Last Updated: August 26, 2026
F&D Ventures LLC, doing business as Tormano (“Tormano”), engages the third-party subprocessors listed below to deliver the Tormano CRM service. This list is maintained in accordance with Article 28 of the GDPR and the corresponding provisions in our Data Processing Agreement and Privacy Policy.
Before we engage a new subprocessor to process Customer Personal Data, we email you at least 30 days before it begins processing, naming the specific subprocessor being added. That email goes to your account Owner’s address and to every address on the notification list. At the same time we publish the change in the table above, revise the “Last Updated” date, and add a dated entry to the Change History below, so you can confirm what changed and when. We do not treat publishing this page as a substitute for telling you, and you do not have to watch this page to be notified. To add an address to the notification list, or remove one, email privacy@tormano.com with the subject line “Subprocessor Notifications”. If your organization has accepted our Data Processing Agreement, Section 6.3 of it gives you 30 days from that notice to object, and sets out what happens if we cannot accommodate your objection.
The following subprocessors are engaged as of the date above. We select them on the security and privacy posture each one publishes, and we engage each of them under the standard terms that provider publishes and that we accepted when we opened our account. The Compliance column records the certifications and audit reports each provider publishes about itself.
We would rather you knew exactly what that does and does not mean. The entries in the Compliance column are each provider’s own published claim, repeated here so you can evaluate it; they are not statements that Tormano has verified them. We have not negotiated or executed a separate, signed data processing agreement with any subprocessor on this list, and we have not obtained or reviewed a copy of any subprocessor’s audit report. Several of these providers incorporate data processing terms into the standard online terms we accepted, which would make those terms binding on them by acceptance rather than by signature — but we have not established that provider by provider, and we will not describe it as established until we have. Closing this gap is an open item we are working through, not one we have finished.
If you need the data processing terms for a particular subprocessor — for your own record, an audit, or a security review — email privacy@tormano.com naming the provider. We will tell you precisely what is in place for that provider today, send you what we hold, and where terms are not yet in place we will say so and pursue them with that provider. Our own commitments to you about how we handle your data are in our Data Processing Agreement, and under Section 6.5 of it we remain fully liable to you for a subprocessor’s failure to meet its data protection obligations.
| Subprocessor | Purpose | Location | Compliance (the provider’s own published claim — not verified by Tormano, for any row) |
|---|---|---|---|
| Hetzner Cloud (Hetzner Online GmbH) | Server hosting, virtual machines, network. Holds all customer data at rest | United States — Ashburn, Virginia. All customer data at rest is in Ashburn. No customer data is stored in Hetzner’s European locations | ISO 27001 — Hetzner’s certificate scope names its Nuremberg, Falkenstein and Helsinki sites and does not cover Ashburn. Hetzner does not publish a SOC 2 report |
| Backblaze B2 | Encrypted database backups, file storage | United States | SOC 2 Type II |
| Stripe | Payment processing for paid plans, subscriptions and donations — engaged when an organization purchases a paid plan or accepts payments through the Service; no data is sent to Stripe at signup or during a free trial. Where an organization connects its own Stripe account, that organization is the merchant of record for donations and payments it accepts and Stripe acts as that organization’s own payment processor under its agreement with Stripe | United States | PCI DSS Level 1, SOC 1/2 |
| SendGrid (Twilio) | Transactional and campaign email delivery | United States | SOC 2 Type II |
| Twilio | Inbound text messages to our registered number and the automated HELP, STOP and START keyword replies. Tormano does not send outbound text messages, and no longer places, receives or records voice calls | United States | SOC 2 Type II, HIPAA eligible |
| Meta Platforms, Inc. | WhatsApp Business Platform (Cloud API). Customer-initiated: engaged only if your organization connects its own Meta Business account, and then it receives the WhatsApp message content and the recipient’s phone number | United States | Governed by the Meta Business Tools Terms and the WhatsApp Business Solution Terms you accept with Meta directly |
| Anthropic | AI-powered features (Claude API) | United States | SOC 2 Type II, GDPR compliant |
| OpenAI | AI-powered features (GPT API, fallback) | United States | SOC 2 Type II, GDPR compliant |
