---
title: "Sub-processors"
canonical: "https://help.releasemanagement.app/space/TRUSTRM/2615869496/Sub-processors"
format: markdown
---
![Y2_Logo_WhiteBG.png](media://1cbee3dc-098f-4aa3-94a7-f2b35b64b5c4)

# History

> Macro (change-history)

# Topics

> Macro (toc)

---

# Release Management Sub-processors

Release Management uses the third party entities below (each, a “sub-processor”) to process personal data on behalf of Release Management Customers and in accordance with contract terms between Release Management and the sub-processor to uphold Release Management’s commitments in Release Management's [Data Processing Addendum (DPA)](https://releasemanagement.atlassian.net/wiki/spaces/TRUSTRM/pages/2615869441).

Release Management carries out an internal onboarding due diligence and annual compliance reviews of its sub-processors and imposes obligations on its sub-processors to implement appropriate technical and organizational measures ensuring that the sub-processing of personal data is protected to the standards required by applicable data protection laws (according Release Management Information Security, Data Management, Third Party Management and Risk Management Policies).

Further information relating to sub-processor security measures can be found via the external links below. For each sub-processor below, processing of personal data will be for the duration of use of the applicable service(s) by the customer, and for the retention periods as set out in the customer’s agreement with Release Management and any product documentation.

We recommend you become a Watcher for this Confluence page to receive updates on any changes to sub-processors list. The process of changes to the sub-processors list is outlined in Section [2.10](https://releasemanagement.atlassian.net/wiki/spaces/TRUSTRM/pages/2615869441/Data+Processing+Addendum+DPA#Changes-to-Sub-processors) of DPA.

