Subprocessors & Data Infrastructure

The types of third-party providers that help Vistra deliver the Services, and how we manage them.

Last updated: 14 September 2026

1. Introduction

Vistra uses selected third-party service providers (“Subprocessors”) to help deliver, maintain, secure, and improve the Vistra platform.

These providers may process customer information only when necessary to provide specific services.

This document explains:

  • What subprocessors are
  • Why Vistra uses them
  • The categories of information they may process
  • How Vistra manages third-party service providers

2. What is a subprocessor?

A subprocessor is a third-party company engaged by Vistra that may process customer information while helping provide the Services.

Examples include providers supporting:

  • Cloud infrastructure
  • Data storage
  • Authentication
  • Payments
  • Communication
  • Analytics
  • Monitoring
  • Artificial intelligence features

Vistra remains responsible for ensuring subprocessors are subject to appropriate contractual and security obligations.

3. Subprocessor management

Before using third-party providers, Vistra considers factors including:

  • Security practices
  • Privacy protections
  • Reliability
  • Data handling procedures
  • Service requirements

Subprocessors are only granted access to information necessary for their specific function.

4. Current subprocessor categories

The exact providers used by Vistra may change as our infrastructure evolves.

The following categories describe the types of subprocessors that may support Vistra Services.

4.1 Cloud hosting and infrastructure providers

Purpose: to host and operate Vistra applications, databases, files, and supporting infrastructure.

Possible processing activities:

  • Application hosting
  • Database storage
  • File storage
  • Infrastructure operations
  • Backup support

Information processed may include:

  • Account information
  • Uploaded content
  • Reports
  • Technical information

4.2 Database and storage providers

Purpose: to securely store application data and user-generated content.

Processing may include:

  • Database operations
  • File storage
  • Data retrieval
  • Backup operations

Information processed may include:

  • User account data
  • Project information
  • Inspection records
  • Uploaded files

4.3 Authentication and identity providers

Purpose: to support secure account access.

Processing may include:

  • User authentication
  • Login management
  • Security verification

Information processed may include:

  • Email addresses
  • Account identifiers
  • Authentication information

4.4 Artificial intelligence service providers

Purpose: to provide optional AI-assisted features.

Processing may include:

  • Text generation
  • Content improvement
  • Classification
  • Documentation assistance
  • Image or information analysis where enabled

Information processed may include:

  • User prompts
  • Inspection notes
  • Uploaded information submitted through AI features

AI processing depends on:

  • Enabled features
  • Customer configuration
  • Applicable agreements

See our AI Usage Policy for how AI providers handle submitted information.

4.5 Payment processing providers

Purpose: to process subscription payments.

Payment providers may process:

  • Billing information
  • Transaction details
  • Payment verification information

Vistra does not store complete payment card details unless explicitly stated.

4.6 Analytics and monitoring providers

Purpose: to understand platform performance and improve user experience.

Processing may include:

  • Product usage information
  • Error information
  • Performance metrics
  • Technical information

4.7 Communication providers

Purpose: to provide service communications.

Processing may include:

  • Transactional emails
  • Account notifications
  • Support communications
  • Product updates

5. Data location

Customer information may be processed and stored in locations where Vistra and its service providers operate.

The location of stored data depends on:

  • Infrastructure configuration
  • Customer plan
  • Service provider availability
  • Applicable agreements

Where required, Vistra applies appropriate safeguards for international data transfers.

6. Customer data protection

Vistra requires subprocessors to maintain appropriate protections regarding customer information. These protections may include:

  • Confidentiality obligations
  • Access restrictions
  • Security controls
  • Privacy commitments
  • Contractual requirements

7. Customer responsibilities

Customers are responsible for:

  • Understanding their own compliance obligations
  • Configuring user permissions
  • Selecting appropriate information to upload
  • Ensuring lawful collection of customer data

Vistra provides tools to help manage information but does not determine customer compliance requirements.

8. Changes to subprocessors

As Vistra grows, we may add or replace subprocessors to:

  • Improve reliability
  • Improve security
  • Add functionality
  • Support new features

Material changes may be communicated through:

  • Website updates
  • Customer notifications
  • Contractual communication where required

9. Customer objection rights

Where required by applicable agreements or laws, customers may have the right to object to the appointment of certain subprocessors.

Any objection must:

  • Identify the specific concern
  • Provide reasonable justification
  • Be submitted through official communication channels

Vistra may evaluate alternatives where appropriate.

10. Security review

Vistra periodically reviews third-party services considering factors such as:

  • Security practices
  • Service reliability
  • Privacy requirements
  • Operational necessity

11. Additional security information

For more information about Vistra’s security practices, see:

12. Contact

For questions regarding subprocessors:

Questions about this policy? Contact us or email hello@vistra.report.