Transistor Subprocessors List (September 2026): Changes and History
Transistor names 11 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Transistor subprocessors (September 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Amazon Web Services, Inc. | Application hosting; RDS PostgreSQL database storing account and podcast data | United States |
| 2 | Cloudflare, Inc. | CDN, DNS, DDoS protection, and R2 object storage for podcast media | United States, global edge network |
| 3 | DigitalOcean, LLC | Object storage (Spaces) for static assets and images | United States |
| 4 | Stripe, Inc. | Payment processing, subscription billing, and fraud prevention. Card data is handled by Stripe and never stored on Transistor servers. | United States, Ireland |
| 5 | Twilio Inc. (SendGrid) | Sending transactional and account email | United States |
| 6 | Userlist, Inc. | Sending onboarding messages | United States |
| 7 | Crisp IM SAS | Customer support ticketing and conversation history | France (EU) |
| 8 | Deepgram, Inc. | AI transcription of uploaded audio and video | United States |
| 9 | Conva Ventures Inc. (Fathom Analytics) | Product usage analytics | Canada |
| 10 | Honeybadger Industries LLC | Error and crash monitoring | United States |
| 11 | iubenda s.r.l. | Hosting of privacy policy and cookie consent management on transistor.fm | Italy (EU) |
Get an email when Transistor changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Transistor
What Transistor's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Without undue delay, with no set deadline
“Transistor will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.”
DPA, transistor.fm ↗ - Notice of a new subprocessor
-
30 days ahead
“give at least thirty (30) days' notice of any intended addition or replacement of a Sub-processor”
DPA, transistor.fm ↗ - Transfers outside the EU
-
Standard contractual clauses
“The SCCs are incorporated into this DPA by reference and constitute the transfer mechanism for such transfers.”
DPA, transistor.fm ↗ - Customer data after the contract ends
-
Deleted within 90 days of the contract ending
“Transistor will delete the Personal Data within ninety (90) days of termination”
DPA, transistor.fm ↗ - Audit rights
-
Once a year
“limited to once per twelve (12) month period unless required by a supervisory authority or following a Personal Data Breach”
DPA, transistor.fm ↗
Certifications at Transistor
What Transistor's trust page lists, with the text each one comes from.
- ISO 27001
-
Active
“Do you maintain any security certifications such as SOC 2 or ISO 27001?”
Trust page, transistor.fm ↗
Documents we track for Transistor
- DPA
- checked September 28, 2026 transistor.fm ↗
- Privacy policy
- checked September 28, 2026 transistor.fm ↗
- Subprocessor list
- checked September 28, 2026 transistor.fm ↗
- Terms of service
- checked September 28, 2026 transistor.fm ↗
- Trust page
- checked September 28, 2026 transistor.fm ↗
Change history
Tracking since September 28, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Transistor subprocessors FAQ
- How many subprocessors does Transistor use?
- Transistor lists 11 subprocessors on its published list, including Amazon Web Services, Inc., Cloudflare, Inc., DigitalOcean, LLC, Stripe, Inc., and Twilio Inc. (SendGrid) and 6 more.
- Where does Transistor process customer data?
- The subprocessors named by Transistor are located in United States, Canada, France (EU), Ireland, Italy (EU), and global edge network, as stated on its list.
- How quickly does Transistor report a personal data breach to customers?
- According to its DPA, Transistor reports a personal data breach to customers without undue delay, with no set deadline: “Transistor will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.”
- How much notice does Transistor give before adding a subprocessor?
- Transistor's DPA gives 30 days' notice of a new subprocessor, the time customers have to object: “give at least thirty (30) days' notice of any intended addition or replacement of a Sub-processor”
- How does Transistor transfer personal data outside the EU?
- Transistor's DPA relies on standard contractual clauses: “The SCCs are incorporated into this DPA by reference and constitute the transfer mechanism for such transfers.”
- Which security certifications does Transistor list?
- Transistor's trust page lists ISO 27001.
- When was Transistor's subprocessor list last checked?
- ClauseTrail last checked Transistor's subprocessor list on September 28, 2026. Lists are re-checked daily.
- How do I find out when Transistor adds or removes a subprocessor?
- ClauseTrail monitors Transistor's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.