Gateway logoGateway mascotGATEWAY

List of Subprocessors

January 1, 2026

This page lists the third-party service providers ("Subprocessors") that Gateway.FM AS engages to process personal data on behalf of customers in connection with its services.

What is a Subprocessor?

A subprocessor is a third-party service provider that processes personal data on our behalf under our instructions. We engage subprocessors where necessary to operate and support our services. We assess subprocessors prior to engagement and require them to implement appropriate technical and organisational measures to protect personal data, consistent with applicable data protection laws.

Updates to This List

We will provide at least 30 days' notice of any material changes to our subprocessors that process customer personal data. Notice will be provided by updating this page and, where required, by email notification to the customer's primary contact on file.

Customer Rights

Customer rights relating to subprocessors, including notice and objection rights, are governed by the applicable Data Processing Addendum (DPA).

Customers may object to a new subprocessor on reasonable data protection grounds by contacting legal@gateway.fm within the notice period. If no reasonable alternative is available, the customer may terminate the affected services in accordance with the applicable agreement.

Infrastructure & Hosting

SubprocessorPurposeData ProcessedLocationSafeguards / Certifications
AWS EMEACloud infrastructure hostingName, work email, authentication/access metadata, service logsEU / GlobalSOC 2, ISO 27001, ISO 27701
Google (G Suite / Workspace / Google Sheets / Google Cloud / Google Ads)Cloud productivity, storage, analyticsName, email, profile info, documents, calendar events, IP, location, usage logsGlobalISO 27001, SOC 2, GDPR compliant
Vercel Inc.Hosting / deploymentAccount data, usage metadata, deployment logs, support communicationUS / GlobalISO 27001
DoiTMulti-cloud optimization & managementUsage data, billing data, support communicationsEU / GlobalISO 27001, SOC 2
Servers.com IncBare metal hosting & colocationCustomer data, server logs, account dataEU / US / GlobalISO 27001, SOC 2
Latitude.shBare metal & edge infrastructureAccount data, usage data, support logsUS / EUSOC 2, ISO 27001
Cloudflare, Inc.CDN, DNS, DDoS protection & securityIP addresses, traffic data, cached content, logsGlobalISO 27001, SOC 2 Type II, GDPR aligned

Security & Monitoring

SubprocessorPurposeData ProcessedLocationSafeguards / Certifications
PagerDuty, Inc.Incident management / alertsNames, email, job titles, IP, activity logsUSSOC 2
Twingate Inc.Network security / VPNAccount info, usage logs, device/network dataUS / GlobalSOC 2, ISO 27001
1PasswordPassword & credential managementName, email, phone, job titleGlobalISO 27001
AbsenceLeave & absence managementName, email, job title, department, leave types, leave dates, duration, optional reason, leave balance, working hours, clock-in/out, doctor's notes, approver detailsGermany (EU)GDPR compliant, contractual and technical security measures
VeriffIdentity verification (KYC)ID documents, biometric data, video selfies, verification metadataEU (Estonia), USISO 27001, ISO 27701, GDPR aligned
VantaCompliance & security automation platformAccount information, service metadata, usage and log data, cookies, device and location infoUS / GlobalISO-aligned security measures, EU-U.S. Data Privacy Framework
Adaptive SecurityCybersecurity & risk detection servicesPersonal information as processed per service (general & security metadata)US / GlobalAdheres to EU-U.S., UK & Swiss Data Privacy Frameworks
XFAZero trust device security & complianceDevice identifiers/status, organization account details, email only when linkedIreland (AWS Ireland) / EUEncryption at rest/in transit, privacy-by-design
Aikido SecurityApplication security & vulnerability monitoringIP addresses, code metadata, logs, security eventsEU (Belgium)GDPR compliant, ISO-aligned

Communications & Support

SubprocessorPurposeData ProcessedLocationSafeguards / Certifications
SlackTeam messaging & collaborationUser accounts, messages, workspace/channel data, IPUS / EUSOC 2 Type II
Zendesk.com – IRECustomer support / ticketingCustomer profiles, tickets, feedbackEU / USSOC 2
HubSpotCRM, marketing & customer engagementPersonal email addresses, CRM recordsUS / EUSOC 2, SCCs, GDPR compliant

Analytics & Operations / AI Automation

SubprocessorPurposeData ProcessedLocationSafeguards / Certifications
OpenAIAI conversation / analysisInputs, account info, payment data, IP, usage patternsUS / GlobalSOC 2, ISO 27001
GreenhouseCandidate & recruitment analyticsCandidate info, resumes, tax jurisdiction, expected CTCUS / GlobalISO 27701
Datadog, Inc.Monitoring & analyticsName, email, IP, device location, usage dataUS / EUSOC 2 Type II, ISO 27001

Payment Processing

SubprocessorPurposeData ProcessedLocationSafeguards / Certifications
DeelContractor payroll & paymentsName, bank info, tax IDs, government IDsUS / GlobalSOC 2
Revolut BusinessPayment processingID, EIN, proof of activity, directors/shareholdersEU / GlobalSOC 2, ISO 27001
PowerOffice Go (POGO)Payroll & invoicing communicationEmployee payroll, invoices, receiptsNorway / EUGDPR compliant
ZohoFinancial, accounting & business operationsCompany info, tax IDs, bank details, financial records, vendor & user dataGlobalISO 27001, GDPR compliant

Development & Collaboration Tools

SubprocessorPurposeData ProcessedLocationSafeguards / Certifications
GitHub, Inc.Code repository / collaborationAccount data, usage logs, billing infoUS / GlobalISO 27001
FigmaDesign & collaborationAccount info, design files, version historyUS / EUISO 27001
NotionCollaboration & documentationAccount info, documents, usage logsUSSOC 2, ISO 27001
LinearProject managementAccount data, profile, passwordsGlobalSOC 2 Type II, GDPR compliant
DocuSign Inc.E-signature & contract managementNames, emails, signed documents, IP addresses, logsUS / EUISO 27001, SOC 2 Type II
Docker IncContainer platform & image registryAccount data, usage telemetry, IP addresses, logsUS / GlobalSOC 2 Type II, ISO 27001
FireHydrantIncident management and response platformAccount data (name, email), payment data, authentication data, system logs, IP addresses, device/usage data, support requestsUS / GlobalStandard security measures, contractual controls

Thank you

Your request has been received!