Policies & Terms

GitLaw Subprocessors


GitLaw defines customer data as all data provided by the customer to GitLaw through their use of GitLaw services. Some customer data is personal data as defined under GDPR.

The GitLaw Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitLaw to provide services to our customers. This list is applicable for all GitLaw services governed by the GitLaw Data Protection Agreement.

GitLaw publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor's authorization to perform services that may involve access to customer data or personal data. To be notified when this list changes, email [email protected] and ask to be added to the subprocessor notification list.

If you have questions about this list, please contact us at [email protected].

Name of SubprocessorDescription of ProcessingLocation of ProcessingCorporate Location
AnthropicAI processing for document drafting, review, and analysisUnited StatesUnited States
OpenAIAI processing for document drafting, review, and analysisUnited StatesUnited States
Google (Gemini API)AI processing for document drafting, review, and analysisUnited StatesUnited States
Google Cloud Platform (GCP)Cloud Hosted InfrastructureUnited States, BelgiumUnited States
CloudflareContent delivery serviceUnited StatesUnited States
SendGridTransactional and notification email deliveryUnited StatesUnited States
TwilioSMS notification provider for 2 Factor AuthenticationUnited StatesUnited States
SegmentAnalytics event routingUnited StatesUnited States
SentryApplication error and performance monitoringUnited StatesUnited States
ClayData enrichment (firmographic/professional data)United StatesUnited States
Apollo.ioData enrichment (sub-processor engaged by Clay)United StatesUnited States
People Data LabsData enrichment (sub-processor engaged by Clay)United StatesUnited States

This table covers providers that process customer data - the documents, inputs and account information you give us. Providers that only ever see site-usage telemetry, advertising measurement or payment-fraud signals, and never customer documents, are listed in the Cookies policy instead. Where a provider does both, it appears in both places.

Sign up to source, customize, and store contracts for free

Sign Up