Team Clarity, Inc. DBA Iron Gorilla Public Subprocessor and Service Provider List
This list identifies providers and provider categories that may process personal data in connection with Iron Gorilla. Not every provider processes every customer's data. Customer-authorized integrations are not Team Clarity subprocessors unless Team Clarity separately engages them to provide the Services. The applicable Order Form, DPA, data region, plan, configuration, and Regulatory Addendum determine which providers may be used.
| Provider/category | Purpose | Possible data | Location framework | Regulated-data status |
|---|---|---|---|---|
| Amazon Web Services | Hosting, compute, storage, networking, backups, logging, and cloud infrastructure. | Account, Customer Data, logs, metadata, security and operational data, depending on configuration. | Provider and selected region; support and operational access may occur elsewhere as disclosed. | PHI or other regulated data only when the provider, services, region, and upstream contract are expressly approved in the applicable activation schedule. |
| Cloudflare | DNS, CDN, traffic management, web application firewall, DDoS protection, bot mitigation, security, and performance. | IP addresses, request metadata, security events, traffic and limited content depending on configuration. | Global network with regional and product-specific processing. | Regulated data only for specifically approved products/configurations and signed upstream terms; otherwise excluded. |
| Sentry | Error monitoring, debugging, reliability, and performance analysis. | Error events, stack traces, identifiers, metadata, and content inadvertently included by configuration. | Provider locations and project settings. | Not authorized for PHI or other specially regulated data unless specifically approved and configured to exclude or protect that data. |
| Stripe | Payment processing, billing, invoices, subscriptions, tax and payment-related fraud prevention. | Billing, transaction, payment-method metadata, business contact and account information. | Provider locations and financial network participants. | Not an approved PHI processing path. Customers must not place PHI or sensitive Customer Data in billing descriptions or payment metadata. |
| Microsoft 365 | Business email, documents, internal communications, support, and operations. | Business contact, support, account, document, and communication data. | Tenant and provider locations. | PHI only through an expressly approved tenant, service, configuration, and BAA schedule. Standard support email is not automatically HIPAA Eligible. |
| Google Analytics | Website and usage analytics, subject to consent and settings. | Cookie identifiers, device/browser data, page interactions, IP-derived location and referral data. | Provider network. | Not authorized for PHI, consumer health data, biometric identifiers, student data, or nonpublic financial information. |
| Twilio | SMS, verification, notifications, communications, and related messaging. | Telephone numbers, message metadata, verification and communication content depending on feature. | Provider and carrier network locations. | Regulated data only for expressly approved products, regions, configurations, and upstream contractual terms. |
| OpenAI | Supported AI model API processing, model calls, prompts, outputs, moderation, and related AI services where enabled. | Prompts, outputs, files, metadata, model and tool-call data as configured. | Provider locations and selected enterprise/API settings. | Default: not authorized for PHI or specially regulated data. Permitted only if named in the applicable activation schedule and all upstream contractual, retention, training, security, and regional requirements are satisfied. |
| Anthropic | Supported AI model API processing, model calls, prompts, outputs, and related AI services where enabled. | Prompts, outputs, files, metadata, model and tool-call data as configured. | Provider locations and selected enterprise/API settings. | Default: not authorized for PHI or specially regulated data. Permitted only if named in the applicable activation schedule and all upstream requirements are satisfied. |
| Other supported model providers | Model routing and AI services selected or enabled for a customer. | As described for the specific provider and feature. | Provider-specific. | Not approved for regulated data unless expressly identified in a signed activation schedule. |
| Customer-authorized integrations | CRM, ERP, HRIS, repositories, productivity, ticketing, communications, cloud, data, model, and other systems connected by Customer. | Data selected, transmitted, or accessed by Customer's configuration. | Determined by Customer and the connected provider. | Customer-authorized recipient, not a Team Clarity subprocessor unless separately engaged. Customer is responsible for legality and regulated-data eligibility. |
Change Notice and Objections
Team Clarity may add or replace subprocessors as described in the DPA. Enterprise customers with contractual notice or objection rights should use the contact and period stated in their DPA or Order Form. An objection must identify reasonable data-protection grounds relating to the new subprocessor. This public list should be maintained with version history and a subscription or notice mechanism before relying on it as the contractual change-notice channel.
Regulated Data
Presence on this list does not authorize a provider to receive protected health information, consumer health data, biometric information, student data, nonpublic financial information, controlled information, or other specially regulated data. Authorization requires a signed Regulatory Addendum and activation schedule naming the approved service path.
Contact
Questions and objections: legal@teamclarity.ai.