Legal

Subprocessors

The third parties that process customer data to provide Apex Actions, what each does, and where. Updated with thirty days' notice before a change.

Last updated

These are the providers that process customer data on our behalf to provide the service, as the data processing agreement describes. We give at least thirty days' notice before adding or replacing one, by updating this page and writing to the e-mail address on the account.

Subprocessors

ProviderWhat it does for usWhereData it processes
Amazon Web Services, Inc.Hosts the whole service: the control plane, the runners that execute jobs, the database, and the storage for logs, artifacts and cachesUS East (N. Virginia), United StatesEverything the service holds — repository data, logs, artifacts, caches, account and billing records, audit and agreement records
Stripe, Inc.Collects payment and holds payment methods. We never see or store a card numberUnited StatesAccount e-mail address and organisation name, plan, invoices and payment status; the card details you enter into Stripe's own form

Third parties you use with us

These are not subprocessors: you have your own agreement with each, and the service exchanges data with them because you have asked it to.

ProviderWhy data flows to it
GitHub, Inc.The service is built on GitHub. It reads what the App is permitted to read, and sends check-run results, statuses and annotations back to your repositories. Your agreement with GitHub governs what GitHub does with them
Notification destinationsA notification rule you configure posts what it says to the destination you named — a Slack or Teams webhook, or any HTTPS endpoint
Publishers of actions, images and packagesA workflow that references a third-party action, container image or package causes the service to fetch it from where its publisher hosts it. The request carries what the publisher's protocol requires and no more

Changes

DateChange
2026-09-04First published