Subprocessor public summary
This page is a public summary of service-provider categories that may support BearScope or a contracted managed deployment. It is not a complete, named, or service-specific subprocessor list. When Fibric acts as a processor, the named providers, functions, processing locations, notice process, and objection rights that apply to a customer are identified in the applicable customer agreement, data-processing schedule, or other written notice required by that agreement.
Overview
A third-party provider is a subprocessor only when it processes Customer personal data on Fibric's behalf for the contracted Service. Providers used for Fibric's own controller activities are governed by our Privacy Policy instead. For an incorporated DPA, Fibric applies contractual data-protection, access, and security requirements appropriate to the provider's processing and remains responsible to the extent required by the applicable customer agreement and law. Tenant-scoped controls do not mean Customer Data never reaches an authorized subprocessor; any such processing must be limited to the contracted purpose and provider schedule.
Public provider-category summary
| Provider or category | Potential function | Applicability & location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud compute, storage, database, authentication, and hosting for supported production services | Applies where identified in the customer's named schedule; service and region depend on the contracted deployment. |
| Communications or transactional email provider | Service, authentication, or notification messages | Applies only if a named provider is used for the contracted Service; processing location is stated in the named schedule. |
| Error monitoring or telemetry provider | Application error tracking, security monitoring, or performance telemetry | Applies only if a named provider receives Customer personal data; scope and location are stated in the named schedule. |
| Product analytics provider | Contracted product-usage analytics | Applies only if enabled for the contracted Service and named in the schedule; marketing-site analytics may instead be a controller activity. |
| Customer support tooling provider | Support requests and service communications | Applies only where a named provider processes Customer personal data for support under the contracted Service. |
| Payment processor | Contracted invoicing or payment processing | Applies only if identified in the customer agreement or invoice. Fibric does not currently offer public self-service checkout. |
The categories above describe functions that may be used; they are not a representation that every category or provider is currently used for every customer, or a complete named schedule. Request the schedule for your contracted Service from the contact below.
Named schedules & changes
The applicable customer agreement determines how Fibric provides the initial named schedule and notices additions or replacements. Advance notice, objection procedure, alternatives, and any termination right exist only to the extent stated in that agreement, an incorporated DPA, or applicable law. This public summary may be updated for clarity, but it is not a substitute for a contractually required provider notice.
Contact
Questions about a named schedule or a contract-specific provider change? Email privacy@fibric.io and identify the applicable customer and agreement.