Subprocessors List
Zilliz adheres to the requirements of the General Data Protection Regulation (GDPR) and the California Privacy Rights Act (CPRA) in its selection and management of subprocessors.
To ensure compliance:
Due Diligence & Risk Assessment – Zilliz conducts thorough due diligence on each subprocessor to assess their data protection practices, security controls, and compliance with applicable privacy regulations.
Data Processing Agreements (DPA) – Zilliz enters into legally binding agreements with subprocessors, requiring them to implement appropriate technical and organizational measures to protect personal data.
Data Minimization & Purpose Limitation – Personal data shared with subprocessors is strictly limited to what is necessary for the specified purposes, such as authentication, billing, customer support, and analytics.
Security & Compliance Monitoring – Zilliz continuously monitors subprocessors’ security controls and compliance status to ensure ongoing adherence to GDPR and CPRA standards.
User Rights & Data Transfers – Zilliz ensures that subprocessors support data subject rights (e.g., access, correction, deletion) and implement appropriate safeguards for cross-border data transfers.
By implementing these measures, Zilliz ensures that all subprocessors operate in accordance with GDPR and CPRA, maintaining a high level of security and privacy protection for users' personal data.
Subprocessor | Personal Data Provided | Purpose of Data Sharing | Location |
---|---|---|---|
Amazon Web Services (AWS) | Various technical and system-related data | Cloud infrastructure services, data storage, and hosting | USA and customer-selected cloud regions |
Various technical and system-related data | Cloud infrastructure, analytics, and productivity tools | USA and customer-selected cloud regions | |
Microsoft Azure | Various technical and system-related data | Cloud computing, data storage, and hosting | USA and customer-selected cloud regions |
Auth0 | Email address, password | Authentication when logging in | USA |
Snowflake & Tableau | Contact information (name, email address, country, company, billing address) | User behavior analysis, revenue data monitoring | USA |
Stripe | Payment information (email address, billing address, invoice, TAX ID) | Generating bills and processing payments | USA |
Zendesk | Contact information (name, email address) | User support services for troubleshooting product issues | USA |
HubSpot | Company name, website, phone number, contact name, email, phone number | Customer data access for profile updates, marketing prospect qualification, and sales leads validation | USA |
Vanta | Security and compliance-related data | Compliance monitoring and risk assessment | USA |