Habeo
Product
ComparePricingPartnersBlogPress
Sign inSign upBook a demo
Legal · Subprocessors

Every vendor in the data path, named in full.

The complete list of third parties that process personal data on Habeo's behalf — what each one does, what data it sees, where it runs, and the certifications it holds.

Effective May 1, 2026Last updated May 17, 2026Version 2026.05
On this page
  1. Overview
  2. Core infrastructure subprocessors
  3. Product-service subprocessors
  4. Operations & observability subprocessors
  5. Notification policy
  6. Subprocessor due diligence
  7. Previously used subprocessors
  8. Questions about a subprocessor

Section 01Overview

A “subprocessor” is a third party that Habeo engages to process personal data on behalf of our customer institutions in order to provide the Services. We publish the complete list here so that every Habeo customer, prospect, and privacy office sees exactly the same picture.

This page is updated whenever we add, remove, or replace a subprocessor. Customers are notified at least 30 daysbefore a change takes effect — see Notification policy below.

i
Affiliates. Habeo does not currently have any affiliates or group entities that process Customer Data. If that changes, the affiliate will be added to this page and notified using the standard 30-day window.

Section 02Core infrastructure subprocessors

The platform itself runs on these.

SubprocessorPurposeData processedLocationCertifications
Amazon Web Services
Amazon Web Services, Inc.
Primary cloud infrastructure — compute, storage, networking, KMSAll Customer Data at rest and in transit; backupsUnited States (us-east-2, us-west-2)SOC 2 Type II · ISO 27001 · ISO 27017 · ISO 27018 · FedRAMP High
Vercel
Vercel Inc.
Web frontend and edge runtime hostingAuthentication cookies; cached non-personal page fragmentsUnited States (iad1, sfo1)SOC 2 Type II · ISO 27001 · HIPAA
Neon
Neon Inc.
Managed PostgreSQL for application dataAll Customer Data recordsUnited States (AWS us-east-2)SOC 2 Type II · ISO 27001 · HIPAA
Upstash
Upstash Inc.
Managed Redis for caching and rate limitingSession identifiers; rate-limit countersUnited States (AWS us-east-1)SOC 2 Type II
Cloudflare
Cloudflare, Inc.
DNS, WAF, DDoS protection, edge image optimizationIP addresses; HTTP request metadataGlobal edge; no persistent Customer Data storageSOC 2 Type II · ISO 27001 · ISO 27018 · FedRAMP Moderate

Section 03Product-service subprocessors

Specific in-product features depend on these.

SubprocessorPurposeData processedLocationCertifications
Clerk
Clerk Inc.
Identity, SAML/OIDC SSO, SCIM provisioningAuthorized User authentication identifiers and session dataUnited States (AWS us-east-2)SOC 2 Type II · HIPAA · GDPR
Stripe
Stripe, Inc. / Stripe Payments Europe Ltd.
Subscription billing and payment processingBilling contact data; payment instrument tokens (no full card data on Habeo systems)United States and (for EU customers) IrelandPCI DSS Level 1 · SOC 2 Type II · ISO 27001
Resend
Resend Inc.
Transactional email delivery (account, security, notifications)Recipient email; message contentUnited States (AWS us-east-1)SOC 2 Type II
Anthropic
Anthropic, PBC
LLM inference for the in-product Habeo Copilot assistantPrompts derived from the requesting user's tenant only; zero-retention enterprise tierUnited StatesSOC 2 Type II · ISO 27001 · ISO 42001 · HIPAA

Section 04Operations & observability subprocessors

These help us run the platform but never store Customer Data records.

