Legal

Subprocessor public summary

Last updated July 11, 2026Public summary; the applicable customer agreement controls
On this page Overview Provider categories Named schedules & changes Contact

This page is a public summary of service-provider categories that may support BearScope or a contracted managed deployment. It is not a complete, named, or service-specific subprocessor list. When Fibric acts as a processor, the named providers, functions, processing locations, notice process, and objection rights that apply to a customer are identified in the applicable customer agreement, data-processing schedule, or other written notice required by that agreement.

Overview

A third-party provider is a subprocessor only when it processes Customer personal data on Fibric's behalf for the contracted Service. Providers used for Fibric's own controller activities are governed by our Privacy Policy instead. For an incorporated DPA, Fibric applies contractual data-protection, access, and security requirements appropriate to the provider's processing and remains responsible to the extent required by the applicable customer agreement and law. Tenant-scoped controls do not mean Customer Data never reaches an authorized subprocessor; any such processing must be limited to the contracted purpose and provider schedule.

Public provider-category summary

Provider or categoryPotential functionApplicability & location
Amazon Web Services (AWS)Cloud compute, storage, database, authentication, and hosting for supported production servicesApplies where identified in the customer's named schedule; service and region depend on the contracted deployment.
Communications or transactional email providerService, authentication, or notification messagesApplies only if a named provider is used for the contracted Service; processing location is stated in the named schedule.
Error monitoring or telemetry providerApplication error tracking, security monitoring, or performance telemetryApplies only if a named provider receives Customer personal data; scope and location are stated in the named schedule.
Product analytics providerContracted product-usage analyticsApplies only if enabled for the contracted Service and named in the schedule; marketing-site analytics may instead be a controller activity.
Customer support tooling providerSupport requests and service communicationsApplies only where a named provider processes Customer personal data for support under the contracted Service.
Payment processorContracted invoicing or payment processingApplies only if identified in the customer agreement or invoice. Fibric does not currently offer public self-service checkout.

The categories above describe functions that may be used; they are not a representation that every category or provider is currently used for every customer, or a complete named schedule. Request the schedule for your contracted Service from the contact below.

Named schedules & changes

The applicable customer agreement determines how Fibric provides the initial named schedule and notices additions or replacements. Advance notice, objection procedure, alternatives, and any termination right exist only to the extent stated in that agreement, an incorporated DPA, or applicable law. This public summary may be updated for clarity, but it is not a substitute for a contractually required provider notice.

Contact

Questions about a named schedule or a contract-specific provider change? Email privacy@fibric.io and identify the applicable customer and agreement.