Skip to main content

BeneVets Sub-processor List

Effective date: July 4, 2026 Last updated: July 4, 2026 Version: 1.0


§ 1. In Plain English (Summary)

In plain English: A "sub-processor" is an outside company that handles personal information for us so we can run the Service. This document lists every outside company we use today, what they do for us, what data they touch, where they operate, and whether we have a Data Processing Agreement ("DPA") with them. We update this list when anything material changes. If a change is adverse to your privacy, we will publish the change at least 30 days in advance.


§ 2. Defined Terms

For purposes of this List:

  • "Personal Information" has the meaning set forth in Cal. Civ. Code § 1798.140(v) (West, 2024).
  • "Service Provider" has the meaning set forth in Cal. Civ. Code § 1798.140(ag): a person who processes Personal Information on behalf of a business and to whom the business discloses Personal Information for a business purpose pursuant to a written contract that meets the requirements of Cal. Civ. Code § 1798.100(d).
  • "Contractor" has the meaning set forth in Cal. Civ. Code § 1798.140(j): a person to whom a business makes available Personal Information for a business purpose pursuant to a written contract meeting the requirements of Cal. Civ. Code § 1798.100(d), and who is by definition not a Service Provider but is similarly constrained.
  • "Third Party" has the meaning set forth in Cal. Civ. Code § 1798.140(ai): a person who is not the business that collected the Personal Information from the consumer and not a Service Provider or Contractor.
  • "Sub-processor" is the umbrella term BeneVets uses in this List for Service Providers and Contractors. The U.S. Department of Veterans Affairs is identified in § 5 as a Third Party (federal data source), not a Sub-processor.

§ 3. BeneVets's Approach to Sub-processors

In plain English: Before we let an outside company handle data for us, we put a written contract in place that says what they can and cannot do with the data. We never let them use the data for their own purposes. We pick processors based in the United States whenever we can.

BeneVets engages each Sub-processor under a written Data Processing Agreement ("DPA") or comparable contractual instrument that meets the requirements of Cal. Civ. Code § 1798.100(d) and Cal. Code Regs. tit. 11, § 7051. Each DPA:

  1. Specifies the categories of Personal Information disclosed and the business purposes for which it may be processed.
  2. Prohibits the Sub-processor from selling or sharing the Personal Information.
  3. Prohibits the Sub-processor from retaining, using, or disclosing the Personal Information for any purpose other than the specific business purpose, including for the Sub-processor's commercial purpose other than providing the contracted service.
  4. Prohibits combining the Personal Information with data from any other source, except as expressly permitted under Cal. Civ. Code § 1798.140(ag)(1)(D) and Cal. Code Regs. tit. 11, § 7050(b).
  5. Requires the Sub-processor to assist BeneVets in complying with consumer privacy requests.
  6. Requires the Sub-processor to notify BeneVets if it can no longer meet its obligations.
  7. Permits BeneVets to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.

BeneVets selects U.S.-based Sub-processors whenever a U.S. option is reasonably available. Where a Sub-processor has global presence, BeneVets configures the service to keep data in the United States whenever the configuration is available.


§ 4. Current Sub-processor Inventory

In plain English: Here is the actual list of vendors that process information on BeneVets's behalf.

