Sub-processors
A sub-processor is a third-party service that may store or process data on our behalf to deliver Tempus 7. This page lists every sub-processor we currently use, what they do for us, and what categories of data flow through them.
Last updated: 2026-08-04. We will update this page at least 14 days before adding a new sub-processor that has access to tenant data.
Current list
Amazon Web Services (AWS)
- Role: primary infrastructure — application hosting (EC2), database (Aurora PostgreSQL), file storage (S3), secrets storage (Secrets Manager), backup vaults, transactional email infrastructure (SES, see below).
- Region: us-east-1 (Northern Virginia)
- Data accessed: all tenant data — account information, business records, files, audit logs. Encrypted at rest with AWS-managed keys; encrypted in transit with TLS 1.2+.
- Why: AWS is the underlying infrastructure for the entire platform. Replacing this would mean replacing Tempus 7.
- Privacy policy: aws.amazon.com/privacy
Microsoft Corporation
- Role: transactional email delivery during beta, via Microsoft 365 and the Microsoft Graph API. Account-related emails (invitations, password resets) and in-app notifications to outside project participants are sent through this path.
- Data accessed: recipient email address, sender domain, subject line, and email body content (which may include project names, contact names, and links into the application).
- Why: Amazon SES production access for this account is currently provisioning. Once SES is fully enabled, transactional email will route through AWS and Microsoft will no longer have email-content access. We will update this page when that transition completes.
- Privacy policy: privacy.microsoft.com
GoDaddy
- Role: DNS hosting and domain registration for tempus7.com.
- Data accessed: DNS records only. No tenant data flows through GoDaddy.
- Privacy policy: godaddy.com/legal/privacy-policy
Stripe
- Role: payment processing for subscription plans (card and ACH bank transfer).
- Data accessed: billing contact name and email, organization name, payment method details (handled directly by Stripe — we never see card or bank account numbers).
- Privacy policy: stripe.com/privacy
Anthropic (AI import wizard — only when you use it)
- Role: AI mapping suggestions in the optional data-import wizard. When a tenant uploads a spreadsheet for AI-assisted import, Anthropic's Claude API suggests which sheets and columns map to Tempus 7 records.
- Data accessed: file structure only — sheet names, column headers, row counts, and up to five sample rows per sheet with emails, phone numbers, and street addresses masked before sending. Full file contents are parsed on our servers and never sent to Anthropic.
- Terms: processed under Anthropic's commercial terms — inputs and outputs are not used to train their models. TLS in transit; we log analysis metadata (counts, timing) but never the content.
- Why: loading years of spreadsheet data into a new system is the hardest part of onboarding. The wizard reads any workbook shape instead of forcing rigid templates; the free CSV-template path remains for tenants who prefer it.
- Privacy policy: anthropic.com/legal/privacy
Intuit (QuickBooks Online — only if your tenant connects it)
- Role: optional accounting integration, activated per tenant and only at that tenant's direction. Not a sub-processor in the classic sense — data flows to the tenant's own QuickBooks account, not to ours.
- Data exchanged: the accounting records the tenant chooses to sync (customers, vendors, invoices, bills, payments). Connection tokens are stored by us with application-level encryption at rest.
- Privacy policy: intuit.com/privacy/statement
What we don't use
For transparency, here's the long list of common SaaS sub-processors that we have not integrated:
- No third-party analytics (no Google Analytics, no Mixpanel, no Segment, etc.)
- No third-party advertising or marketing platforms
- No third-party error monitoring services (Sentry, Rollbar, Datadog — error data stays inside our own AWS account)
- No third-party customer-data platforms or CRM integrations
- No third-party live-chat widgets
- No third-party AI training data flows — your business data is never used to train AI models
How we choose sub-processors
We add a sub-processor only when its function cannot be self-hosted at our scale without unreasonable cost or risk (e.g., transactional email deliverability, payment processing). Each candidate is evaluated on data minimization, security posture, and contractual data-protection terms.
Questions
For sub-processor inquiries or to request notification of changes ahead of time: privacy@tempus7.com