Planhat Subprocessors List (September 2026): Changes and History
Planhat names 7 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Planhat subprocessors (September 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Google LLC., Google Ireland Ltd., Google Cloud EMEA Ltd. | Cloud hosting services, Analytics | United States, EU |
| 2 | MongoDB | Database management services | United States, EU |
| 3 | Twilio | Email service provider | United States |
| 4 | Google Vertex AI | Generative AI functionality | United States, EU |
| 5 | OpenAI | Generative AI functionality | United States, EU |
| 6 | Intercom | Customer support | United States |
| 7 | Planhat, Inc | Assist in delivery of some or all of the Services | United States |
Get an email when Planhat changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Planhat
What Planhat's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“In the event of a Personal Data breach concerning data processed by the Processor, the Processor shall notify the controller without undue delay after the Processor having become aware of the breach.”
DPA, www.planhat.com ↗ - Notice of a new subprocessor
-
30 days ahead
“the controller may object to the changes in the list within thirty (30) days of receiving the notification.”
DPA, www.planhat.com ↗ - Transfers outside the EU
-
Standard contractual clauses and adequacy decisions
“transfers will only take place on the basis of an adequacy decision, or, in the absence of such a decision, on the basis of appropriate safeguards, such as using standard contractual clauses (SCCs), provided the conditions for the use of those SCCs are met.”
“transfers will only take place on the basis of an adequacy decision, or, in the absence of such a decision, on the basis of appropriate safeguards, such as using standard contractual clauses (SCCs), provided the conditions for the use of those SCCs are met.”
DPA, www.planhat.com ↗ - Customer data after the contract ends
-
Deleted within 30 days of the contract ending
“Generally, data is deleted thirty (30) days after termination.”
DPA, www.planhat.com ↗ - Audit rights
-
On request
“At the controller's request, the Processor shall also permit and contribute to audits of the Processing activities covered by this DPA, at reasonable intervals or if there are indications of non-compliance.”
DPA, www.planhat.com ↗
Certifications at Planhat
What Planhat's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?
- SOC 2 Type II
-
Active
“SOC 2 Type II”
Trust page, www.planhat.com ↗ - ISO 27001
-
Active
“ISO27001”
Trust page, www.planhat.com ↗
Documents we track for Planhat
- DPA
- checked September 28, 2026 www.planhat.com ↗
- Privacy policy
- checked September 28, 2026 www.planhat.com ↗
- Subprocessor list
- checked September 28, 2026 trust.planhat.com ↗
- Terms of service
- checked September 28, 2026 www.planhat.com ↗
- Trust page
- checked September 28, 2026 www.planhat.com ↗
Change history
Tracking since September 28, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Planhat subprocessors FAQ
- How many subprocessors does Planhat use?
- Planhat lists 7 subprocessors on its published list, including Google LLC., Google Ireland Ltd., Google Cloud EMEA Ltd., MongoDB, Twilio, Google Vertex AI, and OpenAI and 2 more.
- Where does Planhat process customer data?
- The subprocessors named by Planhat are located in United States and EU, as stated on its list.
- How quickly does Planhat report a personal data breach to customers?
- According to its DPA, Planhat reports a personal data breach to customers without undue delay, with no set deadline: “In the event of a Personal Data breach concerning data processed by the Processor, the Processor shall notify the controller without undue delay after the Processor having become aware of the breach.”
- How much notice does Planhat give before adding a subprocessor?
- Planhat's DPA gives 30 days' notice of a new subprocessor, the time customers have to object: “the controller may object to the changes in the list within thirty (30) days of receiving the notification.”
- How does Planhat transfer personal data outside the EU?
- Planhat's DPA relies on standard contractual clauses and adequacy decisions: “transfers will only take place on the basis of an adequacy decision, or, in the absence of such a decision, on the basis of appropriate safeguards, such as using standard contractual clauses (SCCs), provided the conditions for the use of those SCCs are met.”
- Does Planhat have a SOC 2 Type II report?
- Yes. Planhat's trust page lists a SOC 2 Type II report: “SOC 2 Type II”
- Which security certifications does Planhat list?
- Planhat's trust page lists SOC 2 Type II and ISO 27001.
- When was Planhat's subprocessor list last checked?
- ClauseTrail last checked Planhat's subprocessor list on September 28, 2026. Lists are re-checked daily.
- How do I find out when Planhat adds or removes a subprocessor?
- ClauseTrail monitors Planhat's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.