Colloquial Logo

Sub-processors and Third-Party Service Providers

Last updated on 5 July, 2025

This page lists all sub-processors and third-party service providers that Colloquial Solutions Pty Ltd ("Colloquial") engages to process personal data in connection with our services. This information is provided in accordance with our Data Processing Addendum (DPA) and ISO 27001 compliance requirements.

Data Processing Arrangements

All sub-processors listed below are engaged under written agreements that include appropriate data protection obligations consistent with our DPA and applicable data protection laws, including the General Data Protection Regulation (GDPR) and other relevant privacy legislation.

Sub-processor Information

The table below provides details about each sub-processor, including their function, data processing location, and relevant compliance information.

Sub-processorPurposeLocationData ProcessedLegal BasisAdditional Details
AirwallexInternational payments and banking servicesAustralia/GlobalPayment data, banking information, transaction recordsContract PerformanceISO 27001, PCI DSS certified. Global financial services compliance
AzureCloud infrastructure and hosting servicesGlobal (Multiple Regions)Application data, user data, system logsContract PerformanceSOC 1/2/3, ISO 27001, GDPR compliant. Data residency controls available
VantaCompliance and security monitoringUnited StatesSecurity logs, compliance data, audit trailsLegitimate InterestSOC 2 Type II, ISO 27001 certified. Continuous monitoring
GitHubSource code repository and development collaborationUnited StatesSource code, development data, user identifiersContract PerformanceSOC 2 Type II, ISO 27001 certified. Enterprise security features
LaunchDarklyFeature flag management and A/B testingUnited StatesFeature usage data, user identifiers, application metricsLegitimate InterestSOC 2 Type II certified. Data retention: 30 days
PipedriveCustomer relationship managementEstonia (EU)Customer contact data, sales informationContract PerformanceISO 27001, GDPR compliant. EU-based data processing
PostmarkTransactional email deliveryUnited StatesEmail addresses, email content, delivery metricsContract PerformanceSOC 2 Type II certified. GDPR compliant email processing
SentryApplication performance monitoring and error trackingUnited StatesError logs, performance data, user identifiersLegitimate InterestSOC 2 Type II certified. Data retention: 90 days
ShortcutProject management and issue trackingUnited StatesProject data, task information, user identifiersContract PerformanceSOC 2 Type II certified. Data retention: As configured
StripePayment processing servicesUnited States/GlobalPayment data, billing information, transaction recordsContract PerformancePCI DSS Level 1, SOC 1/2 certified. Strong encryption and security
XeroAccounting and financial managementNew Zealand/GlobalFinancial data, invoicing information, business recordsContract PerformanceSOC 2 Type II, ISO 27001 certified. Multiple data center locations

Data Protection Safeguards

All sub-processors are required to implement appropriate technical and organisational measures to ensure the security of personal data, including:

  • Encryption in transit and at rest for all personal data
  • Access controls limiting data access to authorised personnel only
  • Regular security assessments and compliance audits
  • Incident response procedures for data breaches or security events
  • Data retention policies aligned with business and legal requirements
  • Staff training on data protection and security practices

Data Subject Rights

Data subjects maintain all rights under applicable data protection laws when their data is processed by our sub-processors, including:

  • Right of access to personal data
  • Right to rectification of inaccurate data
  • Right to erasure (right to be forgotten)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing

Updates and Changes

This list is updated regularly to reflect changes in our sub-processor relationships. Any new sub-processors will be added to this list with appropriate notice to customers as required by our DPA.

Last updated: 5 July, 2025

Contact Information

For questions about our sub-processors or data processing practices, please contact us:

  • Email: privacy@colloquial.io
  • Address: Colloquial Solutions Pty Ltd, Australia
  • Data Protection Officer: privacy@colloquial.io

Compliance and Certifications

Colloquial maintains the following certifications and compliance frameworks:

  • ISO 27001:2013 Information Security Management
  • GDPR Compliance European data protection regulation

For more information about our data processing practices, please refer to our Privacy Policy and Data Processing Addendum.