
BrandOps9 document
Sub-processors
Last updated August 13, 2026
BrandOps9 uses the third-party services below to deliver the platform. Each processes only the data needed for its purpose. Providers outside the EEA operate under appropriate safeguards such as Standard Contractual Clauses. A Data Processing Agreement is available on request, and we will give notice of material changes to this list.
OpenAI: content generation (United States)
Purpose: generate text, images and video. Data: brand and campaign context and the prompts you submit. Not used to train OpenAI's models. Safeguard: Standard Contractual Clauses.
RunwayML: video generation (United States)
Purpose: render video when you enable the RunwayML provider. Data: the prompt text and the source image for the clip. Safeguard: Standard Contractual Clauses.
Google: sign-in (United States)
Purpose: Google OAuth login. Data: your email, name, profile picture and Google account identifier, returned to us when you choose 'Continue with Google'. Safeguard: Standard Contractual Clauses.
Meta (Facebook / Instagram): publishing (United States)
Purpose: publish and measure content on Pages/accounts you connect. Data: the post content and media you publish, connected account identifiers, and engagement metrics returned by Meta. Safeguard: Standard Contractual Clauses.
LinkedIn: publishing (United States)
Purpose: publish and measure content on the person or organization you connect. Data: the post content and media you publish, connected account identifiers, and engagement metrics. Safeguard: Standard Contractual Clauses.
X (Twitter): publishing (United States)
Purpose: publish and measure posts on a connected X account. Data: the post content and media you publish, the connected account identifier, and public metrics. Safeguard: Standard Contractual Clauses.
Stripe: payments (United States / EU)
Purpose: process credit purchases. Data: your account email and purchase metadata. Card details are entered on Stripe's hosted checkout and are never received or stored by BrandOps9. Safeguard: Standard Contractual Clauses.
SendPulse: transactional email
Purpose: deliver operational email (password resets, invites, review requests, reminders). Data: the recipient address and message content. Safeguard: Standard Contractual Clauses. Where a self-hosted SMTP server is configured instead, email is delivered through that server.