Subprocessor List
Current subprocessors and service providers used by Cap Orbit.
This Subprocessor List is referenced by the Cap Orbit Data Processing Addendum (the "DPA") and the Cap Orbit Privacy Policy, and forms part of the DPA where the DPA incorporates it. Capitalized terms used but not defined here have the meanings given to them in the DPA, the Cap Orbit Terms of Service, or the Privacy Policy. In this document, "Cap Orbit", "we", "us", and "our" mean Cap Orbit, Inc., a Delaware corporation, the operator of the Service, and "Customer", "you", and "your" mean the organization that subscribes to the Service and its Authorized Users.
1. About this list
A "Subprocessor" is a third party Cap Orbit engages to process Customer Content in providing the Service.
This list identifies providers Cap Orbit uses to deliver the Service. Amazon Web Services (AWS) Processes Customer Content for the Cap Orbit-hosted Service. Anthropic Processes Customer Content only when the Customer's configuration uses Claude Platform directly rather than Amazon Bedrock. We also disclose providers that process account and identity data (WorkOS), billing data (Stripe), and Usage Data (Metronome), together with the provider that hosts our public marketing website and processes no Customer Content (Vercel). This document uses "Subprocessors and service providers" when referring collectively to these categories.
Each provider identified in this list is engaged as a service provider, contractor, processor, or other vendor as appropriate for the function it performs. Where a provider processes Personal Information on Cap Orbit's behalf, Cap Orbit uses contractual restrictions intended to limit the provider's use of that Personal Information to the services it provides to Cap Orbit and to prohibit the provider from selling or using it for targeted advertising.
Before a Subprocessor receives Customer Content, Cap Orbit enters into a written agreement that flows down data-protection obligations equivalent in substance to those Cap Orbit owes to the Customer under the DPA, including obligations limiting the Subprocessor to the documented processing purposes, requiring confidentiality, requiring reasonable security measures, and prohibiting any use of Customer Content to train, fine-tune, or otherwise improve any AI or machine-learning model unless the Customer has opted into that use. Cap Orbit remains responsible to the Customer for the performance of each Subprocessor's obligations.
You can subscribe to advance notice of changes to this list. See Section 5 (Changes and notification) for how to subscribe and how we provide notice before a new Subprocessor begins processing Customer Content.
2. Current Subprocessors and service providers
The following table lists the providers Cap Orbit currently engages. A provider marked as configuration-specific Processes Customer Content only when that configuration is selected. As used here, "Usage Data" has the meaning given in the DPA and Privacy Policy (metadata about use of the Service, excluding Customer Content).
Location entries identify the primary region or configuration currently used for the Service. They are not a general data-residency commitment unless the applicable Order expressly says otherwise.
| Provider | Purpose | Data Processed | Primary location / configuration |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, database, content delivery, and AI model inference for Amazon Bedrock configurations | Customer Content, and account and Usage Data | United States configuration unless an Order states otherwise |
| Anthropic | AI model inference through Claude Platform on AWS; applies only when that provider is selected | Inputs, Outputs, and related request data | Anthropic-operated processing through the configured AWS region |
| WorkOS | Identity, authentication, single sign-on, and organization and seat membership | User identifiers, name, email address, and organization data | United States |
| Stripe | Payment processing and subscription billing | Payment method data and Stripe customer and subscription identifiers | United States |
| Metronome | Usage metering and billing | Usage Data (metadata only, no Customer Content) | United States |
| Vercel | Hosting of the public marketing website only | Website visitor server logs (IP address, user agent, referrer); no Customer Content | United States |
3. Configuration-specific AI processing
Cap Orbit supports more than one AI-inference configuration:
- Amazon Bedrock. For sessions configured to use Amazon Bedrock, AWS operates the inference service and is the Subprocessor. AWS states that Amazon Bedrock does not share customer inputs or outputs with model providers or use them to train foundation models. Current AWS service terms and documentation govern that processing.
- Claude Platform on AWS. For sessions configured to use Claude Platform on AWS, Anthropic operates the inference service and Processes Inputs, Outputs, and related request data as a Subprocessor. This processing is outside the Amazon Bedrock service boundary. Anthropic's standard commercial API retention is up to 30 days for Inputs and Outputs, subject to exceptions in Anthropic's current terms and documentation, including longer retention for certain features, safety and usage-policy enforcement, legal requirements, or a different written retention arrangement.
Cap Orbit does not use, or authorize either provider to use, Customer Content to train or fine-tune generalized models unless the Customer expressly opts in or gives a documented instruction permitting that use. Provider documentation may change, so this list describes Cap Orbit's current configuration and links to the providers' current terms rather than incorporating provider statements into the Terms of Service. See the [Amazon Bedrock documentation](https://aws.amazon.com/bedrock/faqs/) and [Anthropic commercial retention information](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data).
4. Customer-controlled deployments
Where the Service is deployed into infrastructure the Customer owns or controls, that infrastructure provider is not a Cap Orbit Subprocessor for the Customer-controlled Processing. The Customer is responsible for the configuration, access controls, logging, retention, deletion, and revocation of its infrastructure. A provider Cap Orbit separately engages to Process Customer Content, including a configuration-specific AI provider, remains a Subprocessor and is listed above.
The following continue to apply as Cap Orbit service providers in a Customer-controlled deployment because they support identity and billing rather than the hosting of Customer Content:
- WorkOS, for identity, authentication, single sign-on, and organization and seat membership.
- Stripe, for payment processing and subscription billing.
- Metronome, for usage metering and billing (Usage Data only, no Customer Content).
Vercel hosts the public marketing website only and does not process Customer Content.
5. Changes and notification
Effective date: June 18, 2026. Last updated: July 11, 2026.
Cap Orbit may add to or change its Subprocessors from time to time. Before a new Subprocessor begins processing Customer Content, Cap Orbit will update this list and provide at least ten (10) business days' advance notice to Customers who have subscribed to Subprocessor change notifications. Customers may object to a new Subprocessor as set out in the DPA. To subscribe to notifications, or to ask a question about this list, contact us at privacy@cap-orbit.com.
This list is maintained in connection with the DPA, the Privacy Policy, and the Cap Orbit Terms of Service. If there is a conflict between this list and the DPA as to the processing of Customer Content, the DPA controls.
(c) 2026 Cap Orbit