Sub-Processor List
Processor: Empathy Works Inc. (operating the Orbit platform)
Last Updated: March 23, 2026
This document lists the sub-processors engaged by Empathy Works Inc. to process personal data on behalf of Organizations using the Orbit platform. This list is maintained in accordance with GDPR Article 28 requirements and the Data Processing Agreement between the Platform and each Organization.
Organizations are notified of changes to this list in accordance with the DPA. If you have questions, contact privacy@orbitams.com.
Active Sub-Processors
| Sub-Processor | Purpose | Data Processed | Location | Compliance |
|---|---|---|---|---|
| Amazon Web Services (via Heroku) | Application hosting, database | All application data (account info, membership records, event data, analytics) | United States | SOC 2 Type II, ISO 27001, CSA STAR |
| Stripe, Inc. | Payment processing | Email, name, payment card details (tokenized), transaction amounts, billing metadata | United States | PCI DSS Level 1, SOC 2 Type II |
| Cloudflare, Inc. | CDN, file storage (R2), DDoS protection | Uploaded files (images, documents, videos), traffic data | United States (R2: US East) | SOC 2 Type II, ISO 27001 |
| Wildbit LLC (Postmark) | Transactional and marketing email delivery | Email addresses, email content, delivery/engagement metadata | United States | SOC 2 Type II |
| Zoom Video Communications, Inc. | Virtual event hosting | Registrant name, email, organization, job title (for Zoom-integrated events only) | United States | SOC 2 Type II, ISO 27001 |
| Google LLC | OAuth authentication (optional) | Email address, name (for Google sign-in only) | United States | SOC 2 Type II, ISO 27001 |
Optional Sub-Processors
The following sub-processors are only engaged when the corresponding feature is enabled by the Organization:
| Sub-Processor | Purpose | Data Processed | Location | Compliance | Feature |
|---|---|---|---|---|---|
| OpenAI, Inc. | AI-assisted data import | Content submitted for structured import (admin-initiated) | United States | SOC 2 Type II | AI Import |
| CloudConvert GmbH | Document thumbnail generation | Document files (via public URL) | Germany (EU) | GDPR compliant | Resource thumbnails |
| Cloudflare Stream | Video transcoding and delivery | Video files, video metadata | United States | SOC 2 Type II, ISO 27001 | Video hosting |
| Unsplash, Inc. | Stock photo search and selection | Search queries only (no personal data) | United States | N/A (no personal data) | Image picker |
| MaxMind, Inc. | Country-level geolocation | IP addresses (processed locally, not sent to MaxMind servers) | N/A (local database) | N/A (local processing) | Analytics geolocation |
Sub-Processors Used by Tenant-Configured Integrations
Organizations may configure their own third-party integrations. These are not sub-processors of Empathy Works Inc.; they are engaged directly by the Organization:
| Integration | Purpose | Notes |
|---|---|---|
| Custom OAuth2/OIDC Provider | Single sign-on authentication | Configured per-Organization; provider chosen by Organization |
| LMS Providers (Docebo, TalentLMS, LearnDash) | External learning management | Configured per-Organization; data sharing determined by Organization |
Change Notification Process
- Empathy Works Inc. will update this list when sub-processors are added, removed, or replaced
- Organizations will be notified of material changes via email to the administrative contact on file
- Organizations may object to a new sub-processor within 30 days of notification
- If an objection cannot be reasonably resolved, the Organization may terminate the Service agreement in accordance with the DPA
Contact
For questions about this sub-processor list or to report concerns:
Empathy Works Inc.
- Email: privacy@orbitams.com
- Address: 329 Howe St, Unit #540, Vancouver, BC, V6C 3N2, Canada