Privacy

We respect your privacy and follow industry standards to protect your personal information. Learn more about how your data is processed, transferred, and stored.

Subprocessors

A sub-processor is a third-party engaged by HashiCorp who processes Personal Data of HashiCorp customers in order to deliver and support our Products or Services. HashiCorp engages different types of sub-processors to perform various functions, as explained in the tables below.

Due diligence

HashiCorp undertakes to use a commercially reasonable selection process by which it evaluates the security, privacy and confidentiality practices of proposed sub-processors that will or may have access to or otherwise process Personal Data.

Contractual safeguards

HashiCorp requires its sub-processors to satisfy equivalent obligations as those that apply legally or contractually to HashiCorp (as a Data Processor), all as set forth in HashiCorp’s Data Processing Agreement (“DPA”), including but not limited to the following requirements to:

  • Process Personal Data in accordance with data controller’s (i.e. the customer’s) documented instructions (as communicated in writing to the relevant sub-processor by HashiCorp);

  • In connection with their sub-processing activities, use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable, pursuant to applicable data protection laws;

  • Require a duty of confidentiality of personnel to whom they grant access to Personal Data;

  • Implement and maintain appropriate technical and organizational measures and provide an annual certification that evidences compliance with this obligation. In the absence of such certification, HashiCorp reserves the right to audit the sub-processor;

  • Comply with Standard Contractual Clauses with respect to personal data transfers;

  • Not engage in the sale of customer’s personal data;

  • Promptly inform HashiCorp about any actual or potential security breach in accordance with applicable data privacy laws; and

  • Cooperate with HashiCorp in order to deal with requests from data controllers, data subjects or data protection authorities, as applicable.

Process to engage new subprocessors

HashiCorp will provide a notice of updates to this list of sub-processors that are utilized to deliver its Services. HashiCorp undertakes to keep this list updated regularly to enable its customers to stay informed of the scope of sub-processing associated with HashiCorp.

Subprocessors

For information on where HashiCorp production systems and support teams are located, please see hashicorp.com/trust/privacy/tia

The following table describes the countries and legal entities engaged by HashiCorp in the storage or processing of Personal Data.

Entity NameNature of processingEntity CountryProduct(s) in scope
AWSCloud Service ProviderHashiCorp maintains operations through AWS within the United States.TFC
HashiCorp maintains operations through AWS, with various regions supported at your choosing.HCP
Auth0 (Okta)Authentication ProviderAuth0 data is hosted in the United States.HCP
AzureCloud Service ProviderHashiCorp maintains operations through Azure, and allows customers to provision their own consul clusters.HCS

HCP

BackupifyBackup for Google SuiteBackupify data is hosted in the United States.All Products
DatadogLog and event aggregatorDatadog data is hosted in the United States.TFC

HCP

FastlyContent delivery network, Internet security services, load balancing, and video and streaming servicesFastly data is hosted in the United States.TFC
ForethoughtCustomer support and ticket routingForethought data is hosted in the United States.All Products
GainsightCustomer success and supportGainsight data is hosted in the United States.All Products
GoogleEmail service providerGoogle email services are hosted in the United States.All Products
HeapAnalytics for product usage and user behaviorHeap data is hosted in the United States.TFC

HCP

LaunchDarklyFeature flaggingLaunchDarkly data is hosted in the United States.HCP
LookerAnalytics for product usage behaviorLooker data is hosted in the United States.TFC

HCP

MarketoCustomer and sales leads managementMarketo data is hosted in the United StatesAll Products
NetsuiteBilling and accountingNetsuite data is hosted in the United States.All Products
ReplicatedInstallation and packagingReplicated data is hosted in the United States.Terraform Enterprise
SalesforceCustomer relationship managementSalesforce data is hosted in the United States.All Products
SegmentCustomer data collection platformSegment data is hosted in the United States.TFC

HCP

SentryError monitoringSentry data is hosted in the United States.TFC

HCP

SlackCustomer supportSlack data is hosted in the United States.All Products
SnowflakeData warehouseSnowflake data is hosted within the United States.All Products
StripePayment processingStripe data is hosted in the United States.TFC

HCP

SumoLogicLogging and monitoringSumoLogic data is hosted in the United States.TFC

HCP

TwilioMessaging service for multi factor authenticationTwilio data is hosted in the United States.TFC

HCP

WorkatoProfessional services for data warehouseWorkato data is hosted in the United States.All Products
ZendeskCustomer supportZendesk data is hosted in the United States.All Products
ZoomCustomer supportZoom data is hosted in the United States.All Products
HashiCorp Federal, Inc. Use Only
DLT SolutionsCustomer support for HashiCorp Federal, Inc.Data is hosted in the United States.Any products for which the customer purchases dedicated DLT support.

HashiCorp engages various HashiCorp wholly-owned subsidiaries to perform limited internal activities in connection with delivering our products and services, and those subsidiaries may qualify as Subprocessors. HashiCorp, Inc. and its subsidiaries are parties to an intra-group data transfer agreement. For any questions regarding these subsidiaries, please reach out to privacy@hashicorp.com.