1. About this list
To provide MaxorConnect, Maxor Global LLC engages a small set of trusted sub-processors. Each is bound by a written data-processing agreement (or equivalent) that requires appropriate security and confidentiality and permits processing only on our instructions. This page is our current public list; we keep it lean on purpose.
For Customer Data, these providers act as our sub-processors. For certain controller-side website and billing data, the same providers may process data under our instructions as controller. Customer-chosen integrations (Microsoft 365, Google Ads, etc.) are not sub-processors we impose — see §3.
2. Current sub-processors
| Sub-processor | Purpose | Typical data | Location |
|---|---|---|---|
| Vercel Inc. | Website & application hosting, edge delivery, serverless compute | Request metadata, app traffic; may process Customer Data in transit/runtime | USA (global edge) |
| Cloudflare, Inc. | CDN, DNS, DDoS and edge security (via hosting/edge path) | IP, request metadata, traffic patterns | Global / USA |
| Supabase | Managed Postgres, auth, storage for Customer Data and accounts | Customer Data, account data, files | USA / EU / Canada (regional options) |
| Resend | Transactional and contact-form email delivery | Email addresses, message content you trigger | USA |
| Plausible Analytics | Cookieless marketing-site analytics | Aggregate page metrics (no cross-site ID) | EU (Germany) |
| xAI (Grok) | Generative large-language-model processing for Heisen (underlying production model) | Prompts/context you submit to AI features; model outputs | USA |
| Stripe | Subscription billing and payment processing | Billing contact, payment method tokens, invoices | USA |
| Apollo.io | Prospecting & enrichment (only when you enable it) | Contact/company data you process via the integration | USA |
The production generative path for Heisen is Grok via xAI. xAI processes prompts and necessary context to return model outputs for features you use in the Service. We contractually restrict use of Customer Data for training third-party foundation models as described in the Privacy Policy. Anthropic and similar tools used only in Maxor's internal development workflow are not listed here because they are not engaged to process Customer Data in the live Service. Material changes to the production AI path will be reflected on this page.
3. Integrations you control
When you connect an optional integration such as Microsoft 365, Google Workspace, Google Ads, LinkedIn, or other connectors we offer, that provider processes data at your direction under your agreement with them. These are not Maxor-imposed sub-processors. You can disconnect them in product settings. Disconnecting stops new syncs; residual data already imported remains your Customer Data until you delete it.
4. Diligence & contractual controls
- Written DPA or equivalent with each sub-processor.
- Security and confidentiality obligations no less protective in substance than our commitments to you for the same data.
- Processing limited to providing the contracted service to us.
- Flow-down of deletion/return and assistance with data-subject requests where applicable.
- Transfer safeguards (e.g. SCCs) where personal data leaves the EEA/UK/Switzerland to a non-adequate country.
5. Changes & notice
We may add, replace or remove a sub-processor as the Service evolves. We will update this page when we do. Enterprise customers with a signed DPA may receive advance notice (for example 15–30 days before a new sub-processor processes Customer Data) and a right to object on reasonable data-protection grounds as set out in that DPA. To request notification of changes, email [email protected] with subject "Sub-processor notice".
6. Contact
Questions about sub-processors: [email protected]. Related documents: Privacy Policy, DPA (/legal/dpa), Terms.