Compliance
Every third-party data processor, subprocessor, business associate, third-party service provider, and partner that handles customer data on behalf of WatchSuit.
This page lists every data processor and subprocessor authorized to receive customer data when you use WatchSuit. We update this list at least 30 days before engaging any new vendor and notify active customers by email of any substantive change.
| Subprocessor | Service | Data Processed | Region |
|---|---|---|---|
| Neon | Postgres database hosting (data processor) | Customer accounts, scan results, scores | US (AWS us-east-1) |
| Render | Application hosting | Application logs, request bodies | US (Oregon) |
| Postmark | Transactional email service providers | Email addresses, message content | US |
| Stripe | Payment processing (data processor) | Billing data, card metadata | US / Ireland |
| Polsia Analytics | First-party analytics (consent-gated) | Anonymous visitor ID, page views | US |
The vendors above are the only third-party service providers authorized to process customer data. We work with additional vendors for marketing, sales, and product development — those vendors do not have access to customer data.
For HIPAA-impacted customers, WatchSuit offers a Business Associate Agreement addendum that covers the limited scope where PHI may transit through our system. Customers who handle PHI directly with any of our sub-processor partners (Neon, Render, Postmark) should request the business associate list from each upstream vendor directly.
Active customers will be notified at least 30 days before any new subprocessor is engaged. If you do not consent to a new subprocessor, you may terminate your subscription for a full refund of the unused subscription period.
Last updated: July 15, 2026. Questions? Email privacy@watchsuit.polsia.app.