| Sentry | Error tracking and performance monitoring (PII-scrubbed before transmission) | United States | SOC 2 Type II, GDPR compliant |
| Cloudflare Turnstile | Bot protection on public forms | United States | SOC 2 Type II, GDPR compliant |
| Mapbox | Address geocoding for the contact map view: both the scheduled batch geocoder and the on-demand map send contact addresses to Mapbox | United States | SOC 2 Type II |
| People Data Labs | Optional contact enrichment. Engaged only if your organization connects its own People Data Labs API key, and then it receives a contact’s email address and nothing else from your records | United States | SOC 2 Type II |
| Hunter.io | Optional contact enrichment. Engaged only if your organization connects its own Hunter.io API key. It is the one enrichment provider that receives more than an email address: it receives a contact’s email address, to check whether that address is deliverable, and separately a company’s web domain, to look that company up. It is also the only one engaged for company records, where a domain is sent and no email address is | Not established — see Data Residency below | No published certification identified; governed by your organization’s own agreement with the provider |
| Apollo.io | Optional contact enrichment. Engaged only if your organization connects its own Apollo.io API key, and then it receives a contact’s email address and nothing else from your records. We do not ask Apollo.io to reveal personal email addresses or telephone numbers | Not established — see Data Residency below | No published certification identified; governed by your organization’s own agreement with the provider |
| Lusha | Optional contact enrichment. Engaged only if your organization connects its own Lusha API key, and then it receives a contact’s email address and nothing else from your records | Not established — see Data Residency below | No published certification identified; governed by your organization’s own agreement with the provider |
| Intuit QuickBooks | Customer-initiated accounting integration | United States | SOC 2 Type II |
| Xero | Customer-initiated accounting integration | New Zealand / United States | SOC 2 Type II |
| Google Workspace | Customer-initiated email and calendar OAuth integration | United States | SOC 2 Type II, ISO 27001 |
| Microsoft 365 (Microsoft Graph) | Customer-initiated email and calendar OAuth integration | United States | SOC 2 Type II, ISO 27001 |
| Slack (Salesforce) | Customer-initiated team-notifications integration | United States | SOC 2 Type II, ISO 27001 |
| Intuit Mailchimp | Customer-initiated marketing-email sync. Receives contact names, email addresses and subscription state | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Constant Contact, Inc. | Customer-initiated marketing-email sync. Receives contact names, email addresses and subscription state | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Eventbrite, Inc. | Customer-initiated event sync. Receives and returns attendee names, email addresses and ticket data | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Calendly LLC | Customer-initiated scheduling. Receives and returns invitee names, email addresses and meeting times | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Zoom Communications, Inc. | Customer-initiated video meetings. Receives meeting metadata and participant identifiers, and returns recordings or transcripts where your organization enables them | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Zapier, Inc. | Customer-initiated automation through the public Zapier directory. Receives whatever records your organization’s own Zap is configured to move | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Double the Donation (360MatchPro) | Customer-initiated matching-gift screening. Engaged only if your organization connects its own Double the Donation account, and then, for each online gift it registers, it receives the donor’s first and last name, email address, telephone number and full mailing address, together with the gift amount, date, campaign name, payment identifier, and the employer the donor selected or typed into the employer-lookup field on the donation form. Gifts marked anonymous are never registered | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Google Sheets (Google LLC) | Customer-initiated spreadsheet export and sync. Receives whatever records your organization configures the sync to write | United States | No published certification identified; governed by your organization’s own agreement with the provider |
| Microsoft Teams (Microsoft Corporation) | Customer-initiated team notifications. Receives notification content and channel identifiers | United States | No published certification identified; governed by your organization’s own agreement with the provider |
The services below are used by Tormano but are not sub-processors: they are either public bodies publishing open data, or services that receive no Customer Personal Data at all. There is no data processing agreement behind a public-records API, and we would rather name them here than let their absence imply nothing is sent.
