Sub-processors

Sub-processors

Last reviewed: June 29, 2026

LogicLinks relies on the third parties listed below to deliver the product. Each one has a published privacy and security posture (linked from each row). We maintain Data Processing Agreements (or the equivalent under each provider's terms of service) where required. This list is reviewed annually and on every material change to the production data path; we commit to notifying customer organization admins at least 30 days before adding a sub-processor that touches their data.

Amazon Web Services

Privacy policy ↗

Hosting, database (RDS Postgres), object storage (S3), DNS (Route 53), and secrets storage (Secrets Manager, Parameter Store) — the foundation of LogicLinks's application infrastructure. AWS Bedrock is additionally used to invoke Anthropic Claude (for borrower-document analysis and a planned mortgage-guideline Q&A assistant) and Cohere embedding + rerank models (for the same Q&A retrieval pipeline). Bedrock does NOT retain prompts or completions, does NOT train models on customer content, and processes all requests in our account's region (us-east-1).

Data categories: All customer + tenant data at rest; OAuth tokens (encrypted at the application layer); Borrower PII (SSN/ITIN encrypted at the application layer; never sent to Bedrock in plaintext); Borrower documents submitted for analysis (in transit only; not retained by Bedrock); Mortgage guideline corpus + LO question text passed to Bedrock for retrieval (in transit only); Application logs (CloudWatch)
Processing region: United States (us-east-1)

Gmail and Google Workspace APIs (when an LO connects their Gmail account) and Google Cloud Platform OAuth verification. We do not store Google user data outside the Workspace APIs themselves except for the connected mailbox metadata described in our Privacy Policy.

Data categories: Connected mailbox messages, threads, labels (in transit; cached briefly for inbox rendering); OAuth refresh + access tokens (encrypted at rest); User account email + name from Google profile
Processing region: United States + global Google Cloud regions

Microsoft Corporation

Privacy policy ↗

Microsoft Graph APIs (when an LO connects their Microsoft 365 / Outlook account). Same role as Google for Outlook-connected LOs.

Data categories: Connected mailbox messages, threads, labels (in transit; cached briefly for inbox rendering); OAuth refresh + access tokens (encrypted at rest); User account email + name from Microsoft profile
Processing region: United States + global Microsoft Cloud regions

Outbound + inbound SMS, voice, and 2FA delivery for the LO's lead communications.

Data categories: Borrower phone numbers (E.164); SMS message bodies (in transit only; not retained by Twilio beyond their standard windows); LO sender identity
Processing region: United States

SendGrid (Twilio Inc.)

Privacy policy ↗

Transactional email delivery (outbound), inbound email parsing for the unified inbox.

Data categories: Recipient email addresses; Outbound email message bodies (in transit); Inbound email message bodies (passed through to our app, then stored per the retention policy)
Processing region: United States

Stripe, Inc.

Privacy policy ↗

Subscription billing and payment processing for paid LogicLinks plans.

Data categories: Org admin name, email, billing address; Last 4 digits of payment method (PCI-scoped data stays on Stripe; we never see full card numbers)
Processing region: United States

Automated Valuation Model (AVM) provider — used to estimate property values when the LO requests one from the Loan Presenter comparison tool.

Data categories: Property addresses (no borrower identity attached at the vendor)
Processing region: United States

Notification of changes

To receive email notification whenever a sub-processor is added or removed, email info@logiclinks.io with the subject line "Subscribe sub-processor updates."