Subprocessor List
The third parties Sales Day engages to process personal data on behalf of Customers.
Effective date: 1 July 2026
Last updated: 1 July 2026
1. Introduction
This Subprocessor List identifies the principal third parties engaged by Sales Day Software Ltd to process personal data in connection with the Sales Day Service.
It should be read together with the:
- Sales Day Terms of Service;
- Sales Day Privacy Notice;
- Sales Day Data Processing Addendum;
- Sales Day Cookie Notice; and
- Sales Day Security and Data Protection Overview.
In this List:
- "Sales Day", "we", "us" or "our" means Sales Day Software Ltd;
- "Customer Personal Data" means personal data contained within Customer Data that Sales Day processes on behalf of a Customer;
- "Subprocessor" means a third party engaged by Sales Day to process Customer Personal Data on Sales Day's behalf; and
- "Connected Service" means a third-party service that a Customer or User chooses to connect or use.
2. Sales Day Software Ltd
Legal entity: Sales Day Software Ltd
Company number: NI740756
Registered office: 15 Kerrsland Drive, Belfast, BT5 6ER, United Kingdom
Privacy enquiries:
Security enquiries:
3. Current direct subprocessors
3.1 Base44 / Wix.com Ltd
| Item | Detail |
|---|---|
| Provider | Wix.com Ltd, operating the Base44 branded service, including relevant affiliates |
| Service | Application platform, hosting, database, authentication, backend functions, application storage, routing and infrastructure |
| Data processed | User identity and Account data, Workspace data, Customer CRM data, Tasks, Meetings, support and operational data, authentication and technical metadata, uploaded and generated application data |
| Processing purpose | Hosting, storing, authenticating, transmitting, securing, operating and supporting Sales Day |
| Processing locations | As described in Base44's current DPA and subprocessor schedule |
| Transfer safeguards | As described in Base44's DPA, including applicable contractual and international-transfer safeguards |
| Provider documentation | Base44 Data Processing Addendum and Base44 Subprocessor List |
Base44 is Sales Day's principal application-platform provider.
Because the Sales Day application and database operate through Base44, Base44 may process most categories of information held within Sales Day where necessary to provide the platform.
Base44 maintains its own list of downstream subprocessors. At the date of this List, that published schedule includes providers supporting functions such as:
- database hosting;
- server infrastructure;
- media hosting;
- logging;
- platform analytics;
- email transmission;
- artificial-intelligence platform functions; and
- provision and improvement of the Base44 service.
The exact downstream providers, purposes and countries may change in accordance with Base44's DPA and subprocessor-notification process.
Sales Day does not represent that every Base44 downstream provider receives every category of Sales Day data. Access depends on the platform function involved and Base44's configuration and processing arrangements.
3.2 Resend, Inc.
| Item | Detail |
|---|---|
| Provider | Resend, Inc. |
| Service | Transactional email delivery |
| Data processed | Recipient email addresses, sender identity, email subject and content, Workspace or record context included in the message, delivery metadata, provider message identifiers, delivery failures and technical logs |
| Processing purpose | Delivering Team invitations, notifications, mentions, support replies, Morning Digests and other transactional emails |
| Primary processing location | United States, according to Resend's current DPA |
| Transfer safeguards | Resend's DPA and applicable international-transfer mechanisms |
| Provider documentation | Resend Data Processing Addendum and Resend Subprocessor List |
Resend may process Customer Personal Data where an email generated through Sales Day includes information from a Customer Workspace.
Examples may include:
- names;
- Task or Meeting information;
- Workspace names;
- notification text;
- record information selected by the sender; and
- recipient contact details.
Customers remain responsible for ensuring that information sent to an external recipient is lawful, appropriate and limited to what is necessary.
Resend maintains its own downstream subprocessor list. Sales Day relies on Resend's contractual obligations to control those providers and notify Customers of relevant changes.