§ 4.1. Master Inventory Table

Sub-processorService providedData categoriesRegion (data residency)DPA statusLast reviewed
Vercel, Inc. (Delaware corp.; principal office San Francisco, CA)Hosting and edge compute for the Service; deployments; serverless functions; (potentially) Vercel Blob storageAll Personal Information processed by the Service during request handling and storage, including identifiers, customer records, professional/employment information, free-text content, and (if Vercel Blob is selected) ProfileVault contentsUnited States; underlying cloud provider varies by Vercel region - BeneVets pins to U.S. regions (iad1, sfo1, pdx1 as configured)DPA in place: Vercel Data Processing Addendum; signed 07/04/202607/04/2026
Resend (Resend.com, Inc.)Transactional email transmission; (potentially) marketing email transmission for the newsletter and donor email programEmail address; first/last name (recipient-rendered); transactional message content; bounce/delivery telemetryUnited StatesDPA in place: Resend DPA; signed 07/04/202607/04/2026
Functional Software, Inc. (dba Sentry)Application error monitoringIdentifiers (truncated source IP, account user ID); error stack traces; request metadata; user-agent string. PII scrubber configured; Replay disabled; trace sampling at 0 at v1United StatesDPA in place: Sentry DPA; signed 07/04/202607/04/2026
Google LLCOAuth identity federation (Google Sign-In)Email address; Google account identifier; (optionally) name and profile photo, only as transmitted by Google during OAuthUnited States and global (Google operates a global network; the OAuth identity-federation surface is U.S.-based)DPA in place: Google Cloud Data Processing Addendum, applicable to Google Identity Platform via Cloud Identity terms; signed 07/04/202607/04/2026
Google LLC (Google Analytics 4)Aggregate web analyticsTruncated IP; aggregate event data; client identifier (_ga); referrerUnited States (analytics property region pinned where supported); Google may transit data globally for service operationDPA in place: Google Analytics Data Processing Terms; signed 07/04/202607/04/2026
Vercel, Inc. (Vercel Blob)Storage for AES-256-GCM-encrypted ProfileVault envelopes and profile photosEncrypted DD-214 envelope contents (ciphertext only); profile photo blob; storage object identifiers and metadata. Encryption keys are not stored at the storage provider.United States (B2: U.S. regions; Vercel Blob: U.S. regions as configured)DPA pending: [choose vendor; sign DPA]07/04/2026 (target)
Anthropic, PBCLarge language model for benefit-content summarization. The model receives BeneVets-supplied source regulatory text and editor prompts only. The model does not receive user Personal Information at v1.At v1: source regulatory text and editor-supplied prompts only. No user Personal Information at v1.United StatesDPA pending: must include (a) no training on customer data, (b) U.S. data residency, (c) zero-day retention or short retention with no human review for abuse other than as required by law07/04/2026 (target)
Cloudflare, Inc.DNS; edge proxy; DDoS protection; possibly WAFTruncated source IP; request metadata; user-agent stringUnited States and globalDPA pending if engaged: Cloudflare DPA07/04/2026 (target)
Namecheap, Inc.Domain registration and DNS for benevets.org and related domainsDomain administrative metadata; whois proxy details. No user Personal Information.United StatesStandard registrar terms; data-residency limited to domain administration metadata07/04/2026
Vercel, Inc. (interim; long-term host under evaluation)Static hosting for the production apex page (presently the Namecheap cPanel-hosted under-construction page; production application hosting is via Vercel)None at the apex page stage; will be reviewed before any user-data collection moves to the apexUnited StatesVercel DPA in place07/04/2026

§ 4.2. Telemetry, ad-tech, and tracking - explicit non-engagements

To remove ambiguity, BeneVets discloses that the Service does NOT use the following classes of vendors at v1:

  • Programmatic advertising networks (e.g., Google Ad Manager, AdSense, The Trade Desk).
  • Retargeting / behavioral advertising networks (e.g., Meta Pixel, LinkedIn Insight Tag, X/Twitter Pixel, TikTok Pixel, Pinterest Tag).
  • Session replay tools (e.g., Hotjar, FullStory, LogRocket, Microsoft Clarity).
  • Customer data platforms with default ad-tech connectors (e.g., Segment with ad-network destinations enabled).
  • Browser fingerprinting libraries (e.g., FingerprintJS).
  • Data brokers (none, including no data brokers registered under Cal. Civ. Code § 1798.99.82).
  • Push-notification services (out of scope at v1).
  • Short Message Service ("SMS") gateways (reserved in documents; not active at v1).

§ 5. Third Parties (Not Sub-processors)

In plain English: Some entities receive personal information from BeneVets but are not our sub-processors. They receive the data because you authorize a specific transmission, or because the law requires us to disclose. The most important Third Party is the VA itself, which receives forms and supporting documents you authorize us to send.

The following recipients of Personal Information are Third Parties under Cal. Civ. Code § 1798.140(ai), not Sub-processors.

§ 5.1. U.S. Department of Veterans Affairs (VA Lighthouse APIs)

The U.S. Department of Veterans Affairs operates the VA Lighthouse APIs at developer.va.gov, including the Benefits Intake API, the Veteran Verification API, the Facilities API, and the Health API. VA is a federal agency. It is not a Sub-processor. VA is a federal data source from which BeneVets receives data on your authorization, and a federal data recipient to which BeneVets transmits forms and supporting documents on your pro se authorization.

VA's processing of data submitted via the Benefits Intake API is governed by VA's Privacy Act system-of-records notices and other federal authorities, not by BeneVets's DPAs. Submission to VA is the entire purpose of pro se form preparation.

BeneVets is not VA's representative. BeneVets is not accredited under 38 C.F.R. § 14.629. BeneVets does not hold itself out as the user's representative.

§ 5.2. Lawful-process recipients

BeneVets may disclose Personal Information in response to lawful process (subpoena, court order, search warrant) or to defend BeneVets's legal interests. BeneVets requires legal process for any disclosure to law enforcement absent a good-faith belief that disclosure is necessary to prevent imminent harm to life.

