Graphly Subprocessors
Last Updated: June 2026
Graphly uses carefully selected third-party service providers (“Subprocessors”) to help deliver, secure, maintain, and support our services.
A Subprocessor is a third-party organization engaged by Graphly that may process Customer Personal Data while providing services on Graphly’s behalf.
Graphly conducts reasonable due diligence when selecting subprocessors and requires subprocessors to maintain appropriate privacy, security, and confidentiality protections consistent with applicable data protection laws and Graphly’s contractual obligations.
This page identifies the subprocessors currently authorized to process Customer Personal Data in connection with Graphly services.
Current Subprocessors
| Subprocessor | Purpose |
|---|---|
| Laravel Cloud | Cloud hosting and infrastructure services |
| Amazon Web Services (AWS) | Database, storage and backups |
| Bugsnag | Application error monitoring and diagnostics (error reports may include user identifiers, IP addresses, and request metadata) |
| Cloudflare | Content delivery, TLS, and web application firewall for the service’s edge network (engaged via Laravel Cloud) |
| Mailgun (Sinch) | Transactional email delivery (password resets and service notifications) |
| Pusher | Real-time dashboard update notifications (event signals only; minimal personal data) |
| Google Workspace | Business communications and document management |
| Crisp | Customer support and communications |
| Authorize.net | Payment processing and billing services |
Keap (Thrive) is not a Graphly subprocessor — it is the customer’s own CRM and system of record, which Graphly accesses solely under the customer’s OAuth authorization. Optional customer-connected integrations (e.g., FixYourFunnel) are likewise customer-directed data sources, not subprocessors.
Subprocessor Updates
Graphly may add, remove, or replace subprocessors from time to time as business needs evolve.
Where required by applicable law or contractual commitments, Graphly will provide notice of material subprocessor changes and allow customers an opportunity to raise reasonable objections.
Data Protection
Graphly enters into appropriate contractual agreements with subprocessors that require them to:
- Process personal data only for authorized purposes
- Maintain appropriate security measures
- Protect the confidentiality of personal data
- Comply with applicable privacy and data protection laws
- Assist Graphly in meeting its obligations under applicable data protection regulations where required
Questions
If you have questions regarding Graphly’s subprocessors or data processing practices, please contact:
Dustin Lunt
Data Protection Officer
dustin@graphly.io
For additional information regarding Graphly’s privacy and compliance practices, please review our Privacy Policy, Data Processing Addendum (DPA), and GDPR information pages.