Subprocessors & Data Infrastructure
The types of third-party providers that help Vistra deliver the Services, and how we manage them.
Last updated: 14 September 2026
1. Introduction
Vistra uses selected third-party service providers (“Subprocessors”) to help deliver, maintain, secure, and improve the Vistra platform.
These providers may process customer information only when necessary to provide specific services.
This document explains:
- What subprocessors are
- Why Vistra uses them
- The categories of information they may process
- How Vistra manages third-party service providers
2. What is a subprocessor?
A subprocessor is a third-party company engaged by Vistra that may process customer information while helping provide the Services.
Examples include providers supporting:
- Cloud infrastructure
- Data storage
- Authentication
- Payments
- Communication
- Analytics
- Monitoring
- Artificial intelligence features
Vistra remains responsible for ensuring subprocessors are subject to appropriate contractual and security obligations.
3. Subprocessor management
Before using third-party providers, Vistra considers factors including:
- Security practices
- Privacy protections
- Reliability
- Data handling procedures
- Service requirements
Subprocessors are only granted access to information necessary for their specific function.
4. Current subprocessor categories
The exact providers used by Vistra may change as our infrastructure evolves.
The following categories describe the types of subprocessors that may support Vistra Services.
4.1 Cloud hosting and infrastructure providers
Purpose: to host and operate Vistra applications, databases, files, and supporting infrastructure.
Possible processing activities:
- Application hosting
- Database storage
- File storage
- Infrastructure operations
- Backup support
Information processed may include:
- Account information
- Uploaded content
- Reports
- Technical information
4.2 Database and storage providers
Purpose: to securely store application data and user-generated content.
Processing may include:
- Database operations
- File storage
- Data retrieval
- Backup operations
Information processed may include:
- User account data
- Project information
- Inspection records
- Uploaded files
4.3 Authentication and identity providers
Purpose: to support secure account access.
Processing may include:
- User authentication
- Login management
- Security verification
Information processed may include:
- Email addresses
- Account identifiers
- Authentication information
4.4 Artificial intelligence service providers
Purpose: to provide optional AI-assisted features.
Processing may include:
- Text generation
- Content improvement
- Classification
- Documentation assistance
- Image or information analysis where enabled
Information processed may include:
- User prompts
- Inspection notes
- Uploaded information submitted through AI features
AI processing depends on:
- Enabled features
- Customer configuration
- Applicable agreements
See our AI Usage Policy for how AI providers handle submitted information.
4.5 Payment processing providers
Purpose: to process subscription payments.
Payment providers may process:
- Billing information
- Transaction details
- Payment verification information
Vistra does not store complete payment card details unless explicitly stated.
4.6 Analytics and monitoring providers
Purpose: to understand platform performance and improve user experience.
Processing may include:
- Product usage information
- Error information
- Performance metrics
- Technical information
4.7 Communication providers
Purpose: to provide service communications.
Processing may include:
- Transactional emails
- Account notifications
- Support communications
- Product updates
5. Data location
Customer information may be processed and stored in locations where Vistra and its service providers operate.
The location of stored data depends on:
- Infrastructure configuration
- Customer plan
- Service provider availability
- Applicable agreements
Where required, Vistra applies appropriate safeguards for international data transfers.
6. Customer data protection
Vistra requires subprocessors to maintain appropriate protections regarding customer information. These protections may include:
- Confidentiality obligations
- Access restrictions
- Security controls
- Privacy commitments
- Contractual requirements
7. Customer responsibilities
Customers are responsible for:
- Understanding their own compliance obligations
- Configuring user permissions
- Selecting appropriate information to upload
- Ensuring lawful collection of customer data
Vistra provides tools to help manage information but does not determine customer compliance requirements.
8. Changes to subprocessors
As Vistra grows, we may add or replace subprocessors to:
- Improve reliability
- Improve security
- Add functionality
- Support new features
Material changes may be communicated through:
- Website updates
- Customer notifications
- Contractual communication where required
9. Customer objection rights
Where required by applicable agreements or laws, customers may have the right to object to the appointment of certain subprocessors.
Any objection must:
- Identify the specific concern
- Provide reasonable justification
- Be submitted through official communication channels
Vistra may evaluate alternatives where appropriate.
10. Security review
Vistra periodically reviews third-party services considering factors such as:
- Security practices
- Service reliability
- Privacy requirements
- Operational necessity
11. Additional security information
For more information about Vistra’s security practices, see:
12. Contact
For questions regarding subprocessors:
- Privacy email: hello@vistra.report
- Security email: hello@vistra.report
- Company: Vistra
- Website: https://www.vistra.report/
Questions about this policy? Contact us or email hello@vistra.report.