Skip to main content

Legal

Sub-processors

The third parties that help us run Ṣọ Email Security, what each one does, and exactly what data each one receives.

Effective: July 25, 2026Last Updated: July 25, 2026

A sub-processor is an outside company that handles data on our behalf so we can run the product. If we use a supplier for hosting, payments, sign-in, or sending email, that supplier is a sub-processor. This page names every one of them.

Our Data Processing Addendum refers to this page as the current list. Our Privacy Policy explains what we collect and why. Where a signed agreement names a different list, the signed agreement applies to that customer.

SO Labs Inc. is based in Calgary, Alberta, Canada. Our primary privacy framework is PIPEDA. Canada currently benefits from an EU adequacy decision for commercial organisations subject to PIPEDA.

01Current Sub-processors

This is the full list of third parties that receive data from our services today. It reflects what our code actually calls, not what appears in configuration.

ProviderWhat they do for usWhat data they receiveLocation
Amazon Web Services (EC2)Hosting and infrastructure for the platform and the APIAccount records, usage and billing metadata, and any data our services hold at restCanada. Exact region to confirm
StripePayment processing and subscription billingBilling data only. Never email contentTo confirm
Have I Been Pwned (HIBP)Dark web breach monitoringThe user's email address only. No passwords. No email contentTo confirm
Google (Gmail API, Google OAuth)Mailbox access and sign-inThe mailbox access the user authorises, and basic profile informationTo confirm
Microsoft (Graph API, Microsoft OAuth)Mailbox access and sign-inThe mailbox access the user authorises, and basic profile informationTo confirm
Apple (Sign in with Apple)Authentication onlyAuthentication identifiersTo confirm
SMTP email provider (used via nodemailer)Transactional email delivery, such as verification, alerts, and billing noticesThe recipient email address and the content of the message we sendTo confirm
WiseReferral programme payouts onlyThe payout details a recipient gives us for that purposeTo confirm
CloudinaryHosts the images embedded in our outbound email templatesNo user dataTo confirm
Our own machine learning classifier serviceEmail threat analysis. Returns a verdict and stores nothingEmail subject and body, held in memory onlyOur own infrastructure. Region to confirm

A few points worth stating plainly, because reviewers ask about them every time.

  • Have I Been Pwned gets an email address and nothing else. No password, no password hash, and no email content is ever sent there.
  • Cloudinary receives no user data. It serves the logo and illustration files that our email templates link to. We do not send it any personal data.
  • Stripe never sees email content. It receives the billing data needed to charge a subscription.
  • The classifier is ours, not an outside company. It is listed for completeness so the picture is complete. Once the pending backend change ships, email content is analysed in memory and is not written to persistent storage. The one exception is content a user voluntarily submits when reporting a false positive, which is encrypted at rest and deleted after 90 days.
  • Locations marked “to confirm” are not guesses. We would rather leave a cell honest than fill it with something we have not verified. We will update this page as each one is confirmed.

02The Ṣọ Shield API Uses No External Third Parties

The Ṣọ Shield API service calls no external third parties at all.

Content you submit to the API, including email bodies, headers, documents, URLs, and images, never leaves our infrastructure. It is not sent to a threat intelligence vendor, a reputation service, or any other outside company for analysis. The analysis runs on our own systems and the result is returned to you.

The providers in the table above support the wider platform, for example hosting, billing, sign-in, and outbound email. They are not in the path of an API analysis request. If that ever changes, we will announce it under Section 04 before it takes effect.

The API Terms set out the rest of the arrangement, including roles, retained request metadata, and the limits of automated detection.

03Not Used

Two services appear in older configuration files but are not called by any code path. They receive no data from us, so they are not sub-processors and are deliberately left off the list above.

  • VirusTotal. Present in configuration. Never called. Receives no data.
  • Google Safe Browsing. Present in configuration. Never called. Receives no data.

We state this openly so a reviewer who finds those names in a config file does not assume data is going to them. If we start calling either service, we will add it to the table above and announce it in advance.

04How We Announce Changes, and How to Object

  • Advance notice. We email enterprise and API customers who subscribe to these updates at least 30 days before a new sub-processor starts processing data.
  • This page is updated too. The table and the date at the bottom change at the same time, so you can check the current position at any point.
  • Subscribing. Email privacy@soemailsecurity.com with the subject “Sub-processor updates” and tell us which address to notify.
  • Objecting. Reply to the notice, or email the same address, within the notice period. Tell us the data protection grounds for the objection. We will work with you to find a fix, such as a different provider or a change to the configuration.
  • If we cannot resolve it. You may terminate the affected service under the terms of your agreement. Your signed agreement and our Data Processing Addendum set out how that works.
  • Emergency replacements. If we must replace a provider quickly, for security or because a provider fails, we will act first and tell subscribers as soon as we can with the reason.

Governing law, jurisdiction, and dispute resolution are set out in our Terms of Service.

05Questions and Last Updated

Last updated: July 25, 2026.