1. Purpose
Every third party that touches the Spark platform or customer data is itself a piece of our security posture. This policy defines how SlashLogixx selects, contracts with, monitors, and offboards those parties.
2. Scope
Applies to any external service or company that processes, stores, transmits, hosts, or has logical access to customer data, production infrastructure, source code, or administrative tooling. The current public list is maintained on the Subprocessors page.
3. Customer Notification of Subprocessor Changes
- The public Subprocessors list is updated when a vendor is added, removed, or materially repurposed.
4. Monitoring
- Material vendor incidents are evaluated for customer impact under the Incident Response policy.
5. Concentration & Continuity
- Where reasonable, critical capabilities (compute, storage, identity, payments) maintain a documented secondary path or migration plan to mitigate single-vendor failure.
- Vendors that hold uniquely critical roles are explicitly tracked as key dependencies in the Business Continuity plan.
6. Offboarding
- When a vendor relationship ends, all SlashLogixx-issued credentials are revoked.
- The subprocessor list is updated and, where applicable, customers under DPA are notified.
7. AI Subprocessors
External AI providers that process customer data are treated as Restricted-data subprocessors. SlashLogixx selects AI providers that contractually commit not to train shared models on production traffic. The current AI subprocessor set is shown on the Subprocessors page.
8. Customer Veto
Customers under a signed DPA may, with notice, object to the use of a specific new subprocessor for their data. SlashLogixx will work in good faith to identify an alternative or, where no alternative exists, discuss the customer's options including termination per the master agreement.