Last updated: September 8, 2026

Sub-processors

The complete list of companies that can touch your data on our behalf, what each one does with it, and how you hear about a change.

1. What a sub-processor is

A sub-processor is a company we hire that can process your data in the course of doing its job for us. We process data on behalf of our customers; when we bring in a vendor to help, that vendor sits one level below us, bound by our agreement with it rather than by yours with us.

We keep this list short deliberately. Every vendor added is another company that can hold your participants’ information, so the bar for adding one is high and the list below is the whole of it. There are no advertising networks and no data brokers on it, because we do not use any. The one measurement vendor, Google Analytics, runs on the public waiver.com marketing site and nowhere else — the app, the kiosk, and the signing pages carry no analytics at all.

2. The current list

Everything runs in the United States. Signed records live only with our hosting provider; the others receive the narrow slice their job requires — a name and email address to deliver a notification to, a billing contact to charge, a phone number to text.

Two of these are not handling data yet. Billing has not launched, so our payment processor holds nothing today, and text messaging has not launched, so no SMS provider is configured. We will name the SMS provider on this page, with the notice described in section 4, before the first message is sent.

3. How we choose and check them

Before a vendor receives any customer data we:

  • review its security posture and independent audit reports, such as SOC 2, where it has them;
  • put a written data processing agreement in place that limits it to processing on our instructions;
  • sign a business associate agreement with it before it can receive any protected health information;
  • confirm where the data will be stored and that it stays in the United States;
  • give it the minimum access its job requires, and no standing access to anything else.

Of the vendors above, only our hosting provider can hold protected health information; email delivery carries names and addresses for notifications only, payment processing receives billing data only, and DNS receives no customer data at all. We re-review a vendor whenever it changes something material about how it handles data, and we remain responsible to you for what our sub-processors do with your data.

4. How changes are announced

Account owners get at least 30days’ notice by email before a new sub-processor begins handling customer data, and this page is updated at the same time with the date at the top. The notice names the vendor, what it will do, what it will receive, and where it runs.

If you object to a new sub-processor on reasonable data protection grounds, reply to the notice and tell us why. We will work with you on an alternative; if there is none that works, you may cancel your subscription for the affected service without penalty before the change takes effect, and we will refund the unused portion of what you have paid.

Removing a sub-processor, or replacing one with something we run ourselves, does not require notice, but we update this page.

5. Contact

To ask about a vendor on this list, to request a copy of a data processing agreement, or to be added to the notification list for changes, write to help@waiver.com. Related reading: the Privacy Policy, the security page, and the business associate agreement.

All legal documents

QUESTIONS ABOUT THIS DOCUMENT?

Ask a person, not a form.

Write to help@waiver.com and someone who works on the product will answer. We would rather explain a clause than have you guess at it.