ActiveCampaign Subprocessors List (September 2026): Changes and History
ActiveCampaign names 14 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
ActiveCampaign subprocessors (September 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Amazon Web Services | Data Storage Service | United States, European Union, Australia |
| 2 | CloudFlare | Network Service | United States |
| 3 | Snowflake | Data Warehouse Service | United States, European Union, Australia |
| 4 | Zendesk | Customer Support Service | United States |
| 5 | Zight (formerly CloudApp) | Customer Support Service | United States |
| 6 | Twilio | SMS Delivery Service | United States |
| 7 | OpenAI | Artificial Intelligence Service | United States |
| 8 | ActiveCampaign Ireland Limited | — | Ireland |
| 9 | ActiveCampaign Australia Pty Limited | — | Australia |
| 10 | ActiveCampaign Brasil LTDA | — | Brazil |
| 11 | ActiveCampaign Costa Rica S.R.L. | — | Costa Rica |
| 12 | ActiveCampaign Poland sp. z o.o. | — | Poland |
| 13 | 11 Tecnologías, S. de R.L. de C.V. | — | Mexico |
| 14 | AC Snudrovia LLC | — | United States |
Get an email when ActiveCampaign changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at ActiveCampaign
What ActiveCampaign's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“Company will take commercially reasonable efforts to, without undue delay: (a) notify Client of the Security Breach”
DPA, www.activecampaign.com ↗ - Notice of a new subprocessor
-
7 days ahead
“If within 7 days of Company posting such update, Client does not notify Company in writing of any objections”
DPA, www.activecampaign.com ↗ - Transfers outside the EU
-
Standard contractual clauses and the EU–US Data Privacy Framework
“Company has certified its compliance to the EU-U.S. Data Privacy Framework Principles, including as applied under the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework Principles”
“any regulated data transfer will be conducted pursuant to the Standard Contractual Clauses promulgated by the European Commission Decision 2021/914/EU under Module Two”
DPA, www.activecampaign.com ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“Upon termination of the Agreement and written request by Client, Company will return all Personal Information to Client or destroy all Personal Information and all copies thereof”
DPA, www.activecampaign.com ↗ - Audit rights
-
Once a year
“Company will provide to Client, no more than once a year, Company's latest available security package, which will include a copy of Company's SOC 2 Type 2 report”
DPA, www.activecampaign.com ↗
Documents we track for ActiveCampaign
- DPA
- checked September 26, 2026 www.activecampaign.com ↗
- Privacy policy
- checked September 26, 2026 www.activecampaign.com ↗
- Subprocessor list
- checked September 26, 2026 www.activecampaign.com ↗
- Terms of service
- checked September 26, 2026 www.activecampaign.com ↗
Change history
Tracking since September 26, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
ActiveCampaign subprocessors FAQ
- How many subprocessors does ActiveCampaign use?
- ActiveCampaign lists 14 subprocessors on its published list, including Amazon Web Services, CloudFlare, Snowflake, Zendesk, and Zight (formerly CloudApp) and 9 more.
- Where does ActiveCampaign process customer data?
- The subprocessors named by ActiveCampaign are located in United States, Australia, European Union, Brazil, Costa Rica, and Ireland and 2 other locations, as stated on its list.
- How quickly does ActiveCampaign report a personal data breach to customers?
- According to its DPA, ActiveCampaign reports a personal data breach to customers without undue delay, with no set deadline: “Company will take commercially reasonable efforts to, without undue delay: (a) notify Client of the Security Breach”
- How much notice does ActiveCampaign give before adding a subprocessor?
- ActiveCampaign's DPA gives 7 days' notice of a new subprocessor, the time customers have to object: “If within 7 days of Company posting such update, Client does not notify Company in writing of any objections”
- How does ActiveCampaign transfer personal data outside the EU?
- ActiveCampaign's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “Company has certified its compliance to the EU-U.S. Data Privacy Framework Principles, including as applied under the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework Principles”
- When was ActiveCampaign's subprocessor list last checked?
- ClauseTrail last checked ActiveCampaign's subprocessor list on September 26, 2026. Lists are re-checked daily.
- How do I find out when ActiveCampaign adds or removes a subprocessor?
- ClauseTrail monitors ActiveCampaign's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.