Vendor / Subprocessor Management Policy
Document control
| Field | Value |
|---|---|
| Document owner | Operations, Hybrowlabs Technologies Pvt Ltd |
| Approver | Chinmay Kulkarni, Director |
| Document status | Active policy document |
| Applies to | All third parties engaged by Hybrowlabs in the delivery of customer work |
| Review frequency | Annual, or on material change to the delivery model, tooling or customer commitments |
| Classification | Customer-shareable |
Purpose
This policy sets out how Hybrowlabs assesses, approves, contracts, monitors and offboards the third parties involved in delivering customer work, and how customers are told about the ones that touch their data.
Vendor or subprocessor
The two are treated differently, and the distinction decides everything that follows.
A subprocessor processes, stores or can access customer data on our behalf. Hosting and infrastructure providers, ticketing and support platforms that hold customer attachments, backup services, and subcontracted delivery personnel all fall here.
A vendor supplies a product or service to Hybrowlabs without access to customer data. Accounting software, office supplies and internal-only tooling fall here.
If a third party could access customer data, it is a subprocessor, whether or not it is expected to look at it. Encryption, contractual prohibition or the supplier's own assurances do not move something out of this category.
Classification
| Class | Definition | Assessment | Customer visibility |
|---|---|---|---|
| Subprocessor | Processes, stores or can access customer data | Full assessment before engagement | Named in the Subprocessor Register, notice before addition |
| Vendor with system access | Access to Hybrowlabs systems but not to customer data | Security review before engagement | Not published |
| Vendor without access | No access to systems or data | Commercial review only | Not published |
Where classification is unclear, the higher class applies until assessed.
Where customer data actually sits
Two arrangements are common, and the subprocessor position differs between them.
Where the customer hosts on their own infrastructure or their own Frappe Cloud account, Hybrowlabs introduces no hosting subprocessor at all. Our people hold access to the customer's environment, but the data stays under the customer's contracts.
Where Hybrowlabs hosts or manages the environment, the hosting and backup providers are subprocessors, named in the Subprocessor Register.
Support tooling, communication channels and any service used to move files or hold attachments are assessed on the same basis in both cases, because customer data reaches them regardless of who owns the servers.
Categories of subprocessor
- Hosting and infrastructure providers
- Backup and disaster recovery services
- Ticketing, helpdesk and support platforms holding customer attachments
- Source code hosting where customer-specific code is held
- Email and communication services used for customer correspondence
- Background verification agencies processing personnel data
- Subcontracting organisations supplying delivery personnel
- Any AI or automated service processing customer data or customer-specific code
Assessment before engagement
Subprocessors are assessed on:
- Business purpose and whether the need can be met without introducing them
- What customer data they will hold, and the minimum required
- Security controls, certifications and independent assurance reports
- Data location, and whether cross-border transfer safeguards are required
- Incident notification commitments and timelines
- Their own use of sub-subprocessors
- Deletion and return commitments on termination
- Financial and operational stability where the service is critical
Vendors with system access are assessed on security controls, access scope and incident notification only.
Approval sits with the Director. No third party receives customer data before approval is recorded.
Contract requirements
Every subprocessor agreement includes:
- Confidentiality terms that survive termination
- Data protection obligations matching those we owe our customers
- A prohibition on processing for any purpose other than delivering the service
- Security control commitments
- Incident notification to Hybrowlabs without undue delay
- Restrictions on onward subcontracting without our written approval
- Return or deletion of data on termination, confirmed in writing
- Audit or evidence rights proportionate to the risk
Where a customer contract imposes stricter terms, those terms are flowed down to the subprocessor rather than absorbed by us.
Subcontracted personnel
Subcontracting organisations supplying delivery personnel are subprocessors, and are additionally required to:
- Perform background verification equivalent to our own, and evidence it
- Bind their personnel under confidentiality terms mirroring the customer agreement
- Supply named individuals rather than an interchangeable pool
- Complete our security awareness training before access is granted
Their people are provisioned individually named accounts and are offboarded on the same basis as employees.
Customer notification and objection
Customers are told which subprocessors are involved in their engagement, and the register is published rather than supplied on request.
Before a new subprocessor is added to an engagement, the affected customer is given notice and a period to object. Where a customer objects on reasonable grounds, we look for an alternative or keep the existing arrangement for that account. Where no workable alternative exists, the position is discussed rather than imposed.
Customer-directed tools are treated differently. Where a customer requires us to use a service they have selected, they own that decision and the associated risk, and we record it as such.
Ongoing monitoring
Subprocessors are reviewed at least annually and sooner on an incident or a material change. The review covers:
- Whether the service is still needed
- Whether the access held is still the minimum required
- Security posture, certification currency and any published incident
- Contract validity and whether terms still match customer commitments
- Any change in data location or in their own subprocessors
Review outcomes are recorded, including a decision to retain, restrict or replace.
Incidents
A subprocessor incident affecting customer data is treated as our incident. We notify affected customers within the timelines set out in the applicable agreement and do not wait for the subprocessor to complete its own investigation before giving notice.
Offboarding
When a subprocessor relationship ends:
- Access to Hybrowlabs and customer systems is revoked
- Integrations, API keys and webhooks are disabled
- Data is returned or deleted, with written confirmation obtained
- The Subprocessor Register is updated and affected customers informed
- Credentials that the subprocessor could have observed are rotated
Evidence maintained
Available for customer due diligence or audit, subject to redaction:
- Subprocessor Register with current entries and change history
- Assessment records and approval decisions
- Executed agreements and the relevant security and data protection clauses
- Annual review records and outcomes
- Customer notifications and objection handling
- Incident notices received and passed on
- Offboarding and deletion confirmations
Related documents
- Subprocessor Register
- HR Security Policy
- Acceptable Use Policy
- Background Verification Process
- NDA / Confidentiality Agreement Structure
Questions about our supply chain?
If your security or procurement team needs the current subprocessor list for your engagement, evidence of an assessment, or a specific contractual term confirmed, our team can respond directly.