Compliance and GDPR
Sub-processor
A sub-processor is a third party that a service provider uses to help process personal data on behalf of the provider's customer.
Why it matters
Most tools rely on other services behind the scenes, such as hosting or email infrastructure, and each of those may touch your data. Knowing who they are matters because your compliance extends to them. A provider that hides its sub-processors, or uses ones in places you cannot accept, is a risk to the lawful handling of your data.
How it works in practice
Under the GDPR, a processor may only use a sub-processor with the customer’s authorization, and must pass the same data-protection duties down to it by contract. Providers usually publish a list of their sub-processors, what each does, and where it operates, and give notice before adding a new one so customers can review or object.
Common mistakes
A common mistake is never checking a provider’s sub-processor list, so you do not know who actually holds your data. Another is overlooking where those sub-processors operate, which affects cross-border transfer rules. A third is missing notices of new sub-processors and losing the chance to object.
How hubsell approaches it
hubsell is transparent about the services behind the platform and keeps data handling within the EU, so the sub-processing behind your outreach is clear rather than hidden.