Subprocessor List
This page lists the third parties (“subprocessors”) that AttribuLead engages, and what each of them can access.
We publish this because enterprise and agency buyers need it, and because in our case the answer is unusually short — and that’s the point.
The important distinction
AttribuLead is a WordPress plugin that runs on your server and stores data in your database.
No subprocessor of ours ever touches your visitor or lead data, because we never touch your visitor or lead data. It does not reach our infrastructure. There is nothing for us to pass on.
The subprocessors below support the attribulead.com business — our website, our billing, our support desk, our email. They can access things like your name, your billing email, and your support tickets. They cannot access the attribution data inside your WordPress site.
To be explicit:
| Data category | Where it lives | Subprocessors with access |
|---|---|---|
| Your website visitors’ attribution data | Your WordPress database, on your host | None |
| Your leads’ names, emails, companies | Your WordPress database, on your host | None |
| Your AttribuLead account & billing details | attribulead.com infrastructure | See the list below |
| Your support conversations with us | Our helpdesk | See the list below |
Current subprocessors
These parties process customer account data (i.e. data about you, our customer — not about your website visitors).
| Subprocessor | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| KnownHost | Hosting attribulead.com and the customer account/licensing system | Account email, name, license key, site URL, IP address of visits to our site | United States | EU Standard Contractual Clauses (SCCs) |
| Stripe | Processing payments and subscriptions | Name, billing email, billing address, tax status, payment method details (held by Stripe, not AttribuLead) | United States | EU-U.S. Data Privacy Framework and SCCs, where applicable |
| Awesome Support (self-hosted) | Handling support requests | Name, email, and any information you include in your support message | Canada | N/A (processed on AttribuLead’s own infrastructure) |
| Google Analytics | Understanding traffic to attribulead.com | Aggregated, non-identifying site usage | Global (processed by Google, including the United States) | EU-U.S. Data Privacy Framework and SCCs, where applicable |
| Umami | Understanding traffic to attribulead.com | Aggregated, non-identifying site usage | United States | EU Standard Contractual Clauses (SCCs) |
What the plugin sends us
For completeness, since it’s the question buyers actually mean:
The AttribuLead plugin makes exactly one outbound call to us. When your site activates, deactivates, or re-checks its license, it sends:
- your license key
- the product ID
- your site URL
Nothing else. No visitor data. No lead data. No usage statistics or telemetry of any kind.
What is NOT a subprocessor of ours
Your CRM. If you connect AttribuLead to HubSpot, Microsoft Dynamics, Pipedrive, Salesforce, Brevo, or a webhook, your WordPress server sends data directly to your own CRM account using your own credentials. That traffic never passes through our infrastructure.
Your CRM is therefore your vendor, not our subprocessor, and that relationship is governed by your agreement with them. We mention it here only because it’s a reasonable thing to wonder about.
Your web host. Your attribution data sits in your WordPress database with your hosting provider. That’s your vendor relationship too — but it’s worth noting in your own records (see your ROPA), since that’s where the data actually rests.
Changes to this list
We’ll update this page whenever we add or replace a subprocessor.
If you’d like advance notice of changes so you can object, email [privacy@attribulead.com] and we’ll add you to the notification list. Customers with a signed Data Processing Agreement receive [30] days’ notice of any new subprocessor, and may object on reasonable data-protection grounds.
Questions: [privacy@attribulead.com]
Related: Security & Privacy · Privacy Policy · Data Processing Agreement