4. Payment provider
4.1 Stripe
| Item | Detail |
|---|---|
| Provider | The applicable Stripe contracting entity, which may include Stripe Payments UK Ltd, Stripe Payments Europe Limited, Stripe Technology Company Limited or another Stripe group entity |
| Service | Subscription checkout, payment processing, invoices, receipts, payment recovery, Customer Portal and billing administration |
| Data processed | Customer or billing-owner name, email address, billing address where supplied, plan, billing interval, seat quantity, Subscription identifiers, invoice and transaction information, tax information and payment details entered directly into Stripe |
| Processing purpose | Processing payments, managing Subscriptions, preventing fraud, complying with financial regulation and providing billing services |
| Processing locations | As identified in Stripe's applicable services agreement, DPA and service-provider register |
| Transfer safeguards | As described in Stripe's applicable DPA and international-transfer terms |
| Provider documentation | Stripe Data Processing Agreement and Stripe Service Providers, Sub-processors and Affiliates register |
Stripe may act in different legal capacities depending on the processing activity.
For example, Stripe may act:
- as a processor or service provider for certain Business User data;
- as an independent controller where required to provide regulated payment services;
- as an independent controller for fraud prevention, legal compliance and financial regulation; or
- through an applicable Stripe regulated affiliate.
For that reason, Stripe is disclosed here as a key payment provider rather than being described as a Sales Day Subprocessor for every payment activity.
Sales Day does not store full payment-card numbers or card-security codes.
Payment information is entered into and processed through Stripe-controlled systems.
Stripe publishes and maintains its own extensive service-provider, affiliate and subprocessor register.
5. Customer-selected connected services
5.1 Google Calendar and Google OAuth
| Item | Detail |
|---|---|
| Provider | Google LLC and relevant Google affiliates |
| Service | Account authorisation and Google Calendar integration |
| Data exchanged | Connected Account identity, calendar identifiers, event identifiers, Task or Meeting title, dates, times, descriptions, locations, linked Contacts where applicable, assignee information and synchronisation metadata |
| Processing purpose | Creating, reading, updating, deleting and synchronising calendar events at the User's instruction |
| Processing locations | Determined by Google under the User's or organisation's Google service arrangements |
| Transfer safeguards | Determined under Google's applicable terms, data-processing terms and Account configuration |
| Provider documentation | Google Privacy Policy and applicable Google Workspace, Cloud or API service terms |
Google Calendar is a Connected Service selected and authorised by the User.
When a User connects Google Calendar:
- the User instructs Sales Day to exchange relevant data with Google;
- Google processes information under its own terms and privacy documentation;
- the permissions depend on the scopes approved by the User;
- the User or Google Workspace administrator may control or withdraw access; and
- disconnecting the integration may not delete events already created in Google.
Google is not necessarily a Sales Day Subprocessor merely because Sales Day enables the integration.
Its legal role may depend on:
- the User's Google Account;
- whether the Account is personal or organisational;
- the applicable Google contract;
- the specific data exchanged; and
- the Customer's own relationship with Google.
6. Authentication and platform services
Authentication, secure sessions and application access are currently provided as part of the Base44 platform.
Sales Day does not currently identify a separate direct authentication vendor outside the Base44 service relationship.
Where Base44 uses downstream providers for authentication, hosting or security, those providers are governed through Base44's DPA and subprocessor schedule.
7. Email-routing distinction
Sales Day currently uses Resend as its direct transactional-email delivery provider.
Base44's own published subprocessor schedule may also identify other email-transmission providers used within the Base44 platform.
Those providers should not automatically be understood as receiving every Sales Day transactional email.
The relevant provider depends on which platform or product function initiates the communication.
Sales Day will update this List if a material direct email provider is introduced or replaced.
8. Artificial-intelligence providers
Sales Day does not currently send Customer CRM data routinely to an external artificial-intelligence provider as part of ordinary CRM use.
Base44's platform documentation may identify AI providers used in connection with Base44 platform functionality.
Their inclusion in Base44's downstream subprocessor schedule does not mean that Sales Day routinely sends all Customer Data to those providers.
If Sales Day introduces a Customer-facing AI feature that processes Customer Personal Data, we will:
- identify the provider;
- explain the feature and data flow;
- assess the provider's contractual and security position;
- update this Subprocessor List where appropriate;
- update the Privacy Notice and DPA where necessary; and
- provide required notice before material processing begins.
9. Professional advisers and authorities
Sales Day may disclose limited personal data to:
- accountants;
- solicitors;
- auditors;
- insurers;
- tax advisers;
- regulators;
- courts;
- law-enforcement bodies; and
- other competent authorities.
These recipients are not normally Sales Day Subprocessors.
