Temporal Subprocessors List (September 2026): Changes and History
Temporal names 7 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Temporal subprocessors (September 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Auth0 | Authentication | United States |
| 2 | AWS | Infrastructure for Namespaces that customers decide to host in Amazon Web Services. Control plane. | Customer-Defined Jurisdiction |
| 3 | Elastic | Visibility, monitoring and analysis of business and operational data for Namespaces hosted in Google Cloud or Microsoft Azure. | Customer-Defined Jurisdictions (Optional) |
| 4 | Google Cloud | Infrastructure for Namespaces that customers decide to host in Google Cloud. | Customer-Defined Jurisdictions (Optional) |
| 5 | IBM | Datastax Database | Customer-Defined Jurisdictions |
| 6 | Microsoft Azure | Infrastructure for Namespaces that customers decide to host in Microsoft Azure. | Customer-Defined Jurisdictions (Optional) |
| 7 | WorkOS | Customer identity and access management platform | United States |
Get an email when Temporal changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Temporal
What Temporal's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“Temporal will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Customer Personal Data.”
DPA, temporal.io ↗ - Notice of a new subprocessor
-
15 days ahead
“Customer may object in writing to the use of any new Subprocessor within fifteen (15) days of the publishing of a new Subprocessor list, provided that the written objection includes reasonable grounds for the objection.”
DPA, temporal.io ↗ - Transfers outside the EU
-
Standard contractual clauses and adequacy decisions
“By signing this DPA, Customer and Temporal conclude Module 2 (controller-toprocessor) of the Standard Contractual Clauses”
“Customer hereby authorizes Temporal to perform International Data Transfers to any country deemed adequate by the European Commission or the competent authorities”
DPA, temporal.io ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“All customer data is deleted upon contract termination.”
DPA, temporal.io ↗ - Liability cap
-
Fees paid or payable in the 12 months preceding the claim
“TEMPORAL'S LIABILITY FOR ALL CLAIMS ARISING UNDER THIS DPA, WHETHER IN CONTRACT, TORT OR OTHERWISE, SHALL NOT EXCEED THE AMOUNT OF FEES PAID OR PAYABLE BY CUSTOMER UNDER THE AGREEMENT DURING THE TWELVE (12) MONTH PERIOD PRECEEDING THE CLAIM.”
DPA, temporal.io ↗ - Audit rights
-
Once a year
“will be subject to Customer giving reasonable prior written notice to Temporal, and not conducted more than once per calendar year”
DPA, temporal.io ↗
Documents we track for Temporal
- DPA
- checked September 28, 2026 temporal.io ↗
- Privacy policy
- checked September 28, 2026 trust.temporal.io ↗
- Subprocessor list
- checked September 28, 2026 trust.temporal.io ↗
- Terms of service
- checked September 28, 2026 temporal.io ↗
- Trust page
- checked September 28, 2026 temporal.io ↗
Change history
Tracking since September 28, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Temporal subprocessors FAQ
- How many subprocessors does Temporal use?
- Temporal lists 7 subprocessors on its published list, including Auth0, AWS, Elastic, Google Cloud, and IBM and 2 more.
- Where does Temporal process customer data?
- The subprocessors named by Temporal are located in Customer-Defined Jurisdictions (Optional), United States, Customer-Defined Jurisdiction, and Customer-Defined Jurisdictions, as stated on its list.
- How quickly does Temporal report a personal data breach to customers?
- According to its DPA, Temporal reports a personal data breach to customers without undue delay, with no set deadline: “Temporal will notify Customer without undue delay after becoming aware of a Personal Data Breach involving Customer Personal Data.”
- How much notice does Temporal give before adding a subprocessor?
- Temporal's DPA gives 15 days' notice of a new subprocessor, the time customers have to object: “Customer may object in writing to the use of any new Subprocessor within fifteen (15) days of the publishing of a new Subprocessor list, provided that the written objection includes reasonable grounds for the objection.”
- How does Temporal transfer personal data outside the EU?
- Temporal's DPA relies on standard contractual clauses and adequacy decisions: “By signing this DPA, Customer and Temporal conclude Module 2 (controller-toprocessor) of the Standard Contractual Clauses”
- When was Temporal's subprocessor list last checked?
- ClauseTrail last checked Temporal's subprocessor list on September 28, 2026. Lists are re-checked daily.
- How do I find out when Temporal adds or removes a subprocessor?
- ClauseTrail monitors Temporal's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.