Sub-Processors

Last updated: March 26, 2026

Kosmatic Inc. ("Kosmatic") uses the following third-party sub-processors to deliver the Auraflow platform. Each sub-processor has been vetted for appropriate data protection practices and is bound by data processing agreements consistent with GDPR, CCPA, and other applicable privacy laws.

We will provide 30 days' written notice before adding a new sub-processor. Customers may object within 14 days of notice per the terms of our Data Processing Agreement.

Infrastructure

Sub-ProcessorServiceLocationData ProcessedDPA/Certifications
RenderCloud hosting (compute, storage, managed PostgreSQL, managed Redis)United States (Oregon)All platform data (encrypted at rest AES-256, in transit TLS 1.3)SOC 2 Type II

E-Commerce Platform

Sub-ProcessorServiceLocationData ProcessedDPA/Certifications
Shopify Inc.E-commerce platform integration, OAuth, Billing API, webhooksUnited States / CanadaStore metadata, customer data (as authorized), order history, Script Tag hostingShopify DPA

Marketing Integrations

Sub-ProcessorServiceLocationData ProcessedDPA/Certifications
KlaviyoEmail marketing automationUnited StatesEmail address, behavioral archetype, segment membership, CLV estimate, suggested playbookKlaviyo DPA, SOC 2
HubSpotCRM integrationUnited StatesEmail address, name, archetype, segment, CLV, engagement dataHubSpot DPA, SOC 2
Meta Platforms (Facebook)Advertising optimization via Conversions API (server-side)United StatesHashed email (SHA-256), hashed phone (if available), conversion events. No raw behavioral data.Meta Data Processing Terms
Google LLCGoogle Analytics 4 (Measurement Protocol), Google OAuth, Google Ads (audience sync)United StatesAnonymized usage events, OAuth profile (name, email), hashed identifiers for audience matchingGoogle DPA
Slack (Salesforce)Merchant notificationsUnited StatesHigh-intent visitor alerts (archetype, score) sent to Merchant's own Slack workspace via incoming webhookSlack DPA

AI Processing

Sub-ProcessorServiceLocationData ProcessedDPA/Certifications
AnthropicAI processing via MCP for AI Workflows and chat-based analyticsUnited StatesMerchant-scoped analytics queries. No End User PII used for model training.Anthropic Terms

Transactional Email

Sub-ProcessorServiceLocationData ProcessedDPA/Certifications
SMTP ProviderTransactional email delivery (login codes, password resets, breach notifications)Varies by configurationMerchant email address, email content (codes/links)Configured per merchant

Changes to This List

DateChange
March 26, 2026Updated Privacy Policy, Terms of Service, and Cookie Policy with automated decision-making disclosures per GDPR Article 22.
March 23, 2026Added Anthropic (MCP AI processing), SMTP Provider (transactional email). Added DPA links for all processors.
March 4, 2026Initial list published.

Questions?

If you have questions about our sub-processors or wish to object to a new sub-processor, contact support@kosmatic.com.