Subprocessor Policy
Purpose
This Policy explains how BizExchangeX ("BEX") evaluates, approves, monitors, and manages subprocessors that support platform operations.
Definition
A subprocessor is a third party engaged by BEX to process personal information on behalf of BEX customers.
Selection Criteria
BEX evaluates subprocessors based on:
- Security controls
- Privacy practices
- Regulatory compliance
- Business continuity capabilities
- Contractual protections
- Incident response maturity
Current Subprocessor Categories
| Category | Purpose | Data Types |
|---|---|---|
| Cloud Infrastructure | Application hosting | Account, procurement, operational data |
| Email Services | Transactional messaging | Contact information |
| Monitoring Services | Performance and security monitoring | System telemetry |
| Support Platforms | Customer support workflows | Support records |
| Analytics Providers | Service improvement | Usage information |
Subprocessor Obligations
BEX requires subprocessors to:
- Maintain appropriate security safeguards
- Protect confidential information
- Process data only for authorized purposes
- Notify BEX of security incidents
- Support applicable privacy obligations
Change Management
BEX maintains an inventory of subprocessors and reviews changes periodically.
Material changes will be communicated as required by applicable law or contract.
Customer Rights
Customers may request information regarding subprocessors supporting BEX services.
Contact Information
compliance@bizexchangex.io
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 2026-06-19 | Initial draft |