Legal

Data Processing & Sub-processors

Last updated: 9 June 2026

This page describes how Prosperise processes personal data on your behalf and lists the sub-processors we use. It complements our Privacy Policy and Terms of Service. A signed Data Processing Agreement (DPA) is available on request for business customers.

1.Roles

For the personal data you upload or generate about your prospects and contacts, you act as the data controller and Prosperise acts as your processor: we process that data only to provide the service, on your documented instructions, and as described in our agreement with you.

2.Sub-processors

We engage a small set of sub-processors who process personal data on our behalf, each under contractual data-protection obligations:

  • Stripe — payment processing and subscription billing. Card data is collected and stored by Stripe; we never receive it. (PCI-DSS Level 1 certified.)
  • Amazon Web Services (AWS) — cloud hosting, database, and file storage for the platform.
  • Anthropic, via AWS Bedrock — AI inference to draft content. Prompts and content are processed within our AWS region and are not used to train third-party models.

3.Security measures

We apply encryption in transit (TLS) and at rest, role-based access controls and least-privilege access, encrypted storage of LinkedIn tokens and secrets, and operational logging. Access to production data is restricted to authorized personnel.

4.Data location & residency

The platform is hosted on AWS in our configured region, and AI inference via Bedrock runs within that region. Where any transfer outside your jurisdiction occurs, it is covered by appropriate safeguards (such as Standard Contractual Clauses) and our providers’ certifications.

5.Changes to sub-processors

We will keep this page current. If we add or replace a sub-processor that processes your personal data, we will update this list and, where required, notify you so you can review the change before it takes effect.

6.Assisting with data-subject requests

We will assist you, taking into account the nature of the processing, in responding to requests from individuals exercising their rights (access, correction, deletion, portability, and objection), and in meeting your security and breach-notification obligations.

7.Breach notification

If we become aware of a personal-data breach affecting data we process for you, we will notify you without undue delay and provide the information you reasonably need to meet your own notification obligations.

8.Requesting the full DPA & contact

To put a signed DPA in place, or for any data-protection question, contact privacy@prosperise.io. Payment processing is additionally governed by Stripe’s own Data Processing Agreement.