FundWisr™ Subprocessor List and Change-Notification Policy
1. Purpose
This Subprocessor List and Change-Notification Policy explains:
- what a subprocessor is;
- when FundWisr uses subprocessors;
- the information FundWisr publishes about each material subprocessor;
- how FundWisr evaluates and contracts with subprocessors;
- how enterprise customers receive notice of material subprocessor changes;
- how customers may raise reasonable data-protection objections;
- how emergency replacements and removals are handled; and
- how FundWisr governs artificial-intelligence, infrastructure, payment, communication, analytics, and support providers.
This Policy supplements the FundWisr Master Services Agreement, Enterprise Order Form, Data Processing Addendum, Privacy Policy, and Security and Trust Center Policy.
2. What Is a Subprocessor?
A “Subprocessor” is a third party engaged by Impctrs Management Group, LLC to Process Customer Personal Data on behalf of an organization or enterprise customer in connection with FundWisr services.
A provider is not automatically a subprocessor merely because FundWisr has a business relationship with it. The classification depends on whether the provider Processes Customer Personal Data on FundWisr’s behalf.
Examples may include providers supporting:
- cloud infrastructure;
- database hosting;
- authentication;
- file storage;
- payment processing;
- email delivery;
- artificial-intelligence services;
- analytics;
- monitoring;
- customer support;
- document processing;
- electronic signatures;
- integrations;
- backup and recovery.
3. General Authorization
Where an applicable Data Processing Addendum permits general authorization, Customer authorizes FundWisr to engage the subprocessors listed in the then-current Subprocessor Register, subject to:
- FundWisr’s due diligence;
- a written contract;
- appropriate confidentiality and security obligations;
- materially consistent data-protection duties;
- applicable notice and objection rights;
- FundWisr’s continuing responsibility as required by the Agreement and applicable law.
A customer requiring specific prior authorization must identify that requirement in the Enterprise Order Form.
4. Public Subprocessor Register
The current register of FundWisr's material subprocessors is set out below. This is the register itself, not a pointer to one, updated in place whenever a subprocessor changes.
| Legal name | Service | Purpose | Data categories | Processing location | AI training status | Status | Last verified |
|---|---|---|---|---|---|---|---|
| Vercel Inc. | Application hosting and delivery | Runs and serves the FundWisr web application | Request metadata, no direct access to Customer Content in the database | United States | Not applicable | Active | 2026-08-08 |
| Supabase, Inc. | Database, authentication, and file storage | Stores all organizational and customer data, manages user authentication, hosts uploaded documents | All Customer Personal Data and Customer Content | United States | Not applicable | Active | 2026-08-08 |
| Anthropic, PBC | AI model provider (Claude) | Powers the AI Co-Strategist, Document Studio, diagnostic scoring, and every other AI-assisted feature | Organizational context, user prompts, and uploaded document text sent to generate a response | United States | Anthropic's commercial API terms do not use customer API inputs or outputs to train its models | Active | 2026-08-08 |
| Stripe, Inc. | Payment processing and subscription billing | Processes subscription payments, hosts the billing portal, manages checkout | Billing contact information and payment details; FundWisr does not store card numbers directly | United States | Not applicable | Active | 2026-08-08 |
| PandaDoc Inc. | Contract generation and e-signature | Routes and collects signatures on enterprise contracts (Order Forms, DPAs, SLAs, and related agreements) generated through Contract Center | Signer name, email, and the contract content itself | United States | Not applicable | Active | 2026-08-08 |
| Resend | Transactional email delivery | Sends account notifications and digest emails | Recipient email address and message content | United States | Not applicable | Active, sandbox sender pending a verified FundWisr™ domain | 2026-08-08 |
| Functional Software, Inc. d/b/a Sentry | Application error monitoring | Records diagnostic information when the application fails, so faults can be found and fixed | Error messages, stack traces, the URL being requested, browser and device information, and the identifier of the signed-in user where one is present. Not used to read Customer Content, and sampled at ten percent for performance traces | United States | Not applicable | Active | 2026-08-29 |
| Deepgram, Inc. | Speech-to-text transcription | Converts audio dictated into a form into text, so the Fill by Voice feature can complete form fields. Available on Core, Growth and Multi-Org | The audio a user records while dictating, which may contain any information they choose to speak, including personal data about constituents, volunteers or staff. FundWisr does not retain the audio: it is held in memory for the length of the request, sent for transcription, and discarded. Only the resulting text is processed further | United States | Deepgram's terms do not use customer audio submitted through its API to train its models | Active | 2026-08-29 |
FundWisr must not list a vendor that has not been approved or omit a material provider that Processes Customer Personal Data.
