Back to Compliance

RepLogix Vendor & Subprocessor Management Policy

Effective Date: August 8, 2026

This Vendor and Subprocessor Management Policy defines how RepLogix selects, evaluates, and manages third-party service providers that process, store, or transmit customer data. It ensures that vendors meet appropriate security and privacy standards.

1. Purpose and Scope

This policy applies to all third-party vendors and subprocessors used by RepLogix to deliver the Service, including hosting, database, authentication, payment processing, email, SMS, analytics, and support tools.

2. Current Subprocessors

RepLogix uses the following categories of subprocessors:

ProviderFunctionData Accessed
Base44Application hosting, database, auth, file storageAll application data (encrypted at rest)
StripePayment processing, subscription billingPayment metadata (no card numbers stored by RepLogix)
Google (OAuth)Authentication providerEmail, name (for account creation)
ResendEmail deliveryEmail addresses, message content
TwilioSMS notificationsPhone numbers, message content

All subprocessors are located in or process data within the United States. An up-to-date subprocessor list is maintained and available upon request.

3. Vendor Selection Criteria

Before engaging a new vendor or subprocessor, RepLogix evaluates:

  • Security Certifications: SOC 2, ISO 27001, or equivalent attestations
  • Data Handling: How the vendor processes, stores, and protects data
  • Data Location: Where data is stored and processed (US-based preferred)
  • Compliance: Alignment with FERPA, COPPA, GDPR, and other applicable regulations
  • Breach History: Past security incidents and response practices
  • Contract Terms: Data processing agreements, BAAs, and liability provisions
  • Subprocessor Disclosure: Whether the vendor uses fourth-party processors

4. Due Diligence Process

Vendor due diligence includes:

  • Reviewing the vendor's security documentation and certifications
  • Completing a security questionnaire for vendors handling sensitive data
  • Assessing data flow and integration points
  • Verifying data residency and transfer mechanisms
  • Documenting the risk assessment and approval decision

5. Contractual Requirements

Vendor contracts must include:

  • Data processing terms defining scope and purpose of data use
  • Confidentiality obligations
  • Security requirements aligned with RepLogix's standards
  • Breach notification timelines (no more than 72 hours)
  • Data deletion or return upon contract termination
  • Audit rights where applicable
  • Restrictions on subcontracting to fourth parties without approval

6. Ongoing Monitoring

Vendors are monitored on an ongoing basis:

  • Annual review of security certifications and documentation
  • Monitoring of vendor security incidents and breach notifications
  • Review of vendor performance and service level compliance
  • Re-assessment when vendors introduce significant changes to their service

7. Vendor Offboarding

When a vendor relationship ends:

  • Data access is revoked and credentials are deactivated
  • The vendor is required to return or securely delete RepLogix and customer data
  • Data deletion is confirmed in writing
  • Alternative arrangements are made for any critical function the vendor performed

8. Policy Review

This Vendor Management Policy is reviewed at least annually and when significant vendor changes occur.

9. Contact

For questions about this policy or to request the current subprocessor list, contact:

RepLogix Security

Email: RepLogixapp@gmail.com