Subprocessors
The third-party services Converly uses to operate, what each one processes, and where.
Last updated: 21 September 2026
Attributer Pty Ltd, trading as Converly, uses the third-party services below to operate the product. Each is bound by data-protection terms, and none is authorised to use personal information for any purpose other than providing its service to Converly.
For website visitors whose form submissions Converly handles, the website operator is the data controller and Converly is the processor. The services below are therefore subprocessors. See the Privacy Policy for the full picture, and Security for how the data is protected.
| Subprocessor | Purpose | What it processes | Location |
|---|---|---|---|
| Railway | Application hosting (frontend and delivery service) | All data handled by Converly passes through the application, including conversion records and the contact details attached to them. | United States |
| Supabase | Database hosting (PostgreSQL) for conversion events | Conversion records at rest, including the lead's contact details until the 7 day purge, and the credential vault. Encrypted at rest. | United States |
| Amazon Web Services | Content delivery for the Converly tracking script | Request metadata only, being the IP address and browser user agent of a visitor loading the script. No conversion or form data passes through it. | Global edge network |
| Stripe | Payment processing for customer subscriptions | Converly customer billing details. No website visitor data. Card numbers are entered directly into Stripe and never reach Converly. | United States |
| SendGrid | Transactional email delivery | Converly customer email addresses, for account and service email. No website visitor data. | United States |
| Sentry | Error tracking, performance monitoring, and session replay | Error diagnostics from the Converly dashboard. Session replay masks all input fields and personal information by default, and does not record visitor activity on customer websites. | United States |
International transfers
Converly is operated from Australia and its infrastructure subprocessors are in the United States. If you access Converly from the EU, the UK, or elsewhere outside the United States, personal information is transferred to and processed in the United States.
Where GDPR, UK GDPR, or other applicable law requires it, we rely on Standard Contractual Clauses approved by the European Commission and, where applicable, the UK International Data Transfer Addendum. A copy is available on request from privacy@converly.io.
Changes to this list
Adding or replacing a subprocessor is a notifiable change. We update this page and notify customers by email before the change takes effect, so you have time to object.
Data processing agreement
A DPA is available on request for customers who need one. Email privacy@converly.io and tell us which jurisdiction you are contracting from, so we can send the right transfer terms with it.
