Postmark Subprocessors List (October 2026): Changes and History
Postmark names 3 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Postmark subprocessors (October 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Deft (formerly known as ServerCentral) | Infrastructure hosting | — |
| 2 | Amazon Web Services | Cloud infrastructure hosting | — |
| 3 | Zendesk | Help desk software to communicate with our customers | — |
Get an email when Postmark changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Postmark
What Postmark's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“AC PM will take commercially reasonable efforts to, without undue delay: (a) notify User of the Security Breach and any third-party legal processes relating to the Security Breach”
DPA, postmarkapp.com ↗ - Notice of a new subprocessor
-
7 days ahead
“If within 7 days of AC PM notifying User, User does not notify AC PM in writing of any objections (on reasonable grounds relating to the protection of Personal Information) to the appointment, it will be deemed that User has consented to the appointment.”
DPA, postmarkapp.com ↗ - Transfers outside the EU
-
Standard contractual clauses, the EU–US Data Privacy Framework, binding corporate rules, and adequacy decisions
“any regulated data transfer to a country not subject to an adequacy decision will be conducted pursuant to the Standard Contractual Clauses promulgated by the European Commission Decision 2021/914/EU under Module Two (transfer controller to processor)”
“AC PM has certified its compliance to the EU-U.S. Data Privacy Framework Principles, including as applied under the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework Principles (collectively, the "DPF Principles") with the U.S. Department of Commerce”
“through the use of other legally recognized validation methods such as Standard Contractual Clauses or Binding Corporate Rules.”
“that are recognized by the European Commission as providing an adequate level of protection for Personal Information”
DPA, postmarkapp.com ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“Upon termination of the Terms and written request by User, AC PM will return all Personal Information to User or destroy all Personal Information and all copies thereof (excluding any backup or archival copies which will be deleted in accordance with AC PM's data retention schedule), except to the extent that AC PM is required or allowed by Data Protection Laws to keep a copy of Personal Information for a specified period of time.”
DPA, postmarkapp.com ↗ - Audit rights
-
Once a year
“User may request Audit Information up to once per year.”
DPA, postmarkapp.com ↗
Documents we track for Postmark
- DPA
- checked October 6, 2026 postmarkapp.com ↗
- Subprocessor list
- checked October 6, 2026 postmarkapp.com ↗
- Terms of service
- checked October 6, 2026 postmarkapp.com ↗
- Trust page
- checked October 6, 2026 postmarkapp.com ↗
Change history
Tracking since October 6, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Postmark subprocessors FAQ
- How many subprocessors does Postmark use?
- Postmark lists 3 subprocessors on its published list, including Deft (formerly known as ServerCentral), Amazon Web Services, and Zendesk.
- How quickly does Postmark report a personal data breach to customers?
- According to its DPA, Postmark reports a personal data breach to customers without undue delay, with no set deadline: “AC PM will take commercially reasonable efforts to, without undue delay: (a) notify User of the Security Breach and any third-party legal processes relating to the Security Breach”
- How much notice does Postmark give before adding a subprocessor?
- Postmark's DPA gives 7 days' notice of a new subprocessor, the time customers have to object: “If within 7 days of AC PM notifying User, User does not notify AC PM in writing of any objections (on reasonable grounds relating to the protection of Personal Information) to the appointment, it will be deemed that User has consented to the appointment.”
- How does Postmark transfer personal data outside the EU?
- Postmark's DPA relies on standard contractual clauses, the EU–US Data Privacy Framework, binding corporate rules, and adequacy decisions: “any regulated data transfer to a country not subject to an adequacy decision will be conducted pursuant to the Standard Contractual Clauses promulgated by the European Commission Decision 2021/914/EU under Module Two (transfer controller to processor)”
- When was Postmark's subprocessor list last checked?
- ClauseTrail last checked Postmark's subprocessor list on October 6, 2026. Lists are re-checked daily.
- How do I find out when Postmark adds or removes a subprocessor?
- ClauseTrail monitors Postmark's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.