Subprocessors
To operate DODD Agency Pro, we rely on a small number of trusted third-party service providers (subprocessors). This page lists who they are, what they do, and exactly what client information each one does — and does not — receive.
Last updated: August 12, 2026
This page describes providers and data paths that are visible in the current application code and configuration. It does not claim that a particular contract, BAA, certification, or regional hosting commitment is in place unless an executed agreement says so.
The Client Compliance Tracking encrypts client names with AES-256-GCM before storage. Its bounded service and service-span fields are not field-encrypted. Other enabled client-related modules have separate data models and may rely on tenant and role-based access controls instead.
AI-facing routes and the email queue include detectors intended to block likely client-identifying content before it is sent. Those controls reduce risk but are not described here as a guarantee that no sensitive content can ever reach a provider.
| Subprocessor | Purpose | Region | Client information received |
|---|---|---|---|
DigitalOcean | Production cloud hosting and database infrastructure | Not asserted here | Hosts the application and database records. Client Compliance Tracking names use application-level AES-256-GCM encryption; other records may rely on infrastructure and access controls rather than field-level encryption. |
Resend | Transactional and notification email delivery | Not asserted here | Receives account, contact-form, and notification content sent through the email pipeline. The pipeline scans outgoing content for likely client-identifying information before enqueueing it. |
OpenAI | AI-assisted compliance features and knowledge-base embeddings | Not asserted here | Receives user prompts, retrieved compliance context, and text submitted to the embedding pipeline. Chat and form-generation routes scan prompts for likely client-identifying information before model calls. The application does not use OpenAI for client-record storage. |
Stripe | Subscription checkout, billing, and payment lifecycle events | Not asserted here | Receives billing and subscription information used for checkout and account billing. Client operational records are not part of the Stripe integration. |
Provider exposure depends on the integration described above. Application-level encryption applies only to fields specifically identified as encrypted; it is not a claim that every database field or backup is encrypted by the application.
Agencies may request a copy of our Business Associate Agreement (BAA) and additional detail about any subprocessor listed here — including the categories of data involved and the safeguards in place. We will provide this information to support your own compliance and vendor due-diligence obligations.
To make a request, contact the Privacy and security contact at support@doddagencypro.com, or reach us through our contact page. Please do not include any client or individual information in your request.
We may update this list as our services evolve. When a subprocessor that handles protected information is added or changed, this page will be revised and the "Last updated" date above will reflect the change.