Subprocessors
The third parties that process customer data to run Waltz, what each one receives, and where.
Draft · Last updated
Draft for counsel's review. Not yet in effect.
1. What this list is
A subprocessor is a company Waltz engages that processes customer personal data to run the Service. This page lists them, as the Data Processing Addendum requires. We give at least [30] days' notice before adding one.
The list matches the deployment Waltz runs today: one environment, hosted in the United States.
2. Current subprocessors
| Subprocessor | Purpose | Data it processes | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting: compute (EC2) for the API, ingest, worker and the analysis runner; the database (RDS PostgreSQL); object storage (S3) for Briefs and analysis bundles; key management (KMS); secrets (Systems Manager); logs (CloudWatch) | All customer data the Service stores: facts, snapshots, Briefs, reviews, org chart, recipient lists, encrypted integration credentials. Source code only transiently, in the runner's memory, during analysis | United States (us-east-1) |
| Amazon Web Services, Inc. (Amazon SES) | Sending email: sign-in links, invitations and Brief emails | Recipient email addresses; email content (the Brief's headline, key points and a signed link) | United States (us-east-1) |
| Anthropic, PBC | Hosted language model that phrases Brief text | Facts (people appear only as hashed identities); pull request and commit titles and messages; ticket text; document excerpts; short code excerpts (40 lines or fewer) | United States |
| Stripe, Inc. | Subscription billing, checkout, invoices and the billing portal | Billing contact name and email, company name and address, tax ids, seat quantities. Card details go to Stripe directly and never reach Waltz | United States [and Stripe's other processing locations] |
| Vercel Inc. | Hosting the waltz.run website and the console's pages | IP addresses and request metadata of visitors and members. The console's data passes from the browser to api.waltz.run directly, not through Vercel | [Global edge network; functions in the United States] |
| Cloudflare, Inc. | DNS for waltz.run; receiving and forwarding mail sent to waltz.run addresses (Email Routing) | DNS queries. Email sent to Waltz's addresses, including replies to Brief emails, which may contain personal data | [Global network] |
| [Mailbox provider of the forwarding destination] | The mailbox where Waltz's team reads mail sent to its addresses | Email sent to support@, security@ and Waltz's other addresses, and replies to Brief emails | [Location] |
[Counsel and operations to confirm each entity name, the data processing terms in place with each, and the transfer mechanism. Cloudflare is DNS-only for Waltz's hosts: it does not proxy web or API traffic.]
3. Not subprocessors
Integrations you connect. GitHub, GitLab, Jira, Linear, Slack, AI agent vendors and the other systems in Waltz's integration catalog belong to you. You choose to connect them and you control the data that flows between them and Waltz. They act for you, not for Waltz. When Waltz delivers a Brief to Slack, for example, it sends the Brief's headline, key points and link to your workspace.
Your own model provider. On Enterprise, if you connect your own model provider and key, that provider processes data under your agreement with it.
Public data services. To report end-of-life runtimes, known vulnerabilities and deprecated packages, Waltz queries public services, including endoflife.date, OSV.dev, deps.dev, the GitHub Advisory Database and OpenSSF Scorecard. Waltz sends them only the names and versions of open-source dependencies and runtimes, never personal data, code or Brief content.
4. Possible future subprocessors
These are part of Waltz's design but not in use. Each will be added to this list, with notice, before it processes customer data:
- a single sign-on and directory provider for Enterprise SSO and SCIM (for example WorkOS);
- a unified API vendor for HRIS and file-storage integrations, used only for an org that opts in.
An authentication proxy for long-tail integrations, if used, would be self-hosted by Waltz and so would not be a subprocessor.
5. Changes
[To be told about changes, subscribe at [link] / org owners are notified by email.] Past versions of this list are kept at [link].