This page lists the third-party service providers ("subprocessors") Incenti Solutions, Inc. ("Incenti") engages to deliver Incenti EDOS, Insights; the independent recipients to which customers may direct data; the AI providers used and their retention terms; and how long data is kept. It is the Subprocessor List referenced in the Master Subscription Agreement and the Data Processing Addendum.
Customer data means data our customers submit to or generate in Incenti EDOS: accounts, contacts, opportunities, properties, form responses, uploaded documents, notes, tasks, and reports. Insights data (economic, demographic, and subsidy datasets) is sourced from public agencies, is not tenant-scoped, and contains no customer data; its sources are listed in § 5.
Each subprocessor is bound by a written agreement imposing data protection and security obligations no less protective than Incenti's commitments to its customers, and Incenti remains liable for its subprocessors' performance as for its own.
Changes. Incenti announces additions or replacements of subprocessors at least thirty (30) days in advance, by email to customer account administrators and by updating this page. Prior versions are archived at https://incenti.co/legal.
1. Subprocessors
Each vendor below receives or can access customer data (or end-user identity data) in providing its service.
| Subprocessor | Service | Customer data processed | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting (portal, public forms, workers, MCP server), edge network, file storage (Vercel Blob), AI Gateway routing | All application traffic in transit; uploaded files and generated documents at rest; AI prompts in transit | United States |
| Neon Inc. | Managed PostgreSQL (primary datastore, all environments) | All customer data at rest, encrypted | United States |
| WorkOS Inc. (configured; not currently in the production authentication path) | Authentication (AuthKit), SSO, user identity | Names, email addresses, authentication events, if and when activated | United States |
| Inngest Inc. | Background job orchestration and realtime channels | Event payloads: record identifiers, form and notification content in transit | United States |
| Resend Inc. | Transactional email delivery | Recipient names, email addresses, notification content | United States |
| Anthropic PBC | Large language model inference (chat assistant, form template extraction, AI grading), routed through Vercel AI Gateway | Prompt content, which can include tenant records the user asks about — see § 3 | United States |
| OpenAI, L.L.C. | Large language model inference (legacy scoring and summary paths) | Prompt content on legacy code paths — see § 3 | United States |
| GIS WebTech, LLC (scheduled — see note) | Proposal generation and form data handling performed on Incenti's documented instructions (subprocessor capacity) | Tier 1 and Tier 2 form and proposal fields only; no Tier 3 data flows in this capacity. The partner may not use, retain or disclose this data for its own purposes | United States |
| Better Stack, Inc. | Log ingestion and uptime monitoring (pipeline heartbeats) | Application logs, which can include user and record identifiers | United States / EU |
| Metabase, Inc. | Embedded analytics dashboards (signed JWT embeds, 10-minute expiry), scoped to the requesting tenant | Aggregated tenant metrics rendered in embedded dashboards | United States |
| Google LLC / Microsoft Corp. | OAuth identity providers for sign-in (Google OAuth, Microsoft Entra ID) | Identity token exchange at sign-in only | United States |
Geocoding: property street addresses submitted by customers are transmitted to the OpenStreetMap Foundation (Nominatim API, EU) for address geocoding. OSMF is a data recipient operating a public API, not a subprocessor under a data processing agreement, and only street addresses are transmitted.
GIS WebTech, LLC — scheduled integration. The GIS WebTech integration is not yet live. Its listing here — in both capacities (§§ 1 and 2) — constitutes the advance notice required by MSA § 10.3, and each listing takes effect when the integration launches.
2. Independent recipients (not subprocessors — listed for transparency)
| Recipient | What it receives | Under whose authority | What it does with it |
|---|---|---|---|
| GIS WebTech, LLC (scheduled — see note above) | Property and site records a customer has enabled for sharing — Tier 1 data only. Property sharing is off by default and occurs only for records a customer switches on, with per-record controls and an account-level administrator switch | The customer's authorization (MSA §§ 5.1.1(c), 5.1.2 and Schedule A § A.6) — never Incenti's own initiative | Uses them for its own purposes under its own terms — including its national property database and public listings. Incenti cannot compel deletion of copies the partner has already distributed (§ A.9.3) |
This recipient also appears in § 1 in a legally distinct capacity. The two data paths are separated: data received in the subprocessor capacity may not be retained or used under the independent-recipient capacity.
