Appendix H — Subprocessors

Last updated July 2026 · v.02

Required Appendix to the Master Services Agreement.

1. Purpose and Scope

This Appendix identifies the subprocessors Clasp uses to provide the Service. Subprocessors perform limited processing activities on Customer Data as necessary for Clasp to operate, maintain, and support the Service. Clasp may update this list from time to time in accordance with Section 5.12 of the Agreement.

2. Current Subprocessors

2.1 Cloud Hosting & Storage

Subprocessor: Google Cloud Platform (GCP)

Purpose: Primary hosting, storage, encryption at rest, infrastructure services

Location: United States

Explanation: GCP provides physical, environmental, and infrastructure-level security controls. Region selection is not configurable by Customer.

2.2 Document Processing (OCR)

Subprocessor: Unstructured.io

Purpose: OCR and text extraction for document indexing and search

Location: United States

Explanation: OCR is read-only and does not modify document content.

2.3 Email Delivery

Subprocessor: Postmark

Purpose: Transactional email delivery for notifications, sharing links, OTP emails, and system messages

Location: United States

Explanation: Postmark handles all outbound email delivery. Clasp does not guarantee delivery times or deliverability rates.

2.4 Identity & Authentication

Subprocessor: Supabase

Purpose: Authentication flow for “Sign in with Google” and OTP generation

Location: United States

Explanation: Supabase does not access document content.

2.5 Messaging & Notifications

Subprocessor: Twilio

Purpose: Programmable SMS messaging for system notifications

Location: United States

Explanation: Twilio is used only for SMS messaging. Twilio does not access document content.

2.6 Payments (If Applicable)

Subprocessor: Stripe

Purpose: Payment processing for subscription fees

Location: United States

Explanation: Stripe processes billing information only; Stripe does not access Customer Data stored in the Service.

2.7 AI Vendors

Explanation: Clasp does not use external AI vendors for embeddings or inference in the core Service. All metadata and embeddings used for search, document organization, and workflow features are generated internally.

Clasp uses OpenAI solely for the optional Time Capture module, and only when Customer elects to enable both (a) Time Capture and (b) AI processing for Time Capture. When enabled, OpenAI processes internal metadata only to generate draft time-capture descriptions. Clasp does not transmit document text or Customer Data to OpenAI.

OpenAI processes submitted metadata solely to provide the requested inference. Under OpenAI’s published API terms, data submitted through the API is not used to train or improve OpenAI’s models and is not used for advertising or marketing purposes. OpenAI’s processing is governed by its published API policies and enterprise data-handling commitments.

This optional use of OpenAI is limited to the Time Capture module and does not affect any other part of the Service.

3. Subprocessor Limitations

Subprocessors:

  • do not access Customer Data except as required to perform their limited functions;

  • do not provide legal advice or legal analysis;

  • do not receive Customer Data for training or model development;

  • do not receive Customer Data for marketing or analytics;

  • do not receive Customer Data beyond what is necessary for their operational role.

4. Updates to Subprocessors

Clasp may update this Appendix from time to time. Updates will be made in accordance with Section 5.12 of the Agreement. Customer’s sole remedy for objections to new subprocessors is set forth in the Agreement.