Subprocessors
Last updated: September 8, 2026
Cerkl Incorporated (“Cerkl”) engages a limited number of third-party service providers, or subprocessors, to support the delivery, security, reliability, and operation of Cerkl Broadcast.
This page identifies the subprocessors that may process Customer Data on Cerkl’s behalf in connection with providing Broadcast.
Current Subprocessors
Google Cloud Platform
Provider: Google LLC
Purpose: Cloud infrastructure, application hosting, databases, storage, backup, and related infrastructure services
Applicability: All Broadcast customers
Primary Processing Location: United States
Data Processed: Customer Data stored or processed within Broadcast
Twilio SendGrid
Provider: Twilio Inc.
Purpose: Email delivery
Applicability: Customers using Broadcast email functionality
Primary Processing Location: United States
Data Processed: Email addresses, message content, delivery metadata, engagement metadata, and related email transmission data
WorkOS
Provider: WorkOS, Inc.
Purpose: Enterprise identity and Single Sign-On (SSO) infrastructure
Applicability: Only customers that enable supported SSO functionality
Primary Processing Location: United States
Data Processed: User identity information and authentication-related metadata necessary to provide SSO
WorkOS is used only when a customer elects to enable applicable SSO functionality. It does not process Customer Data on Cerkl’s behalf for customers that do not use this functionality.
How Cerkl Uses Subprocessors
A subprocessor is a third-party service provider engaged by Cerkl that may process Customer Data on Cerkl’s behalf in connection with providing Broadcast.
Not every vendor Cerkl uses in the ordinary operation of its business is a subprocessor. Vendors that do not process Customer Data in connection with providing Broadcast are not included on this page.
Cerkl evaluates subprocessors based on the nature of the service they provide and the associated security, privacy, and operational risks.
Subprocessor Security and Oversight
Cerkl maintains a third-party risk management process for service providers that may access or process Customer Data.
Depending on the nature of the service, Cerkl evaluates factors including:
- Information security and privacy practices
- Independent security certifications and attestations
- Data protection and confidentiality commitments
- Identity and access controls
- Incident response capabilities
- Data location and international transfer considerations
- Business continuity and operational resilience
Cerkl requires subprocessors that process Customer Data to maintain appropriate confidentiality, privacy, and security protections consistent with the services they provide.
Cerkl remains responsible for its subprocessors to the extent required under Cerkl’s agreements with its customers and applicable data protection law.
Data Location
Broadcast Customer Data is primarily processed and stored in the United States.
Where personal data is transferred across jurisdictions and applicable law requires additional safeguards, Cerkl uses appropriate data transfer mechanisms, including Standard Contractual Clauses where applicable.
Unless expressly agreed in writing, Cerkl does not represent that all processing, support activities, network routing, caching, or other incidental processing performed by its subprocessors will occur exclusively within a particular geographic jurisdiction.
Customer-Selected Third-Party Services
Customers may choose to connect Broadcast with third-party systems such as identity providers, HR information systems, collaboration platforms, intranets, or other enterprise applications.
A third-party service independently selected, contracted with, or controlled by a customer is generally not a Cerkl subprocessor, even where Broadcast interoperates with that service.
For example, a customer’s own identity provider used in connection with SSO is customer-selected, while WorkOS is Cerkl’s subprocessor for providing the supporting SSO infrastructure within Broadcast.
Changes to Subprocessors
Cerkl may periodically add, remove, or replace subprocessors as its technology and service infrastructure evolves.
Cerkl manages changes to subprocessors in accordance with its Data Processing Addendum and applicable contractual obligations. Where Cerkl has agreed to provide notice of a new subprocessor, notice will be provided in accordance with the applicable agreement.
The use of a new subprocessor does not reduce Cerkl’s obligations regarding the protection of Customer Data.
Additional Information
Additional information regarding Cerkl’s privacy, security, and data protection practices is available in Cerkl’s:
Customers conducting security, privacy, or procurement reviews may contact their Cerkl representative for additional information regarding Cerkl’s subprocessors or data protection practices.