They may act as:
- independent controllers;
- professional advisers subject to legal duties;
- statutory recipients; or
- recipients required by law.
Information is disclosed only where reasonably necessary and subject to appropriate confidentiality or legal obligations.
10. Internal access
Sales Day personnel or authorised contractors may access personal data only where reasonably necessary for:
- customer support;
- security investigation;
- billing support;
- incident response;
- technical troubleshooting;
- lawful administrative action;
- data deletion or restoration;
- fraud prevention; or
- compliance with legal obligations.
Such access does not make the individual or contractor a separate public Subprocessor where they act under Sales Day's direct authority and confidentiality obligations.
External contractors with independent organisational access to Customer Personal Data may be added to this List where legally required.
11. Downstream subprocessors
A direct Sales Day Subprocessor may itself use downstream subprocessors.
Sales Day does not reproduce every downstream-provider list in full because:
- those lists may be extensive;
- they change as providers update their infrastructure;
- only a subset may apply to the particular service used by Sales Day; and
- the direct provider is contractually responsible for its downstream chain.
Sales Day instead:
- identifies its direct providers;
- refers to their official subprocessor documentation;
- requires appropriate data-protection terms;
- monitors material changes where reasonably practicable; and
- maintains responsibility in accordance with the Sales Day DPA and applicable law.
Customers should review the current official lists maintained by Base44, Resend and Stripe where detailed downstream information is required.
12. International transfers
Some providers listed in this document process information outside the United Kingdom.
Relevant processing may occur in, or be accessible from:
- the United States;
- Israel;
- the European Economic Area;
- the United Kingdom; and
- other countries identified in the provider's current documentation.
Where a restricted transfer requires a safeguard, Sales Day or the relevant provider will rely on a recognised mechanism where applicable, such as:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission Standard Contractual Clauses;
- European Commission Standard Contractual Clauses;
- an approved data-privacy framework;
- binding corporate rules; or
- another legally recognised safeguard.
The applicable mechanism depends on:
- the provider;
- the contracting entity;
- the service;
- the data involved;
- the processing location; and
- the legal role of each Party.
Customers may contact privacy@sales.day for additional information about applicable transfer safeguards.
13. New and replacement subprocessors
Sales Day may add, remove or replace direct Subprocessors as the Service evolves.
We will provide reasonable advance notice of a material new or replacement direct Subprocessor through one or more of:
- email;
- an in-app notice;
- the Sales Day legal pages;
- an update to this List; or
- another reasonable electronic method.
A Customer may object on reasonable, documented data-protection grounds in accordance with the Sales Day Data Processing Addendum.
An objection should be sent to:
It must:
- identify the Subprocessor;
- explain the specific data-protection concern; and
- be submitted within the objection period stated in the Data Processing Addendum.
14. Provider changes without a Sales Day decision
A provider may update its own:
- corporate structure;
- affiliates;
- processing locations;
- subprocessors;
- legal entity;
- service architecture;
- transfer mechanism; or
- privacy documentation.
Sales Day will use reasonable efforts to keep this List current, but the provider's official documentation is authoritative for its own current downstream arrangements.
Where a provider change materially affects Sales Day's processing of Customer Personal Data, Sales Day will assess whether:
- this List must be updated;
- Customer notice is required;
- an objection right applies;
- the DPA or Privacy Notice requires amendment; or
- another operational change is necessary.
15. Current provider summary
| Provider | Relationship | Main purpose | Main data categories |
|---|---|---|---|
| Base44 / Wix.com Ltd | Direct Subprocessor and platform provider | Application hosting, database, authentication, backend functions and infrastructure | Account, Workspace, CRM, technical, support and operational data |
| Resend, Inc. | Direct Subprocessor | Transactional email delivery | Email addresses, message content and delivery metadata |
| Stripe | Payment provider with role depending on processing | Checkout, payments, Subscriptions, invoices and fraud prevention | Billing, identity, transaction and payment data |
| Customer-selected Connected Service | Google OAuth and Calendar synchronisation | Account identity, Task, Meeting, event and synchronisation data |
16. Contact
Questions about this List or Sales Day's providers should be sent to:
Sales Day Software Ltd
15 Kerrsland Drive
Belfast
BT5 6ER
United Kingdom
Company number: NI740756
Privacy: privacy@sales.day
Security: security@sales.day
