Pendo Subprocessors List (October 2026): Changes and History
Pendo names 9 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Pendo subprocessors (October 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Google Cloud Platform | Hosting infrastructure services, (optional) AI services | US, EU, JPN, AUS |
| 2 | Amazon Web Services | Email routing, legacy CDN | US, EU, JPN, AUS |
| 3 | OpenAI | (Optional) AI functionality in product | US, EU |
| 4 | Elastic.co | Logging and query solution | US, EU, JPN, AUS |
| 5 | Core10 | (Optional with purchase) Professional Services | US |
| 6 | Microsoft Azure | (Optional) AI functionality in product | US, EU, JPN |
| 7 | Tray.ai | Workflow automation and systems integration | US, EU, JPN, AUS |
| 8 | LangChain | (Recommended Optional) AI agent development infrastructure | US, EU |
| 9 | Anthropic Claude | (Optional) AI functionality in product | US |
Get an email when Pendo changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Pendo
What Pendo's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“Pendo shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as in its sole discretion deems necessary and reasonable to remediate such violation”
DPA, www.pendo.io ↗ - Notice of a new subprocessor
-
30 days ahead
“At least thirty (30) days before enabling any third party other than existing Subprocessors to access or participate in the processing of Personal Data, Pendo will provide notification to Customer”
DPA, www.pendo.io ↗ - Transfers outside the EU
-
Standard contractual clauses, the EU–US Data Privacy Framework, and adequacy decisions
“the EU SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows”
“pursuant to the Data Privacy Framework, provided Pendo is certified under such and the Data Privacy Framework remains a lawful transfer mechanism”
“If Pendo transfers Personal Data protected under this DPA to a jurisdiction for which the European Commission has not issued an adequacy decision, Pendo will ensure that appropriate safeguards have been implemented”
DPA, www.pendo.io ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“Following completion of the Services, at Customer's choice, Pendo shall return or delete Customer's Personal Data, unless further storage of such Personal Data is required or authorized by applicable law.”
DPA, www.pendo.io ↗ - Audit rights
-
Once a year
“such audit shall only be performed during business hours and occur no more than once per calendar year”
DPA, www.pendo.io ↗
Documents we track for Pendo
- DPA
- checked October 6, 2026 www.pendo.io ↗
- Privacy policy
- checked October 6, 2026 www.pendo.io ↗
- Subprocessor list
- checked October 6, 2026 trust.pendo.io ↗
- Trust page
- trust.pendo.io ↗
Change history
Tracking since October 6, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Pendo subprocessors FAQ
- How many subprocessors does Pendo use?
- Pendo lists 9 subprocessors on its published list, including Google Cloud Platform, Amazon Web Services, OpenAI, Elastic.co, and Core10 and 4 more.
- Where does Pendo process customer data?
- The subprocessors named by Pendo are located in US, EU, JPN, and AUS, as stated on its list.
- How quickly does Pendo report a personal data breach to customers?
- According to its DPA, Pendo reports a personal data breach to customers without undue delay, with no set deadline: “Pendo shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as in its sole discretion deems necessary and reasonable to remediate such violation”
- How much notice does Pendo give before adding a subprocessor?
- Pendo's DPA gives 30 days' notice of a new subprocessor, the time customers have to object: “At least thirty (30) days before enabling any third party other than existing Subprocessors to access or participate in the processing of Personal Data, Pendo will provide notification to Customer”
- How does Pendo transfer personal data outside the EU?
- Pendo's DPA relies on standard contractual clauses, the EU–US Data Privacy Framework, and adequacy decisions: “the EU SCCs, which are deemed entered into (and incorporated into this DPA by this reference) and completed as follows”
- When was Pendo's subprocessor list last checked?
- ClauseTrail last checked Pendo's subprocessor list on October 6, 2026. Lists are re-checked daily.
- How do I find out when Pendo adds or removes a subprocessor?
- ClauseTrail monitors Pendo's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.