SubprocessorPurposeData processedLocationCertifications
PostHog
PostHog, Inc.
First-party product analyticsAuthenticated user identifier; feature usage events; IP truncated to /24United States (self-hosted in Habeo AWS account)SOC 2 Type II (PostHog Cloud); Habeo self-hosts the EU OSS build
Sentry
Functional Software, Inc. dba Sentry
Application error and performance monitoringStack traces; HTTP request metadata; scrubbed user identifiersUnited StatesSOC 2 Type II · ISO 27001 · HIPAA
Datadog
Datadog, Inc.
Infrastructure monitoring and log aggregationService logs; metadata; scrubbed PIIUnited States (us5.datadoghq.com)SOC 2 Type II · ISO 27001 · HIPAA · FedRAMP Moderate
Linear
Linear Orbit, Inc.
Internal issue tracking — for support escalations referencing CustomerCustomer name; redacted ticket content; no Customer Data recordsUnited StatesSOC 2 Type II · ISO 27001
Slack
Slack Technologies, LLC
Customer-facing shared Slack Connect channels (opt-in)Messages and files Customer chooses to share in the channelUnited StatesSOC 2 Type II · ISO 27001 · ISO 27017/18 · FedRAMP Moderate

Section 05Notification policy

Habeo notifies customers of changes to this list in two ways:

  • Email.Every customer’s designated security contact receives an email at least 30 days before a new subprocessor begins processing personal data, or before an existing subprocessor is replaced.
  • RSS feed. A machine-readable feed is available at https://usehabeo.com/subprocessors/feed.xml for procurement teams that automate vendor monitoring.

Customers may object to a new subprocessor on reasonable data-protection grounds within 15 days of notice in accordance with our Data Processing Addendum.

Section 06Subprocessor due diligence

Before onboarding any subprocessor, Habeo:

  • completes a HECVAT-aligned security questionnaire and reviews the vendor’s SOC 2 or ISO 27001 report;
  • signs a data-processing agreement that imposes obligations no less protective than those in our customer DPA;
  • incorporates the EU SCCs or UK IDTA where the vendor processes personal data outside the EEA / UK;
  • verifies that the vendor’s data-residency and certification posture matches what we publish on this page.

Each subprocessor is re-assessed at least annually, and any material change (region change, certification lapse, ownership change) triggers an out-of-cycle review.

Section 07Previously used subprocessors

We list removals here for the trailing 24 months so that customers have visibility into the historical data path.

SubprocessorReplaced byEffectiveReason
MixpanelPostHog (self-hosted)2025-09-15First-party analytics; remove third-party processor
SendGridResend2025-06-01Improved deliverability; better data-residency commitments

Section 08Questions about a subprocessor

For data-protection questions about a specific subprocessor, email privacy@usehabeo.com. For security-posture questions, our security team responds at security@usehabeo.com. We can share each subprocessor’s SOC 2 or ISO 27001 report under NDA on request.

Questions about this policy?

For legal questions write to legal@usehabeo.com. Privacy requests, data-subject access, and FERPA-related inquiries go to privacy@usehabeo.com and are routed to our Data Protection Officer.

Contact legal
More legal documents
Customers & visitorsPrivacy PolicyMaster agreementTerms of ServiceGDPR · FERPAData Processing AddendumUpdated listSubprocessorsUptime & creditsService Level Agreement
Habeo

The institutional system of record for everything a university holds.

HECVAT 2024 · Published

Product

  • Copilot
  • CMDB
  • Discovery
  • Lifecycle
  • Why Habeo
  • Replace ServiceNow

Compare

  • All comparisons
  • Habeo vs ServiceNow
  • Habeo vs Asset Panda
  • Habeo vs EZOfficeInventory
  • Habeo vs Snipe-IT
  • Habeo vs Lansweeper
  • Habeo vs Freshservice

Developers

  • Developer hub
  • API overview
  • API reference
  • OpenAPI 3.1 spec
  • Webhooks
  • Quick start

Resources

  • Pricing
  • Blog
  • Technology partners
  • HECVAT response
  • Trust center
  • Book a demo

Company

  • About
  • Press
  • Contact
  • Privacy
  • Terms
  • DPA
  • Subprocessors
  • SLA
© 2026 Habeo LLC · usehabeo.com
Habeo. We hold.