Skip to content

Sub-processor register

Who touches your information, who does not, and how we know.

Every company that processes personal information for Futureful, what each one receives, and the services that receive none. Derived by enumerating every outbound request our servers make, and held there by a check that fails our build when a new one appears.

Effective

Derived, not remembered

Nineteen external services enumerated from the code, each one read to decide whether personal information reaches it. A build check fails if a new one appears in neither list.

The negative list too

Most registers publish only who receives your data. The useful half is who does not, and why, so that half is published here as well.

And what we cannot produce

No executed data agreement, no NIST attestation, no VPAT, no residency warranty. Each is a program to run, not a page to write, and pretending otherwise is worse than the gap.

01

What this register is, and how it is built

02

The register

03

AI models, retention and training

04

Services that receive no personal information

05

Connections you make yourself

06

What we do not have yet

07

How this page changes

08

Reaching a person

FUTUREFUL · SUB-PROCESSOR REGISTER · REV A