Amplitude Subprocessors List (September 2026): Changes and History
Amplitude names 9 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Amplitude subprocessors (September 2026)
| # | Subprocessor | Purpose | Location | Data |
|---|---|---|---|---|
| 1 | Amazon Web Services | Cloud hosting and infrastructure provider; generative AI technology used to enhance Amplitude's AI features (AWS Bedrock) | United States | United States |
| 2 | Datadog, Inc. | Logging and operational monitoring | United States | United States |
| 3 | Google, LLC | Generative AI technology, delivered via Google Vertex AI, used to enhance Amplitude’s AI features Cloud hosting and infrastructure provider for the Statsig-branded Amplitude Services (US only) | United States | United States |
| 4 | OpenAI, LLC | Generative AI technology used to enhance Amplitude and Statsig’s AI features | United States | United States |
| 5 | Snowflake Computing, Inc. | Data warehousing services (if Customer has purchased an applicable add-on service or is using AI Feedback) | United States | United States |
| 6 | Wiz, Inc. | Security vulnerability management and detection | United States | United States |
| 7 | Fivetran Inc. | Cloud-based data movement platform | United States | United States |
| 8 | MongoDB, Inc. | Database provider for the Statsig-branded Amplitude Services | United States | United States |
| 9 | Microsoft Azure | Cloud service Provider for the Statsig-branded Amplitude Services | United States | United States |
Get an email when Amplitude changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Amplitude
What Amplitude's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Within 48 hours
“Amplitude will assist Customer in complying with those obligations applicable to Customer by informing Customer of a Personal Data Breach without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach impacting Customer”
DPA, amplitude.com ↗ - Notice of a new subprocessor
-
30 days ahead
“Amplitude will update its list of Subprocessors to include the new Subprocessor at least thirty (30) days prior to giving the Subprocessor access to the Personal Data.”
DPA, amplitude.com ↗ - Transfers outside the EU
-
Standard contractual clauses and the EU–US Data Privacy Framework
“in accordance with the Data Privacy Framework, provided Amplitude is self-certified under the Data Privacy Framework and the Data Privacy Framework remains a lawful transfer mechanism”
“subject to the 2021 Standard Contractual Clauses and the UK Addendum, as appropriate”
DPA, amplitude.com ↗ - Customer data after the contract ends
-
Deleted within 30 days of the contract ending
“Amplitude shall make available to Customer all Personal Data stored within the Amplitude Services for thirty (30) days after termination or expiration of the Agreement ("Data Retrievability Period").”
DPA, amplitude.com ↗ - Audit rights
-
Through certifications and audit reports only
“Amplitude will provide Customer with such audit reports or certificates applicable to the Amplitude Services (e.g., SOC 2 report, ISO certificates), to the extent available, or such other information reasonably necessary to demonstrate compliance with this DPA.”
DPA, amplitude.com ↗
Documents we track for Amplitude
- DPA
- checked September 25, 2026 amplitude.com ↗
- Privacy policy
- checked September 25, 2026 amplitude.com ↗
- Subprocessor list
- checked September 25, 2026 amplitude.com ↗
- Terms of service
- checked September 25, 2026 amplitude.com ↗
Change history
Tracking since September 25, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Amplitude subprocessors FAQ
- How many subprocessors does Amplitude use?
- Amplitude lists 9 subprocessors on its published list, including Amazon Web Services, Datadog, Inc., Google, LLC, OpenAI, LLC, and Snowflake Computing, Inc. and 4 more.
- Where does Amplitude process customer data?
- The subprocessors named by Amplitude are located in United States, as stated on its list.
- How quickly does Amplitude report a personal data breach to customers?
- According to its DPA, Amplitude reports a personal data breach to customers within 48 hours: “Amplitude will assist Customer in complying with those obligations applicable to Customer by informing Customer of a Personal Data Breach without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach impacting Customer”
- How much notice does Amplitude give before adding a subprocessor?
- Amplitude's DPA gives 30 days' notice of a new subprocessor, the time customers have to object: “Amplitude will update its list of Subprocessors to include the new Subprocessor at least thirty (30) days prior to giving the Subprocessor access to the Personal Data.”
- How does Amplitude transfer personal data outside the EU?
- Amplitude's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “in accordance with the Data Privacy Framework, provided Amplitude is self-certified under the Data Privacy Framework and the Data Privacy Framework remains a lawful transfer mechanism”
- When was Amplitude's subprocessor list last checked?
- ClauseTrail last checked Amplitude's subprocessor list on September 25, 2026. Lists are re-checked daily.
- How do I find out when Amplitude adds or removes a subprocessor?
- ClauseTrail monitors Amplitude's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.