Compliance and GDPR

Sub-processor

A sub-processor is a third party that a service provider uses to help process personal data on behalf of the provider's customer.

Why it matters

Most tools rely on other services behind the scenes, such as hosting or email infrastructure, and each of those may touch your data. Knowing who they are matters because your compliance extends to them. A provider that hides its sub-processors, or uses ones in places you cannot accept, is a risk to the lawful handling of your data.

How it works in practice

Under the GDPR, a processor may only use a sub-processor with the customer’s authorization, and must pass the same data-protection duties down to it by contract. Providers usually publish a list of their sub-processors, what each does, and where it operates, and give notice before adding a new one so customers can review or object.

Common mistakes

A common mistake is never checking a provider’s sub-processor list, so you do not know who actually holds your data. Another is overlooking where those sub-processors operate, which affects cross-border transfer rules. A third is missing notices of new sub-processors and losing the chance to object.

How hubsell approaches it

hubsell is transparent about the services behind the platform and keeps data handling within the EU, so the sub-processing behind your outreach is clear rather than hidden.

← Back to glossary

See it on live data

Book a demo and we will show you hubsell working on data that is correct today.

Book a demo