# Subprocessors for Zulip Cloud
[Learn about GDPR compliance with Zulip.](/help/gdpr-compliance)
To support delivery of our Services, Kandra Labs, Inc. may engage and
use data processors with access to certain Customer Data (each, a
"Subprocessor"). This section provides important information about
the identity, location and role of each Subprocessor. Terms used on
this page but not defined have the meaning set forth in Zulip's Terms
of Service or superseding written agreement between Customer and
Kandra Labs (the "Agreement").
### Third parties
Zulip currently uses third party Subprocessors to provide
infrastructure services, and to help us provide customer support and
email notifications. Prior to engaging any third party Subprocessor,
we perform diligence to evaluate their privacy, security and
confidentiality practices.
**Subprocessors**
Zulip Cloud may use the following Subprocessors to host Customer Data
or provide infrastructure that helps with delivery and operation of
our Services:
* [Amazon Web Services, Inc.](https://aws.amazon.com/compliance/gdpr-center/)
for cloud infrastructure.
* [DigitalOcean, LLC](https://www.digitalocean.com/security/gdpr/)
for cloud infrastructure.
* [FrontApp, Inc.](https://community.frontapp.com/t/x1p4mw/is-front-compliant-with-gdpr)
for customer support.
* [Functional Software, Inc. d/b/a Sentry](https://blog.sentry.io/2018/03/14/gdpr-sentry-and-you)
for error tracking.
* [Google LLC](https://privacy.google.com/businesses/compliance/) for
cloud infrastructure and services.
* [Mailgun Technologies, Inc.](https://www.mailgun.com/gdpr) for email processing.
* [Rackspace US, Inc.](https://www.rackspace.com/en-us/gdpr) for cloud
infrastructure for our Zephyr mirroring service.
* [Stripe, Inc.](https://stripe.com/guides/general-data-protection-regulation) for payment processing.
* [The Rocket Science Group LLC d/b/a Mailchimp](https://kb.mailchimp.com/accounts/management/about-the-general-data-protection-regulation)
for email processing.