| **Sub-processor** | **Applicable Release Management Products** | **Nature and Purpose of Processing** | **Categories of personal data** | **Location of Processing** | **Security and Supplemental Measures** |
| --- | --- | --- | --- | --- | --- |
| ## Google Analytics / Google Tag Manager (Google, Inc.) | **All **Cloud and DC Products | Analytics service used to improve content of our Apps listing pages on [Atlassian Marketplace](https://marketplace.atlassian.com/vendors/1216961) and our own [Website](https://www.releasemanagement.app/). | *Device and connection information, for example:*<br>- IP address
- Cookie information
- Device information
- Browser information<br>*Information on the use of the Pages, for example:*<br>- Event Name (i.e., what action the user performed)
- Event Timestamp
- Page URL
- Referring URL
- Atlassian User ID | Globally | <u>[Data Processing Terms](https://business.safety.google/adsprocessorterms/)</u><br>[https://policies.google.com/privacy?hl=en-US](https://policies.google.com/privacy?hl=en-US) |
| ## Google Calendar, Google Meet (Google, Inc.) | **All **Cloud and DC Products | Online Calendar and default video conferencing solution we use to schedule, handle and follow up meetings requested by Customer End Users. Also used to automatically create appointments from Calendly (see above)** ** | same as above | Globally | <u>[Data Processing Terms](https://business.safety.google/adsprocessorterms/)</u><br>[https://policies.google.com/privacy?hl=en-US](https://policies.google.com/privacy?hl=en-US) |
| ## Atlassian Marketplace (Atlassian Pty Ltd) | **All **Cloud and DC Products | The Atlassian Marketplace is an online marketplace for Cloud and DC applications that are designed to interoperate with Atlassian’s software and cloud offerings, Release Management Products in particular. | *Technical and Billing Contacts Information, for example:*<br>- Full name
- Email address
- Office / address
- Office / phone number
- Company / organization
- Company web-site URL<br>*Customers' Atlassian Solution Partner, for example:*<br>- Full name
- Email address
- Company / organization
- Company web-site URL<br>*Additional Release Management/Atlassian Product license information, for example:*<br>- App entitlement id and number
- Host entitlement id and number
- Host product edition and frequency of renewals
- License type and status
- License start and end dates
- License tier | US | [https://www.atlassian.com/legal/data-processing-addendum](https://www.atlassian.com/legal/data-processing-addendum)<br>[https://www.atlassian.com/legal/privacy-policy#what-this-policy-covers](https://www.atlassian.com/legal/privacy-policy#what-this-policy-covers) |
| ## Brevo (Sendinblue SAS) | **All **Cloud Products | Email marketing, automation, and CRM used to send updates (including security updates), information about our products, changes in offering and other marketing we deem interesting to your company (our Customers). | same as above | US | [DPA & Privacy Policy](https://www.brevo.com/legal/termsofuse/#annex) |
| ## Slack (Slack Technologies, LLC or Slack Technologies Limited) | **All **Cloud and DC Products | A number of private channels for Release Management owned workspace to instantly update Release Management representatives on key changes in Customers’ licensing | *Technical Contacts Information, for example:*<br>- Full name
- Company / organization
- Company web-site URL<br>*Additional Release Management/Atlassian Product license information, for example:*<br>- App entitlement id and number
- Host product edition and frequency of renewals
- License type and status
- License start and end dates
- License tier | US | [https://slack.com/intl/en-gb/terms-of-service/data-processing](https://slack.com/intl/en-gb/terms-of-service/data-processing)<br>[https://slack.com/intl/en-gb/trust/privacy/privacy-policy](https://slack.com/intl/en-gb/trust/privacy/privacy-policy) |
| ## Amplitude (Amplitude, Inc.) | **All **Cloud and DC Products | Product analytics service used to improve the customer experience and functionality of the App. | *Information on the use of our Products, for example:*<br>- Event Name (i.e., what action the user performed)
- Event Timestamp
- Page URL
- Referring URL
- Atlassian User ID<br>*Additional Release Management/Atlassian Product license information, for example:*<br>- App entitlement id and number
- Host entitlement id and number
- Host product edition and frequency of renewals
- License type and status
- License start and end dates
- License tier | US | [https://amplitude.com/dpa](https://amplitude.com/dpa)<br>[https://amplitude.com/privacy](https://amplitude.com/privacy) |
| ## journy.io | **All **Cloud and DC Products | The SaaS Growth Platform, empowering SMBs to be Data-Driven & Product-Led, in particular helping us to orchestrate Customer journey with us. | same as above | EU | [https://www.journy.io/legal/data-processing](https://www.journy.io/legal/data-processing)<br>[https://www.journy.io/legal/privacy-policy](https://www.journy.io/legal/privacy-policy) |
| ## AWS (Amazon Web Services, Inc.) | **Cloud **Products Only | Hosting provider for our Cloud Applications distributed and scalable clusters. | Personal data defined in App specific tables of [Exhibit A, Part A](https://releasemanagement.atlassian.net/wiki/spaces/TRUSTRM/pages/2615869441/Data+Processing+Addendum+DPA#Part-A:-Description-of-processing-and-transfer-(as-applicable)-for-Modules-2-and-3-of-the-Standard-Contractual-Clauses-(reference-to-Sections-2.2(a)-as-well-as-2.6(a)-DPA)) of DPA. | AWS Region “US East (N. Virginia)” (us-east-1) | [https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html](https://docs.aws.amazon.com/whitepapers/latest/navigating-gdpr-compliance/aws-data-processing-addendum-dpa.html)<br>[https://aws.amazon.com/privacy/](https://aws.amazon.com/privacy/) |
| ## Atlas Mongo (MongoDB, Inc) | **Cloud **Products Only | DB Cluster & Storage of our Cloud Applications backups. | Personal data defined in App specific tables of [Exhibit A, Part A](https://releasemanagement.atlassian.net/wiki/spaces/TRUSTRM/pages/2615869441/Data+Processing+Addendum+DPA#Part-A:-Description-of-processing-and-transfer-(as-applicable)-for-Modules-2-and-3-of-the-Standard-Contractual-Clauses-(reference-to-Sections-2.2(a)-as-well-as-2.6(a)-DPA)) of DPA. | AWS Region “US East (N. Virginia)” (us-east-1)<br>AWS Region “Europe (Frankfurt)” (eu-central-1) | [https://www.mongodb.com/legal/data-processing-agreement](https://www.mongodb.com/legal/data-processing-agreement)<br>[https://www.mongodb.com/legal/privacy/privacy-policy](https://www.mongodb.com/legal/privacy/privacy-policy) |
| ## Cloudflare (Cloudflare, Inc.) | **Cloud **Products Only | Our primary DNS and CDN provider | Our primary DNS and CDN provider plus additional services, namely:<br>- Web requests caching layer
- Web Apps security and endpoints DDoS protection | The Cloudflare global network runs every service in **every data center** so your users have a consistent experience everywhere — whether they are in Chicago or Cape Town. This means all customer traffic is processed at the data center closest to its source, with no backhauling or performance tradeoffs. | [https://www.cloudflare.com/en-gb/cloudflare-customer-dpa/](https://www.cloudflare.com/en-gb/cloudflare-customer-dpa/)<br>[https://www.cloudflare.com/en-gb/privacypolicy/](https://www.cloudflare.com/en-gb/privacypolicy/) |
| ## Grafana Labs (Raintank, Inc.) | **Cloud **Products Only | Log management and analysis used to proactively monitor our Cloud Apps health and fix issues. | Log information of End user actions with our Cloud Apps, for example:<br>- Anonymized user ID
- App configuration excluding any data that may potentially be deemed personal data | US | [https://grafana.com/legal/data-processing-agreement/](https://grafana.com/legal/data-processing-agreement/)<br>[https://grafana.com/legal/privacy-policy/](https://grafana.com/legal/privacy-policy/) |

> Macro (include)