Appendix H — Subprocessors
Last updated July 2026 · v.02
Required Appendix to the Master Services Agreement.
1. Purpose and Scope
This Appendix identifies the subprocessors Clasp uses to provide the Service. Subprocessors perform limited processing activities on Customer Data as necessary for Clasp to operate, maintain, and support the Service. Clasp may update this list from time to time in accordance with Section 5.12 of the Agreement.
2. Current Subprocessors
2.1 Cloud Hosting & Storage
Subprocessor: Google Cloud Platform (GCP)
Purpose: Primary hosting, storage, encryption at rest, infrastructure services
Location: United States
Explanation: GCP provides physical, environmental, and infrastructure-level security controls. Region selection is not configurable by Customer.
2.2 Document Processing (OCR)
Subprocessor: Unstructured.io
Purpose: OCR and text extraction for document indexing and search
Location: United States
Explanation: OCR is read-only and does not modify document content.
2.3 Email Delivery
Subprocessor: Postmark
Purpose: Transactional email delivery for notifications, sharing links, OTP emails, and system messages
Location: United States
Explanation: Postmark handles all outbound email delivery. Clasp does not guarantee delivery times or deliverability rates.
2.4 Identity & Authentication
Subprocessor: Supabase
Purpose: Authentication flow for “Sign in with Google” and OTP generation
Location: United States
Explanation: Supabase does not access document content.
2.5 Messaging & Notifications
Subprocessor: Twilio
Purpose: Programmable SMS messaging for system notifications
Location: United States
Explanation: Twilio is used only for SMS messaging. Twilio does not access document content.
2.6 Payments (If Applicable)
Subprocessor: Stripe
Purpose: Payment processing for subscription fees
Location: United States
Explanation: Stripe processes billing information only; Stripe does not access Customer Data stored in the Service.
2.7 AI Vendors
Explanation: Clasp does not use external AI vendors for embeddings or inference in the core Service. All metadata and embeddings used for search, document organization, and workflow features are generated internally.
Clasp uses OpenAI solely for the optional Time Capture module, and only when Customer elects to enable both (a) Time Capture and (b) AI processing for Time Capture. When enabled, OpenAI processes internal metadata only to generate draft time-capture descriptions. Clasp does not transmit document text or Customer Data to OpenAI.
OpenAI processes submitted metadata solely to provide the requested inference. Under OpenAI’s published API terms, data submitted through the API is not used to train or improve OpenAI’s models and is not used for advertising or marketing purposes. OpenAI’s processing is governed by its published API policies and enterprise data-handling commitments.
This optional use of OpenAI is limited to the Time Capture module and does not affect any other part of the Service.
3. Subprocessor Limitations
Subprocessors:
do not access Customer Data except as required to perform their limited functions;
do not provide legal advice or legal analysis;
do not receive Customer Data for training or model development;
do not receive Customer Data for marketing or analytics;
do not receive Customer Data beyond what is necessary for their operational role.
4. Updates to Subprocessors
Clasp may update this Appendix from time to time. Updates will be made in accordance with Section 5.12 of the Agreement. Customer’s sole remedy for objections to new subprocessors is set forth in the Agreement.