Overview
OptimReach engages the following sub-processors to deliver its platform. All sub-processors are bound by data processing agreements that provide data protection standards no less protective than those in our DPA.
For sub-processor change notifications or objections, contact privacy_optimreach@metagrad.in.
Core Platform Sub-processors
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Message delivery, WhatsApp Business Cloud API | Message content, customer phone numbers, delivery metadata |
| Google LLC | OAuth sign-in and Google integrations you enable (Sheets, Calendar, Contacts, Gmail, RCS) | Google account and service data you explicitly authorize |
| Cloudflare | Hosting, media storage (R2) and CDN | Workspace data, media files |
| Payment processor (PCI-DSS compliant) | Subscription billing | Billing details — full card data handled directly by the processor |
How to Object to a New Sub-processor
We will notify customers at least 14 days before engaging a new sub-processor. You may object within that period by emailing privacy_optimreach@metagrad.in with your reasons. We will work with you to address the objection or provide an alternative.
What "Sub-processor" Does NOT Include
- Infrastructure tools that do not access Customer Personal Data (e.g., monitoring tools that only see aggregate metrics)
- Your own third-party integrations configured within OptimReach (e.g., your CRM, your Zapier account) — you are the Controller for those connections and responsible for their compliance
Questions about this document? Email hello_optimreach@metagrad.in or reach us via the contact page.
