Skip to Content
ComplianceSubprocessors

Compliance — Sub-Processors

FlowState uses the following third-party sub-processors to deliver the service. This list is maintained under Article 28 GDPR.

AWS (Amazon Web Services EMEA SARL)

Purpose: Compute, storage, database, key management, email sending, and all core infrastructure.

Data processed: All FlowState client and tenant data (deal data, user profiles, audit logs, credentials, email notifications).

Region: eu-central-1 (Frankfurt) for all data-at-rest and primary compute. us-east-1 (Virginia) for the APN inbound handler (in-memory transit only — no data persisted).

Specific services used:

  • DynamoDB (all structured tenant and user data)
  • S3 (pipeline snapshots, audit archives, export archives)
  • Secrets Manager (per-tenant OAuth tokens, API keys, ExternalIds)
  • KMS (per-tenant encryption CMKs)
  • SES (transactional email, eu-central-1)
  • CloudWatch Logs, Metrics, and Alarms
  • SQS (APN outbound queue, notification dispatch queue)
  • SNS (notification dispatch, SES feedback routing)
  • Lambda (all serverless compute)
  • API Gateway (REST API)
  • Cognito (identity, authentication)
  • CloudFront + S3 (frontend and docs site static hosting)
  • EventBridge (APN inbound event routing)
  • Bedrock (AI analysis via AgentCore)

DPA: AWS GDPR Data Processing Addendum 


Stripe (Stripe Payments Europe, Ltd.)

Purpose: Payment processing, subscription management, and invoicing for tenants on the direct Stripe billing path.

Data processed: Tenant owner’s billing information collected via Stripe Checkout at signup and on the direct Stripe billing path: personal name, business/company name (collected separately from — and not to be confused with — the FlowState tenant name), email, phone number, billing address (including country), and payment method metadata. Stripe stores the card/bank details and this billing information — FlowState stores only the Stripe customer ID and subscription ID, not raw payment data or a copy of the billing profile.

Note: Only applies to tenants that signed up via the direct Stripe path. Tenants on the AWS Marketplace billing path do not interact with Stripe. Phone number and billing address are collected as part of the self-serve, payment-required-at-signup Stripe Checkout flow.

Region: Stripe’s European entity processes EU payment data within the EU under its own DPA.

DPA: Stripe Data Processing Agreement 


HubSpot (HubSpot Ireland Limited)

Purpose: CRM integration. FlowState reads deal and contact data from each tenant’s own HubSpot portal, and writes APN sync status properties back.

Data processed: Deal properties, pipeline stage data, contact names and job titles associated with deals. FlowState does not store contact email addresses or personal data beyond what is required to construct APN opportunity payloads (which are processed transiently in memory during a pipeline run).

Note: FlowState does not control or operate HubSpot. FlowState accesses each tenant’s own HubSpot portal on the tenant’s behalf using OAuth tokens authorized by the tenant. The tenant is the HubSpot data controller; FlowState is a processor acting on their behalf for the specific purpose of APN sync and pipeline analysis.

Region: HubSpot data is stored in the region the tenant’s HubSpot portal is hosted in. FlowState has no control over this.


Anthropic (Anthropic, PBC) — via AWS Bedrock

Purpose: AI analysis of deal pipeline data (stalled deal detection, deal summaries, win/loss analysis).

Data processed: Deal property data (deal name, stage, close date, activities summary, owner) is sent to the Bedrock API for analysis. Contact personal data is not sent.

Note: FlowState accesses Anthropic’s Claude models via AWS Bedrock (not the Anthropic API directly). AWS Bedrock’s data processing terms apply; data processed via Bedrock is not used by AWS or Anthropic to train foundation models.

DPA: Covered by the AWS Bedrock service terms, which are part of the AWS DPA.


AWS Marketplace (Amazon Web Services, Inc.)

Purpose: Billing relationship management for tenants on the AWS Marketplace billing path.

Data processed: AWS customer identifier, AWS account ID, subscription entitlement data. FlowState receives and stores the customer identifier returned by the Marketplace Metering Service.

Note: Only applies to tenants on the AWS Marketplace billing path.


Slack Technologies, LLC

Purpose: Optional integration allowing a tenant to connect their own Slack app for status checks and a connection-test message when the Slack integration is enabled.

Data processed: For any tenant with Slack connected, FlowState looks up tenant member email addresses against the tenant’s Slack workspace to identify users, and can send a direct message to a Slack user as part of the connection-test flow.

Note: FlowState does not control or operate the tenant’s Slack workspace. This integration is optional and is only active for tenants who choose to connect Slack. Region and DPA details for this sub-processor relationship are under legal review.


Google LLC

Purpose: “Sign in with Google” — a federated identity provider option for authentication.

Data processed: For any user who signs in via Google, Google processes the OAuth authentication flow and returns profile claims (email, name) used to authenticate the user.

Note: Only applies to users who choose to sign in via Google. Region and DPA details for this sub-processor relationship are under legal review.


AWS Partner Central (APN) — open question

APN sync writes deal/opportunity data into a tenant’s own AWS Partner Central account, via a role the tenant grants FlowState — not into a FlowState-controlled AWS resource. Whether this constitutes a FlowState sub-processor relationship, as opposed to the tenant directing their own data into their own AWS environment, is a legal question we have not yet resolved. It is noted here so it is considered explicitly rather than omitted.


Changes to this list

FlowState will update this page when sub-processors are added or removed. Tenants who have executed a DPA with FlowState will be notified of material changes to this sub-processor list with at least 30 days’ notice.