Some integrations are activated only when a customer connects their own account through OAuth or an API key: Intuit QuickBooks, Xero, Google Workspace, Google Sheets, Microsoft 365, Microsoft Teams, Slack, Mailchimp, Constant Contact, Eventbrite, Calendly, Zoom, Zapier, Double the Donation (360MatchPro), and Meta Platforms’ WhatsApp Business Platform. Every one of them is listed in the table above, because once connected each receives personal data from Tormano, and a subprocessor you cannot see is a subprocessor you cannot object to under Section 6.3 of our Data Processing Agreement. Being customer-initiated changes when a provider is engaged; it does not change whether it belongs on this list. Tormano does not receive or process data from these services unless and until the customer initiates the integration, and each is additionally governed by that provider’s own privacy policy and terms of service. Zapier became available through the public Zapier directory in July 2026. PayPal is not currently enabled; if we enable it in the future as a payment sub-processor (which would make Tormano a recipient of donor payment information), we will add it to the table above and provide the advance notice described on this page before it begins processing personal data.
Tormano’s production data store and application servers are hosted in a Hetzner Cloud data center in the United States (Ashburn, Virginia). All customer data at rest is in the United States, and no customer data is stored in Hetzner’s European data centers. The processing location shown for each subprocessor in the table above is that provider’s stated location, where we have established one. Every location we have established is in the United States, apart from Xero’s, which is stated as New Zealand / United States. Three rows — the optional enrichment providers Hunter.io, Apollo.io and Lusha —read “Not established”: we have not obtained a stated processing location from those providers, and we will not print a guess into a column that Section 6.6 of the Data Processing Agreement makes contractually authoritative on exactly that point. None of the three receives anything unless your organization connects that provider’s own API key, and we will replace those entries with a location as soon as we have one from the provider. If you are in the EEA, the UK or Switzerland, your personal data is therefore transferred to the United States as a matter of course rather than exceptionally, and we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum and the Swiss adaptation of those Clauses, together with supplementary technical and organizational measures. We do not rely on the EU-U.S., UK Extension or Swiss-U.S. Data Privacy Framework. Section 10 of the Data Processing Agreement sets out the mechanisms in full.
Each change to the table above is recorded here on the date it was published, so that a revised “Last Updated” date is never the only evidence that something moved. Section 6.1 of our Data Processing Agreement makes this page contractually authoritative; this log is the part of it that shows you what changed.
| Published | What changed | Had it begun processing? |
|---|---|---|
| August 26, 2026 | Added Hunter.io, Apollo.io and Lusha as optional contact-enrichment subprocessors, and restated the People Data Labs entry to say what it actually receives. All four could already be connected in the Service before this date; only People Data Labs had been listed, so this entry corrects an incomplete disclosure rather than announcing a new engagement. The processing location for the three new entries reads “Not established” — see Data Residency above for why we will not print a guess there. | No. As at this date no organization had connected any of the four, so none of them had processed any personal data for any customer. None of them can: each is engaged only where a customer supplies that provider’s own API key. Publication therefore precedes any processing rather than following it. |
| August 24, 2026 | Added Double the Donation, and replaced the statement that each subprocessor “has been assessed for security and privacy posture and is bound by data processing terms consistent with our obligations” with the accurate position now set out under Current Subprocessors above. | The removed assessment statement was a correction to what this page claimed about us, not a change of subprocessor. |
This log begins on August 24, 2026. Earlier changes to this page were published by revising the “Last Updated” date alone and were not itemised at the time; rather than reconstruct them now, we have started the log from the first date we can evidence and will keep it from here.
For questions about this list, including subprocessor change notifications, contact privacy@tormano.com.