7. Privacy Policies - GitHub Subprocessors
Updated 17 October 2025
This document provides a comprehensive list of GitHub's authorized subprocessors, detailing the services they perform and their processing locations. It clarifies how customer and personal data are handled in accordance with the GitHub Data Protection Agreement. Users can also find information on how to receive updates to this list.
GitHub Subprocessors
GitHub defines customer data as all data provided by the customer to GitHub through their use of GitHub services. Some customer data is personal data as defined under GDPR.
The GitHub Subprocessor List identifies subprocessors authorized to subprocess customer or personal data on behalf of GitHub to provide services to our Enterprise customers. This list is applicable for all GitHub services governed by the GitHub Data Protection Agreement.
GitHub publishes the names of any new subprocessors for its online services at least 30 days in advance of the subprocessor’s authorization to perform services that may involve access to customer data or personal data.
To receive notifications of updates to this Subprocessor list, please follow the instructions provided in About notifications.
If you have questions about this list, please contact us at [email protected].
Name of Subprocessor | Description of Processing | Location of Processing | Corporate Location |
Amazon Web Services (AWS) | Cloud Hosted Infrastructure and Data Hosting | United States | United States |
Azure (Microsoft) | Cloud Hosted Infrastructure and Data Hosting | United States, France, | United States |
Azure Cognitive Services | Customer support ticketing analysis | United States | United States |
Cloudflare | Content delivery service | United States | United States |
Fastly | Content delivery service | United States | United States |
GitHub Australia Pty Ltd | GitHub Subsidiary | Australia | Australia |
GitHub BV | GitHub Subsidiary | Netherlands | Netherlands |
GitHub Canada ULC | GitHub Subsidiary | Canada | Canada |
GitHub Germany GmbH | GitHub Subsidiary | Germany | Germany |
GitHub India Pty Ltd | GitHub Subsidiary | India | India |
Google Cloud Platform (GCP) | Cloud Hosted Infrastructure | United States | United States |
Microsoft | Technical Services | United States | United States |
Moveworks | Customer support ticketing analysis | United States | United States |
NexMo (aka Vonage) | SMS notification provider for 2 Factor Authentication | United States | United States |
Npm, Inc. | GitHub Subsidiary | United States | United States |
Obsidian Security | Security management | United States | United States |
Pusher | Building and managing real-time infrastructure for web and mobile applications | United States | United States |
Semmle Inc. | GitHub Subsidiary | United States | United States |
SendGrid | SMS notification provider for 2 Factor Authentication | United States | United States |
Twilio | SMS notification provider for 2 Factor Authentication | United States | United States |
VividCortex | Monitor database performance, efficiency, and uptime | United States | United States |
Zendesk | Customer support ticketing system | United States | United States |
About this template
What is this template?
7. Privacy Policies - GitHub Subprocessors is a free, ready-to-use Data Protection & Privacy template you can open, customize, and download on GitLaw. It gives you a professionally structured starting point, so you never have to draft from a blank page. The wording is plain and modern, organized into clear sections that are easy to read, edit, and adapt to your own situation before you share or sign it.
When should you use it?
Reach for this Data Protection & Privacy template whenever you need a reliable agreement quickly and want to be sure the essentials are covered. It suits individuals, freelancers, startups, and established businesses alike. Instead of paying for a document drafted from scratch, you can start here, tailor the details to your arrangement, and have a polished draft ready in minutes. This version is drafted with France, Switzerland, Japan, Australia, Netherlands, Canada, Germany, and India in mind, though you should always review the final wording against the laws that apply to you.
What's typically included?
A well-drafted Data Protection & Privacy usually sets out the parties involved, the scope of the agreement, and each side's rights and responsibilities. Expect sections covering key terms and definitions, how long the agreement lasts, how it can be ended, and what happens if something goes wrong. This template brings those building blocks together in a sensible order, so you can focus on the specifics rather than worrying about what to include. Open it to read the full document, then sign up to edit, negotiate, and e-sign it directly in GitLaw.