Subprocessors
PolicyHQ uses third-party services in the following categories to process customer data. Each entry lists the country where data is processed, the purpose, what data is involved, and the safeguards in place.
Customers can view the named list of subprocessors by signing in; it is also provided as an annex to the DPA on request to security@geminigr.com.
Last updated: September 30, 2026
Cloud database and authentication
Japan (Tokyo region); provider based in the United States- Purpose
- Primary database and user authentication
- Data involved
- All customer data: organization records, members, projects, workspaces, comments, notifications.
- Safeguards
- AES-256 encryption at rest, TLS in transit, SOC 2 Type 2
Application hosting and edge network
Japan (Tokyo region); static assets via a global edge network; provider based in the United States- Purpose
- Application hosting, request routing, scheduled jobs
- Data involved
- Request metadata (paths, headers, IP address). No customer body data persisted beyond standard request logs (30 days).
- Safeguards
- SOC 2 Type 2, ISO 27001
Background job execution
United States- Purpose
- Durable execution of long-running scheduled work
- Data involved
- Jobs run with database credentials, so customer data is readable during a run; job payloads and run logs are retained by the provider.
- Safeguards
- TLS in transit, access-controlled credentials, provider data protection terms
AI model API providers (text generation, embeddings, speech-to-text)
United States- Purpose
- Summaries, classification, chat answers, semantic search, transcription of publicly broadcast hearings
- Data involved
- Public-source text and audio (bills, news, public comments, hearing proceedings), plus user chat queries, retrieved context, and project context supplied by the customer.
- Safeguards
- Not used to train the providers' models; retention limited to the providers' API data-retention terms; SOC 2 Type 2
Machine translation
European Union (Germany)- Purpose
- Japanese ↔ English translation of titles, summaries, and speeches
- Data involved
- Japanese / English text strings.
- Safeguards
- Inputs not retained after the request returns; ISO 27001
Transactional email delivery
United States- Purpose
- Invitations, briefs, digests, and alerts
- Data involved
- Recipient email address, message body, delivery metadata.
- Safeguards
- SOC 2 Type 2
Identity provider (OAuth sign-in)
United States (global infrastructure)- Purpose
- Single sign-on
- Data involved
- Email address, display name, and profile photo URL at sign-in only.
- Safeguards
- SOC 2, ISO 27001
Payment processing
United States (global processing)- Purpose
- Subscription billing and payments
- Data involved
- Billing contact (name, email), subscription and invoice records. Card details are entered directly with the processor and never pass through PolicyHQ systems.
- Safeguards
- PCI DSS Level 1, SOC 2 Type 2
Error and performance monitoring
European Union (Germany); provider based in the United States- Purpose
- Application error and performance monitoring
- Data involved
- Scrubbed exception telemetry (stack traces, request paths, release metadata). Default PII collection disabled; sensitive fields stripped before transmission.
- Safeguards
- PII scrubbing, SOC 2 Type 2, ISO 27001
Public-data collection (web search, page and document fetching, public social-media posts)
United States; European Union (Czechia)- Purpose
- Collecting public government, news, and stakeholder sources
- Data involved
- Search queries, public URLs, and public account handles derived from tracked issues and stakeholders. No customer-identifying data sent.
- Safeguards
- No customer data transmitted