Last Updated: July 22, 2026
Third Space, LLC ("Thirdspace") operates CRM Data Backup & Restore ("the Service") and uses the following sub-processors to provide the Service. Each sub-processor is bound by a data processing agreement that imposes data protection obligations no less protective than those in our Data Processing Agreement.
| Sub-Processor | Purpose | Data Processed | Location | Transfer Mechanism |
|---|---|---|---|---|
| Render, Inc. Privacy Policy |
Application hosting, PostgreSQL database | OAuth tokens (encrypted), Portal IDs, billing status, usage metrics, backup metadata, async job records | Oregon, United States | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Anthropic, PBC Privacy Policy |
1. Reconstruction analysis (Emergency Unmerge feature only) 2. Advanced pattern matching (CRM field comparison for identifying potential duplicates) 3. Web search verification (publicly available information retrieval via web_search tool for validating duplicate matches) |
CRM record data (names, emails, phone numbers, deal amounts, company info, domains, engagement metadata) - transmitted when user initiates Emergency Unmerge or duplicate detection | United States | Standard Contractual Clauses; Anthropic Commercial Terms (no model training on API data; 30-day deletion) |
| Stripe, Inc. Privacy Policy |
Payment processing, subscription management, tax calculation | Stripe Customer ID, subscription status, payment history, credit purchase records | United States | EU-US Data Privacy Framework; Standard Contractual Clauses; PCI DSS Level 1 |
| Functional Software, Inc. (Sentry) Privacy Policy |
Error monitoring and application performance | Error logs, stack traces, request metadata - PII sending disabled (send_default_pii=False) |
United States | Standard Contractual Clauses |
| Amazon Web Services, Inc. Privacy Policy |
Object storage (S3) for the cold-storage tier of older backup data | Backup snapshot payloads, offloaded only as ciphertext: data is encrypted by our application before upload and the encryption keys never leave our application, with S3 server-side encryption as a second layer | United States | EU-US Data Privacy Framework; Standard Contractual Clauses (AWS Data Processing Addendum) |
| Resend, Inc. Privacy Policy |
Transactional and service email delivery | Recipient email address and first name, email subject and body, portal id tags | United States | Standard Contractual Clauses (Resend Data Processing Agreement) |
| Artisan AI, Inc. Privacy Policy |
Website visitor analytics on our marketing pages, used to identify companies visiting our site for our own sales outreach | Visitor IP address, device and browser characteristics, pages viewed and usage data on our website | United States | Standard Contractual Clauses |
We will notify customers of any intended changes to sub-processors (additions or replacements) at least 30 days before the change takes effect. Notifications will be sent via:
If you object to a new sub-processor, you may notify us within 30 days of the notification at joshua@thirdspaced.com. We will discuss the concern in good faith. If the objection cannot be resolved, you may terminate the Service in accordance with the Terms of Service.
No sub-processors have been removed to date.
For questions about our sub-processors or data processing practices, contact us at joshua@thirdspaced.com.
Third Space, LLC
Privacy: joshua@thirdspaced.com
Website: https://crmbackup.io