Subprocessors
Last updated: September 4, 2026
This page is the current, named list of vendors IT Partners Plus LLC uses to operate Current. It is referenced by our Privacy Policy, our Terms of Service, and our Data Processing Addendum, and your agreement to those documents is your authorization for the vendors listed here.
Subprocessors that may process Customer Data
Each of these is bound by a written agreement with data-protection terms, processes data only on our instructions, and is subject to the security commitments in our DPA.
| Vendor | What it does | What it processes | Where |
|---|---|---|---|
| Supabase, Inc. | Application database, authentication, file storage, and serverless functions | All Customer Data | United States |
| Microsoft Corporation (Azure) | Underlying cloud infrastructure — the database and the application front end both run on Azure | All Customer Data | United States |
| Anthropic PBC | AI features — briefs, drafts, summaries, risk analysis, and dashboard generation. Training on our data is disabled by contract | Only the workspace records relevant to the AI feature you invoke | United States |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact, seat counts, payment method (tokenized). No workspace records | United States |
| Resend (Plus Five Five, Inc.) | Transactional and system email — invitations, one-time codes, digests, notifications | Recipient name and email address, message content | United States |
| Cloudflare, Inc. | Bot protection (Turnstile) on public lead-capture forms, booking pages, and the Help Center question box | Visitor IP address and challenge token at the moment of submission | United States and global edge network |
| Microsoft Corporation (Microsoft Graph) | Only where you connect Microsoft 365 — Teams, SharePoint, Outlook calendar, To Do, and optional mailbox capture | The Microsoft 365 data your administrator's delegated permissions allow | Your own Microsoft 365 tenant region |
Website and advertising vendors
These vendors run on our public website and, for analytics, inside the app. They never receive Customer Data — no workspace records, no client data, no contracts, no financials. We are the controller for the visitor data they process, and in the EEA and UK nothing loads until a visitor accepts on the cookie banner.
| Vendor | What it does | What it processes | Where |
|---|---|---|---|
| Google LLC (Analytics 4) | Website and product usage analytics. Consent-gated in the EEA and UK — nothing is set until a visitor accepts | Visitor IP address, device and browser, pages viewed, conversion events | United States |
| Google LLC (Fonts) | Serving the brand typefaces our pages use | Visitor IP address at the moment fonts are requested | United States and global edge network |
| Reddit, Inc. | Advertising conversion measurement for our paid campaigns. Consent-gated in the EEA and UK — the pixel does not load until a visitor accepts | Visitor identifiers and conversion events (sign-up, demo booking, trial start) | United States |
Not subprocessors — integrations you connect
When you connect your own PSA, RMM, or prospecting tool, that vendor is not our subprocessor. You hold the account, you supply the credentials, and your relationship with that vendor is governed by your contract with them. Current exchanges data with the service under your instruction and only as needed for the feature. This covers, among others:
- Your PSA — Autotask, ConnectWise, or HaloPSA, using the API credentials you provide;
- HubSpot — two-way synchronization, through the connection you authorize;
- Seamless.ai — prospecting and contact enrichment, using your own Seamless.ai account and API key. We hold no Seamless.ai account on your behalf and never send your data through ours;
- NeverBounce — email verification, using your own key;
- Handwrytten — physical direct mail, using your own account;
- ScalePad Quoter and Lifecycle Manager, ConnectWise CPQ, CrewHu; and
- View-only reporting feeds — ConnectWise RMM, Datto RMM, NinjaOne, Datto Backup, Backup Radar, Datto EDR, Auvik, RocketCyber, Addigy, and Inky.
Where an integration brings personal data into your workspace — prospecting records especially — you are the controller for that data and you are responsible for having a lawful basis and for giving whatever notices the law requires.
Notice of changes
Before we add a new subprocessor that can process Customer Data, or replace an existing one, we will give at least 30 days’ notice by updating this page and emailing workspace administrators. If you have a reasonable data-protection objection to a new subprocessor, tell us within those 30 days and we will work with you to find a resolution; if we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused term.
We may add a replacement subprocessor with shorter notice where it is needed to keep the Service secure or available — for example, an emergency infrastructure failover. We will tell you as soon as we reasonably can, and the objection right above still applies.
Questions
To subscribe to subprocessor notices, raise an objection, or ask what a vendor does, email privacy@current.day.