6. Providers That May Act as Independent Controllers
Some third parties may Process limited information for their own legally independent purposes rather than solely as FundWisr subprocessors.
Examples may include:
- payment networks;
- banks;
- fraud-prevention providers;
- government authorities;
- legal or professional advisers;
- customer-selected integrations.
Where a provider acts as an independent controller, FundWisr must disclose that role accurately in the Privacy Policy or applicable notice rather than mislabeling the provider as a subprocessor.
7. Subprocessor Review Standard
Before onboarding a material subprocessor, FundWisr must evaluate:
- business necessity;
- data minimization;
- data categories;
- sensitivity;
- customer impact;
- role under privacy law;
- access model;
- encryption;
- authentication;
- tenant separation;
- logging;
- incident response;
- breach-notification commitment;
- retention;
- deletion;
- backup handling;
- international transfers;
- government-access risk;
- subcontractors;
- business continuity;
- audit or certification evidence;
- AI training and model-improvement terms;
- contract termination;
- data return or deletion.
A favorable marketing page, questionnaire, or certification badge alone is not sufficient due diligence.
8. Written Contract Requirement
Every material subprocessor must be governed by a written agreement that addresses, as applicable:
- documented instructions;
- confidentiality;
- purpose limitation;
- data-use restrictions;
- security measures;
- incident notification;
- privacy-rights assistance;
- audit or assurance information;
- subprocessor chain;
- international transfers;
- retention;
- deletion or return;
- cooperation;
- termination;
- prohibited sale or advertising use;
- AI training restrictions.
Where GDPR or UK GDPR applies, the agreement must impose materially equivalent data-protection obligations on the subprocessor.
9. New Subprocessor Notice
FundWisr will provide advance notice before a new material subprocessor begins Processing Customer Personal Data, where practicable.
Standard notice period
At least 15 calendar days before the planned effective date.
An Enterprise Order Form may specify a longer period.
Notice methods
Notice may be provided through:
- email to the Customer privacy or legal contact;
- in-product administrator notice;
- Trust Center subscription;
- customer portal;
- another agreed method.
Posting an update without a reasonable method for subscribed customers to learn of it is not sufficient when the DPA promises active notice.
10. Required Change Notice Content
The notice should include:
- subprocessor legal name;
- service;
- purpose;
- categories of Customer Personal Data;
- categories of Data Subjects;
- processing location;
- planned effective date;
- reason for the change;
- applicable transfer mechanism;
- security or certification summary;
- AI training or retention terms where applicable;
- objection deadline;
- objection instructions.
Recommended notice language
FundWisr plans to add [LEGAL ENTITY] as a subprocessor effective [DATE] to provide [SERVICE]. The provider may Process [DATA CATEGORIES] in [LOCATION] for [PURPOSE]. Applicable transfer and security information is available at [LINK]. Customers may submit a reasonable data-protection objection by [DEADLINE] through [METHOD].
11. Customer Objections
A Customer may object within the applicable notice period when it has a reasonable, documented concern that the proposed subprocessor creates a material risk to Customer Personal Data or prevents Customer from meeting an applicable legal obligation.
An objection should identify:
- Customer;
- proposed subprocessor;
- specific data-protection concern;
- applicable legal, contractual, security, or regulatory requirement;
- affected Customer use;
- requested resolution;
- supporting information.
