Subprocessors
This agreement is between eConsent LLC and the client with regard to access and use of econsent.org and related services. Contact us with questions.
Last Updated: April 6, 2026
Overview
eConsent uses a limited number of third-party service providers (“subprocessors”) to assist in delivering our Services. This page lists the subprocessors that may process customer data or consumer consent data on our behalf.
We will update this page when subprocessors are added or removed. Customers who have executed a Data Processing Agreement (DPA) with eConsent will be notified of material changes to this list in accordance with the terms of the DPA.
Infrastructure Subprocessors
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure — compute (Fargate), storage (S3, S3 Glacier, EFS), networking, CDN (CloudFront), database hosting (RDS, ElastiCache). Includes three-tier storage architecture for consent data: active storage, immutable S3 backup with Object Lock, and Glacier long-term archival. | All service data including session recordings, MP4 video conversions, certificates, attestation hashes, and metadata | United States (US-West-2) |
| Redis Cloud (Redis Ltd) | In-memory caching, session management, job queue storage | Session metadata, queue job payloads (no raw PII stored persistently) | United States |
Open-Source Tools (Self-Hosted)
The following open-source tools run entirely within eConsent’s AWS infrastructure. No customer or consumer data is transmitted to external services by these tools.
| Tool | Maintainer | Purpose | Data Processed | Location |
|---|---|---|---|---|
| FFmpeg | FFmpeg Project (open-source, LGPL/GPL) | Video encoding — converts session replay recordings to MP4 video format for long-term archival and portability | Session recording frames (processed locally, no external transmission) | Self-hosted within AWS (US-West-2) |
| Playwright | Microsoft (open-source, Apache 2.0) | Headless browser — renders session replays in a headless Chromium browser for MP4 video capture | Session recording DOM data (processed locally, no external transmission) | Self-hosted within AWS (US-West-2) |
| Whisper | OpenAI / ggerganov (open-source, MIT) | Speech-to-text transcription of eConsent Voice audio uploads — runs entirely on eConsent infrastructure | Audio files and generated transcripts (processed locally, no external transmission) | Self-hosted within AWS (US-West-2) |
| Resemblyzer | CorentinJ (open-source, MIT) | Speaker-embedding model used to compute 256-dimensional voiceprints for eConsent Voice fraud-integrity checks — runs entirely on eConsent infrastructure | Audio files and generated numerical embeddings (processed locally, no external transmission) | Self-hosted within AWS (US-West-2) |
| ONNX Runtime | Microsoft (open-source, MIT) | Runs the in-house eConsent Voice consent classifier model — no third-party inference service | Consent transcript text (processed locally, no external transmission) | Self-hosted within AWS (US-West-2) |
| pgvector | Andrew Kane (open-source, PostgreSQL License) | Vector similarity search for voiceprint comparison within eConsent’s RDS PostgreSQL database | Voiceprint embeddings (stored within eConsent’s database) | Self-hosted within AWS (US-West-2) |
Payment Processing
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Stripe | Subscription billing and payment processing | Customer billing information (name, email, payment method). Stripe handles all card data — eConsent does not store complete card numbers. | United States |
Communication
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| SendGrid (Twilio) | Transactional email delivery | Recipient email addresses, email content (account notifications, billing alerts, scheduled reports) | United States |
Analytics
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| PostHog | Product analytics and usage tracking | Anonymized usage events, feature adoption metrics. No consumer PII is sent to PostHog. | United States / European Union |
Platform Integrations
| Subprocessor | Purpose | Data Processed | Location |
|---|---|---|---|
| Meta Platforms (Facebook/Instagram) | Lead data retrieval for Meta Lead Ad certificate generation | Lead form responses, form definitions, ad attribution data — processed only when the customer connects their Facebook Page and only for the purpose of generating consent certificates | United States |
Data Processing Principles
- We select subprocessors based on their security posture, compliance certifications, and data handling practices
- All subprocessors are bound by contractual obligations regarding data protection and confidentiality
- We conduct periodic reviews of subprocessor security and compliance
- We limit the data shared with each subprocessor to what is necessary for their specific function
- Consumer consent data is never shared with subprocessors for their own commercial purposes
Changes to This List
We will update this page when we engage new subprocessors or discontinue existing ones. Material changes will be communicated to customers with active DPAs at least 30 days in advance.
Questions
If you have questions about our subprocessors or data processing practices, contact us at privacy@econsent.org.