Skip to main content
Last Updated: October 22, 2025 This page lists the third-party sub-processors that DryMerge, Inc. (“DryMerge”) uses to process customer data in connection with providing our Services. This list is maintained in accordance with our Data Processing Agreement.

Notification of Changes

DryMerge will provide at least 30 days’ prior notice of the addition or replacement of any sub-processor by updating this page and sending an email notification to your account email address. You may subscribe to notifications by contacting privacy@drymerge.com.

Infrastructure and Hosting Sub-processors

Sub-processorPurposeData ProcessedLocationPrivacy/DPA Link
Amazon Web Services (AWS)Cloud infrastructure, data storage, and hostingAll customer data including personal information, workflow data, and integrationsUnited StatesAWS DPA

AI and Machine Learning Sub-processors

Sub-processorPurposeData ProcessedLocationPrivacy/DPA Link
OpenAIAI model inference for chatbot responses (only when explicitly enabled by customer)Message text, automation context (when AI features are enabled)United StatesOpenAI Privacy Policy
AnthropicAI model inference for chatbot responses (only when explicitly enabled by customer)Message text, automation context (when AI features are enabled)United StatesAnthropic Privacy Policy
Important Note on AI Processing:
  • AI processing is opt-in only and requires explicit customer consent through an AI checkbox when creating automations
  • OpenAI and Anthropic do not store customer data or use it to train their models
  • Only the minimum necessary data is shared for inference purposes
  • All processing is done in real-time without long-term storage

Analytics and Monitoring Sub-processors

Sub-processorPurposeData ProcessedLocationPrivacy/DPA Link
PostHogProduct analytics and feature usage trackingUser behavior data, anonymized usage metrics, feature flagsUnited States / EUPostHog DPA
Google AnalyticsWebsite analyticsPage views, user interactions, anonymized browsing dataUnited StatesGoogle Analytics DPA

Payment Processing Sub-processors

Sub-processorPurposeData ProcessedLocationPrivacy/DPA Link
StripePayment processing and subscription managementPayment information, billing details, transaction dataUnited StatesStripe DPA

Communication Sub-processors

Sub-processorPurposeData ProcessedLocationPrivacy/DPA Link
SendGrid (Twilio)Transactional email deliveryEmail addresses, email content, delivery metadataUnited StatesTwilio DPA
SlackInternal team communications and supportSupport ticket content, customer inquiriesUnited StatesSlack DPA

Integration Platform Sub-processors

DryMerge connects to various third-party platforms on behalf of customers. When a customer authorizes an integration, data may be processed by:
Integration CategoryExamplesData ProcessedNote
CRM SystemsHubSpot, Salesforce, Attio, PipedriveContact data, company data, deal information, activity logsCustomer-controlled via OAuth
Communication ToolsGmail, Outlook, Slack, Microsoft TeamsEmail content, messages, calendar events, contactsCustomer-controlled via OAuth
Productivity AppsGoogle Workspace, Microsoft 365, Notion, AirtableDocuments, spreadsheets, databases, project dataCustomer-controlled via OAuth
E-commerce PlatformsShopify, WooCommerce, StripeOrder data, customer information, product catalogsCustomer-controlled via OAuth
Marketing ToolsMailchimp, ActiveCampaign, IntercomContact lists, campaign data, subscriber informationCustomer-controlled via OAuth
Important: These integrations are established directly by customers through OAuth authorization. DryMerge acts as a conduit to facilitate data synchronization as instructed by the customer. Each integration platform has its own privacy policy and DPA, which customers should review.

Data Transfer Mechanisms

For sub-processors located outside the European Economic Area (EEA), DryMerge ensures adequate data protection through:
  • Standard Contractual Clauses (SCCs): Approved by the European Commission for international data transfers
  • Adequacy Decisions: Relying on adequacy decisions where applicable
  • Supplementary Measures: Including encryption, access controls, and contractual commitments

Sub-processor Security Requirements

All sub-processors are required to:
  • Implement appropriate technical and organizational security measures
  • Process data only in accordance with documented instructions
  • Ensure confidentiality of personnel with access to personal data
  • Assist with data subject rights requests and security incidents
  • Delete or return data upon termination of services
  • Submit to audits and provide compliance documentation

Objecting to a Sub-processor

If you object to DryMerge’s use of a new sub-processor, you may:
  1. Notify us in writing at privacy@drymerge.com within 10 business days of receiving notice
  2. Provide specific reasons for your objection based on legitimate data protection concerns
  3. Work with us to identify alternative solutions
We will use reasonable efforts to accommodate valid objections, including making available changes in the Services or recommending configuration adjustments.

Additional Information

For questions about our sub-processors or to request additional information about data processing practices, please contact: DryMerge, Inc.
Data Protection Officer
Email: privacy@drymerge.com
For a copy of our Data Processing Agreement, visit: /legal-policies/data-processing-agreement/page
Note: This list is current as of the last updated date shown above. DryMerge reserves the right to add or change sub-processors with appropriate notice as outlined in our Data Processing Agreement.
I