§ 5.3. Helpers

A Helper is a person granted access to a user's account via the account-linking flow. A Helper receives the data the user authorizes the Helper to see. BeneVets does not consider Helpers Sub-processors of BeneVets because Helpers act for the user, not for BeneVets. Helper relationships are granular, revocable, and audit-logged. See Document 07 (Helper / Account-Linking Terms) for the controlling terms.


§ 6. Regional Residency Statement

In plain English: We pick U.S.-based options when we can. Google has a global network, but the parts of Google we use are configured for U.S. processing. We will tell you in this list if anything material changes about where data lives.

For each Sub-processor in § 4.1 that operates globally, BeneVets has configured the service to use U.S. regions where the configuration is available:

  • Vercel, Inc. Deployments pinned to U.S. regions (iad1, sfo1, pdx1).
  • Google LLC (OAuth and GA4). GA4 property region pinned to U.S. where supported. The OAuth identity-federation surface routes to U.S. Google identity infrastructure. Google may transit data globally as inherent in its global service operation.
  • Cloudflare, Inc. If engaged, U.S.-only routing will be evaluated; Cloudflare's global edge network is by design global, but BeneVets will configure tiering to U.S.-first.
  • Backblaze, Inc. B2 U.S. regions (West, East).
  • Vercel Blob. U.S. regions as configured.
  • Anthropic, PBC / OpenAI, Inc. DPA will require U.S. data residency as a contract term.

No Sub-processor at v1 transfers Personal Information outside the United States as part of its routine operation. Should that change, BeneVets will update this List and disclose the destination jurisdictions and the legal mechanism relied upon (e.g., contractual safeguards, where applicable).


§ 7. Update Commitment

In plain English: This list will change as we add or change vendors. We will keep it current. If a change is adverse to your privacy, we will publish the change at least 30 days before it takes effect.

BeneVets commits to maintaining this List as a current inventory of Sub-processors. Updates occur as follows:

  1. Adverse changes. Material changes that are adverse to user privacy (for example, adding a new Sub-processor that handles Sensitive Personal Information, or moving data to a non-U.S. region) will be published at least thirty (30) days before the change takes effect. Account holders will receive notice by email.
  2. Non-adverse changes. Other material changes (renaming a Sub-processor, adding a non-Sub-processor disclosure that does not affect user data flow, adding a Sub-processor whose addition reduces data exposure) will be published promptly and reflected in the "Last updated" date.
  3. Routine review. BeneVets reviews each Sub-processor at least annually to confirm continued necessity, configuration, and DPA status, and to refresh the "Last reviewed" entry in the table.

§ 8. How to Object to a New Sub-processor

In plain English: If we add a new sub-processor and you do not want your data processed by that company, you can close your account and ask us to delete your information before the new processor goes live, with no penalty.

In addition to the standard Right to Delete described in §§ 15-22 of the Privacy Policy (Document 02), BeneVets honors a specific objection procedure for adverse Sub-processor changes:

  1. Within the thirty (30) day pre-publication notice window for an adverse change, you may email privacy@benevets.org with the subject line "Sub-processor Objection."
  2. BeneVets will treat the objection as a Right to Delete request and will delete your account and Personal Information before the new Sub-processor goes live.
  3. No fee, penalty, or other adverse consequence will follow from the objection. The Right to Non-Discrimination under Cal. Civ. Code § 1798.125 applies.

§ 9. Changes to this List

In plain English: The "Last updated" date at the top reflects when we last changed anything. The publication mechanism is described in § 7.

BeneVets may amend this List from time to time as described in § 7. The "Last updated" date at the top of this List reflects the most recent revision.


§ 10. Contact

In plain English: Email privacy@benevets.org with any sub-processor question.

For sub-processor-related questions or objections:

  • Email: privacy@benevets.org
  • Postal mail: BeneVets, Inc. Attn: Privacy Officer 1441 Pomona Road, Suite 20 Corona, CA 92882

§ 11. Cross-References

This List is part of an integrated document set. It cross-references and is cross-referenced by:

  • Document 02 - Privacy Policy (controlling document for all privacy matters)
  • Document 03 - Cookie Notice (identifies Google Analytics 4 and the BeneVets first-party telemetry)
  • Document 13 - Security and Vulnerability Disclosure Policy
  • Document 14 - Data Retention Schedule
  • Document 15 - Automated Decision-Making and AI Notice (covers the LLM provider Sub-processor)

End of Sub-processor List.