About Services Technology Clients Blog Contact
HomeLegal

Subprocessors

Legal documentCourtesy translation — the Spanish version governs · Last updated: August 2026

What this page is

When a company hands us a process, its data — and its people's data — passes through tools that aren't ours. A server, an inbox, a chat platform. The law calls those third parties subprocessors, and whoever signs the contract has the right to know who they are beforehand, not afterwards.

We publish the full list in writing so that any client's procurement or risk team can check it without having to ask us. It has two parts, and the second one matters as much as the first: which tools we use that do NOT touch client data.

Providers involved in processing

What each one does, where it stores data, and what guarantees it offers.

Microsoft 365 — Microsoft Corporation

  • What for: corporate email and storage of working documents. It is the only provider on this list through which files containing our clients' personal data circulate.
  • Where: Microsoft data centres. The specific region depends on how our workspace is configured, and we disclose it to any client who asks.
  • Guarantees: Microsoft provides a data processing agreement and standard contractual clauses within its online services terms, along with ISO/IEC 27001 certification and SOC 2 reports.

DigitalOcean — DigitalOcean LLC

  • What for: the server running our support platform. That is where the website chat conversations live, including whatever a visitor writes.
  • Where: New York, United States.
  • Guarantees: data processing agreement with standard contractual clauses. Its data centres hold ISO 27001 certification and a SOC 2 Type 2 report.

Cloudflare — Cloudflare, Inc.

  • What for: delivering this website, protecting it against attacks, and measuring visits. The measurement sets no cookies and creates no persistent identifiers.
  • Where: distributed network; content is served from the node closest to the visitor.
  • Guarantees: data processing agreement with standard contractual clauses and ISO/IEC 27001 certification.

Resend — Resend, Inc.

  • What for: sending this site's contact form. It processes the name, email address and message of whoever writes to us.
  • Where: United States.
  • Guarantees: data processing agreement in force from account creation, SOC 2 Type II report, and certification under the EU–U.S. Data Privacy Framework.

Internal tools that do not touch client data

We use these to organise ourselves. We name them precisely to put in writing that the data you entrust to us does not pass through here.

  • Slack — internal team communication. If a client prefers a shared channel, that is agreed separately and recorded in the contract.
  • Airtable — internal administration: task tracking and attendance records for our own staff.
  • GitHub — source code for our platforms and for this website. It holds programs, not operational data.

Our own platforms — éxodo check, cloud, ai and cross — are built and operated by us. They are not subprocessors: they are part of the service.

Transfers outside Argentina

Several of these providers store information in the United States. It is worth stating this precisely: the United States is not on the list of countries recognised as offering an adequate level of protection by the Argentine authority, under Disposition 60-E/2016 and AAIP Resolution 34/2019.

That does not block the transfer, but it does require a mechanism to permit it. Article 12 of Law 25.326 allows transfers where the data subject consents or where contractual clauses guarantee an adequate level of protection. AAIP Resolution 198/2023 expressly recognised the Model Contractual Clauses of the Ibero-American Data Protection Network as a valid mechanism for transfers to jurisdictions without adequacy.

Every client contract records which providers are involved and under which instrument the transfer takes place. If you want the detail that applies to your case before signing, write to us and we will put it in writing.

Changes to this list

If we add or change a provider involved in processing, we update this page and notify clients with active contracts before the change takes effect. The date above shows the last revision.

Contact

About this list, about the data processing agreement, or about any point in our policies: hola@exodobpo.com.

As a data subject you may exercise your rights of access, rectification and erasure as set out in our privacy policy. The Agency for Access to Public Information, the supervisory body for Law 25.326, handles complaints from anyone whose rights are affected.

Next document
Quality Policy
Legal — éxodo bpo