A general preference, unsupported concern, procurement delay, or attempt to renegotiate pricing is not by itself a valid data-protection objection.
12. Objection Resolution
FundWisr will evaluate a timely objection in good faith.
Potential resolutions include:
- providing additional information;
- providing additional safeguards;
- limiting data fields;
- changing configuration;
- excluding the Customer from the affected feature;
- offering a commercially reasonable alternative;
- delaying activation for the affected Customer;
- deciding not to use the proposed subprocessor;
- allowing termination of the materially affected Service.
FundWisr is not required to redesign the entire platform or retain an insecure or unsupported provider solely to avoid a change.
If no reasonable resolution is available, the applicable DPA or Order Form will govern termination rights and refunds, if any.
13. Emergency Subprocessor Changes
FundWisr may need to engage, replace, or activate a subprocessor without the standard advance period when reasonably necessary to:
- respond to a security incident;
- prevent material service disruption;
- comply with law;
- replace a provider that abruptly terminates service;
- address insolvency;
- remediate a critical vulnerability;
- protect Customer Personal Data.
In that event, FundWisr will:
- complete expedited privacy and security review;
- apply written protections;
- notify affected customers as soon as reasonably practicable;
- explain the emergency basis;
- provide objection or alternative procedures where feasible;
- complete full review after stabilization.
“Emergency” must not be used to bypass ordinary governance for convenience.
14. Subprocessor Removal
When a subprocessor is removed, FundWisr must:
- disable production access;
- revoke credentials;
- terminate data flows;
- request return or deletion;
- confirm deletion where available;
- preserve required legal and contract records;
- update data maps;
- update the public register;
- update customer notices;
- verify that backups and residual records are handled appropriately.
The register should show a historical removal date or preserve an archived change record.
15. AI Subprocessors
AI providers require enhanced disclosure.
For every AI subprocessor, disclose or maintain customer-accessible information about:
- provider legal entity;
- model or service family;
- feature using the provider;
- data categories;
- whether prompts or outputs are retained;
- retention period or configuration;
- whether data is used for provider training;
- whether human review may occur;
- region;
- subprocessors;
- security measures;
- opt-out or feature-disable options.
Default FundWisr commitment
FundWisr does not use identifiable Customer Content, prompts, or outputs to train generalized AI models and does not authorize its AI subprocessors to do so unless the applicable Customer gives separate affirmative opt-in consent.
This statement must match every provider’s contract and production configuration.
16. Infrastructure and Database Providers
For core infrastructure providers, FundWisr must verify:
- region selection;
- backup locations;
- administrative support access;
- encryption;
- service-account controls;
- incident notice;
- availability dependencies;
- data deletion;
- provider subprocessors;
- international transfers.
A provider’s global support access or backup replication must not be omitted merely because the primary database region is domestic.
17. Analytics and Tracking Providers
An analytics or tracking provider is a subprocessor only where the relevant role and Processing support Customer services.
FundWisr must additionally evaluate whether the provider:
- acts as an independent controller;
- receives identifiers;
- combines data across customers or services;
- supports advertising;
- creates audiences;
- retains raw events;
- captures form values, AI prompts, or Customer Content.
Analytics providers must not receive unnecessary Customer Content or sensitive form fields.
18. Customer-Selected Integrations
When Customer independently directs FundWisr to send data to a customer-selected integration:
- Customer is responsible for authorizing the recipient;
- the recipient may be Customer’s processor or independent provider;
- FundWisr will follow documented instructions;
- the recipient does not automatically become a FundWisr subprocessor;
- the integration must be identified in the Order Form or configuration;
- FundWisr may disable an insecure integration.
FundWisr™ is operated by Impctrs Management Group, LLC under license from Mzrik Innovations, LLC. © 2026 Mzrik Innovations, LLC. All rights reserved. FundWisr™ and its proprietary frameworks, scoring systems, methodologies, platform content, software, and related intellectual property are owned by Mzrik Innovations, LLC. Technology developed by AI Arkitech, LLC.