Private beta · Request a scoped Agent Firewall evaluation

Legal

Subprocessor Register

Effective 12 July 2026

Legal center · Download DOCX

This register identifies categories of service providers that may process Customer Personal Data for the hosted Service. A row marked "conditional" is used only if the relevant feature is configured. The production owner must update status, processing region, and effective date before enabling a provider.

Provider or categoryPurposeData categoriesRegionStatus
RailwayHosted API, PostgreSQL, Redis, private service networkingAccount, workspace, encrypted credentials, audit and usage metadataUnited States region selected for current serviceActive
Vercel or equivalent frontend hostWebsite and dashboard deliveryBrowser requests, static assets, optional account-session trafficTo be confirmed before production frontend cutoverConditional
StripeGlobal payment processingBilling contact and payment transaction referencesProvider-configuredConditional
RazorpayIndia payment processingBilling contact and payment transaction referencesIndia / provider-configuredConditional
Transactional email providerAccount verification, alerts, invoices, support emailEmail address, name, workspace and event metadataTo be selectedConditional
GoogleOptional OAuth sign-inOAuth identifier, email, profile data authorised by userProvider-configuredConditional
GitHubOptional App, OAuth, Copilot governance, and source-control integrationsInstallation, organisation, repository, user and authorised audit metadataProvider-configuredConditional
Sentry or equivalentError monitoring and diagnosticsPseudonymous technical diagnostics; configured PII scrubbing requiredTo be selectedConditional
Crisp or equivalentOptional support chatVisitor messages and contact informationTo be selected; consent requiredConditional
Customer-selected AI, cloud, or identity providerProvider routing and Customer-authorised discoveryData directed by Customer, including prompts only when Customer routes themCustomer/provider selectedCustomer-directed

Change Process

RakshEx will provide at least 30 days' notice before adding or replacing a material subprocessor that processes Customer Personal Data, except where an urgent security or legal need requires a shorter period. Enterprise Customers may object under the DPA. Contact privacy@rakshex.in for the current register or a completed vendor questionnaire.

Customer-Directed Providers

When Customer connects a provider, Customer controls the account relationship, scopes, and data sent to that provider. Those providers are not RakshEx subprocessors when they independently process data under Customer's direct agreement and instructions.