3. AI providers — retention and training
| Provider | Used for | Training on customer data | Retention of inputs/outputs |
|---|---|---|---|
| Anthropic PBC | Chat assistant, form template extraction, AI grading | No — commercial API data is not used for model training under Anthropic's Commercial Terms | Inputs and outputs deleted within 30 days by default (Incenti has no zero-data-retention agreement and uses no extended-retention features). Exception: content flagged by Anthropic's automated trust-and-safety classifiers as potentially violating its Usage Policy may be retained up to 2 years, and legal holds as required by law |
| OpenAI, L.L.C. | Legacy scoring and summary paths | No — API data is not used to train models by default under OpenAI's API terms | Retained up to 30 days for abuse monitoring, then deleted, unless longer retention is required by law or to protect against harm. Zero-data-retention not in place (requires OpenAI approval; not applied for) |
Evidence: dated captures of each provider's published retention and training policies — together with the commercial terms that incorporate them — are held on file and available to customers on request under MSA § 9.7.
4. Supporting services (no platform customer data)
| Vendor | Service | Data involved |
|---|---|---|
| GitHub, Inc. | Source code hosting, CI/CD (GitHub Actions) | Source code, build artifacts; no production customer data |
| Brevo (Sendinblue SAS) | Newsletter and marketing email | Contact names and email addresses from Incenti's own marketing lists; no platform data. Incenti acts as controller. EU-hosted (France/Germany) |
| Google LLC (Analytics + Tag Manager) | Web analytics on the marketing site only (not present in the portal or public forms) | Website visitor behavior, device data, cookies; no platform data. Incenti acts as controller |
| Slack Technologies, LLC | Internal notification of website demo requests | Prospect name and contact details from the demo request form; marketing data, Incenti as controller |
| Strapi (Strapi Cloud) | CMS hosting for the marketing site | Marketing content only |
| Vercel Inc. | Preview deployments with isolated database branches | Branch databases only; never production data |
5. Upstream data sources (inbound only)
The Insights product ingests public economic and demographic data from roughly 50 government and research sources, including the Bureau of Labor Statistics, Census Bureau, Bureau of Economic Analysis, Energy Information Administration, FEMA, HUD, FDIC, EPA, FBI Crime Data, IRS Statistics of Income, and College Scorecard. These are data sources, not subprocessors: traffic is outbound requests for public datasets, and no customer data is transmitted to them. (Source-level terms and attribution requirements are published on the Third-Party Data & Attribution page.)
6. Data retention
| Data class | Where held | Retention window | Basis |
|---|---|---|---|
| Customer records | Neon PostgreSQL | Life of subscription. On termination: retained through the 60-day post-termination Export Window (MSA § 19.4), then purged within 30 days (≈90 days after termination). Purged within 30 days of a verified deletion request during the subscription | Contract / DPA |
| Uploaded files | Vercel Blob | Life of the parent record; purged with the record, and on the same post-termination schedule as customer records | Contract / DPA |
| Database backups (PITR) | Neon | 14 days rolling — deleted data leaves backups within 14 days of production purge | Provider configuration |
| Security-relevant logs (authentication events, customer-record access, administrative actions) | Better Stack | 12 months | Privacy Policy commitment |
| General application logs | Better Stack | 30 days | Vendor plan setting |
| Error events | Better Stack (via Sentry SDK) | With general application logs above | Plan setting |
| Background job history | Inngest | Per vendor plan | Vendor plan setting |
| Email delivery logs | Resend | Per vendor setting, minimized | Vendor setting |
| AI prompts and outputs | Anthropic / OpenAI APIs | Per § 3 — not used for training; deleted within 30 days (provider defaults; § 3 exceptions) | Vendor published terms |
| Authentication records | Platform database (WorkOS if activated) | Life of the user account; removed on user deletion | Contract / vendor DPA |
Questions: privacy@incenti.co